Responsible Testing Policy
This policy defines how testing is conducted, what is never done, and the standards every engagement is held to — regardless of client, budget or urgency.
Authorization Is Non-Negotiable
Security testing is performed only against systems for which written authorization has been received and verified. There are no exceptions to this rule.
Scope Discipline
Testing is confined to the assets explicitly listed in the agreed scope. Anything discovered outside that boundary is reported, not tested.
Duty Of Care
Techniques are chosen to minimize disruption to authorized systems. Potentially destructive actions are agreed in advance, scheduled, and never performed casually.
Data Handling
Access to data is limited to the minimum required to evidence a finding. Sensitive data is not extracted, retained beyond the engagement, or shared outside the agreed recipients.
Work That Is Declined
Requests for unauthorized access, credential theft, account cracking, malware or ransomware deployment, denial-of-service attacks, data theft, surveillance of individuals, or evasion of law enforcement are refused outright.
Disclosure Conduct
Findings are disclosed privately to the authorized client contact. Public discussion of any finding occurs only with written permission and after remediation.