Written authorization
All tests require written authorization before any activity begins. No exceptions.
Responsible testing
Offensive security is only legitimate when it is authorized. These commitments govern every engagement we run.
Last updated 2026-07-01
All tests require written authorization before any activity begins. No exceptions.
Activities remain strictly within the scope and rules of engagement defined in the statement of work.
Customers must have the authority to authorize testing of the in-scope networks and facilities.
Testing can be paused or stopped at any time using the agreed escalation procedures and stop conditions.
Evidence is collected, stored and transmitted according to the engagement's evidence-handling terms.
The service does not support, encourage or enable unauthorized access to any system or network.
Before any active technique runs, we agree a signed statement of work and rules of engagement covering the facilities and networks in scope, authorized dates and windows, allowed and prohibited techniques, safety limits, escalation contacts, evidence-handling requirements, success criteria, the definition of a critical vulnerability, and stop conditions.
Certain techniques — such as controlled client deauthentication, Evil Twin resilience assessment, credential-resilience and cloud-assisted password auditing, wireless phishing simulations, social-engineering scenarios and any physical-security interaction — are performed only when explicitly authorized in the signed rules of engagement, and never by default.
This website is focused on legitimate, defensive cybersecurity services. It does not publish attack commands, exploit code, payloads or step-by-step instructions that could facilitate unauthorized access. We describe classes of testing at a high level so buyers can make informed decisions.