Legal
Rules of Engagement
Last updated: [DATE]
1. Authorization
[All penetration testing activities are performed only with explicit, written authorization from the asset owner. Testing will not begin until a signed authorization document is in place.]
2. Scope Definition
[The scope of testing is mutually agreed upon before the engagement begins. This includes specific domains, IP ranges, applications, APIs, and any exclusions. Testing will not extend beyond the defined scope.]
3. Testing Windows
[Define agreed-upon testing hours and any blackout periods. Emergency contact procedures if testing causes unexpected issues.]
4. Prohibited Activities
[List activities that are explicitly excluded — denial of service, social engineering of employees (unless in scope), physical security testing, modification or destruction of data, accessing data beyond what is necessary to demonstrate a vulnerability.]
5. Data Handling
[Explain how any accessed data will be handled — minimal data extraction, secure storage, deletion after reporting. No client data used for training or shared with third parties.]
6. Vulnerability Disclosure
[All findings are reported directly and exclusively to the client. Findings will not be publicly disclosed without the client's written consent. Critical vulnerabilities will be reported immediately upon discovery.]
7. Communication
[Define communication channels — encrypted email, Slack, secure portal. Frequency of status updates during the engagement. Emergency escalation procedures.]
8. Reporting
[Describe report format, delivery method, and timeline. Reports are delivered via encrypted channels. Findings include severity rating, proof-of-concept, reproduction steps, and remediation guidance.]
9. Retesting
[Explain the retest process — timeline, scope of retest, and how remediation verification is documented.]
10. Contact
For questions about our rules of engagement, contact us at security@bugvsme.com.