Ethics

Responsible Testing Policy

This policy defines how testing is conducted, what is never done, and the standards every engagement is held to — regardless of client, budget or urgency.

Authorization Is Non-Negotiable

Security testing is performed only against systems for which written authorization has been received and verified. There are no exceptions to this rule.

Scope Discipline

Testing is confined to the assets explicitly listed in the agreed scope. Anything discovered outside that boundary is reported, not tested.

Duty Of Care

Techniques are chosen to minimize disruption to authorized systems. Potentially destructive actions are agreed in advance, scheduled, and never performed casually.

Data Handling

Access to data is limited to the minimum required to evidence a finding. Sensitive data is not extracted, retained beyond the engagement, or shared outside the agreed recipients.

Work That Is Declined

Requests for unauthorized access, credential theft, account cracking, malware or ransomware deployment, denial-of-service attacks, data theft, surveillance of individuals, or evasion of law enforcement are refused outright.

Disclosure Conduct

Findings are disclosed privately to the authorized client contact. Public discussion of any finding occurs only with written permission and after remediation.