Authorized Security Testing

Ethical Hacking & Penetration Testing

Professional security testing designed to identify exploitable weaknesses in websites, web applications, APIs and other in-scope assets — only after the system owner or authorized representative provides written permission and the testing scope is agreed.

Authorization is mandatory. We do not offer unauthorized access, account compromise, credential theft, malware deployment, destructive testing, DDoS, or testing of third-party assets without permission.
View Authorization Requirements

Testing Services

Web Application Pentest

Manual and tool-assisted testing of authentication, authorization, sessions, input handling, business logic and common web security weaknesses.

API Security Testing

Assessment of API authentication, authorization, input validation, access controls, rate limiting and sensitive-data exposure.

Website / CMS Testing

Security assessment of authorized websites and CMS deployments, including configuration and exposure checks.

Network / Infrastructure Testing

Only where explicitly included in the signed scope, with agreed targets, testing windows and safe-testing constraints.

Authenticated Testing

Testing with client-provided test accounts or credentials specifically created and approved for the engagement.

Retesting

Follow-up validation of agreed remediation items, with findings mapped back to the original report.

How an Authorized Engagement Works

1. Scope

Client identifies assets, domains, IPs, applications, environments, accounts and testing window.

2. Written Authorization

Client confirms ownership or authority and signs the testing authorization before active testing begins.

3. Rules of Engagement

Allowed techniques, exclusions, rate limits, emergency contacts, stop conditions and evidence handling are agreed.

4. Testing & Reporting

Testing is performed within scope. Findings are documented with evidence, impact, remediation guidance and limitations.

Typical Scope

AreaExamples
ApplicationsWeb applications, APIs, authorized mobile/API backends, staging environments.
Security controlsAuthentication, authorization, session management, input validation, access control and security configuration.
EvidenceMinimal necessary screenshots, request/response evidence, timestamps and reproducible technical observations.
DeliverablesExecutive summary, scope, methodology, findings, risk description, evidence, remediation guidance and retest status where applicable.

Explicit Exclusions Unless Separately Authorized

  • Denial-of-service or distributed denial-of-service testing.
  • Destructive actions, data deletion or intentional service disruption.
  • Testing of third-party systems, customer systems or infrastructure outside the approved scope.
  • Social engineering, phishing, physical intrusion or credential harvesting unless specifically contracted and legally authorized.
  • Persistence, backdoors, malware deployment or covert access mechanisms.
  • Accessing, copying or exposing unnecessary personal, financial or confidential data.

Standards & Methodology

Where appropriate, the engagement methodology may reference OWASP testing guidance, applicable ISO/IEC security practices, relevant CERT-In guidance and other agreed security-testing methodologies. The exact methodology and scope will be documented for each engagement. A website page should not represent 8X Securities as CERT-In empanelled unless that status is actually held.

Important: A penetration-test report is a point-in-time assessment. It does not guarantee that a system is completely secure or compliant with every legal or regulatory requirement.