Client Authorization
Penetration Testing Authorization Requirements
Active security testing begins only after the client confirms that they own the target or have authority from the owner to authorize testing.
Before Testing Starts
- Identify the legal entity/client and authorized contact.
- List every domain, IP address, application, API, cloud resource or environment included in scope.
- Confirm ownership or documented authority to test each asset.
- Define testing dates, time zone and emergency stop contact.
- Define allowed and prohibited techniques.
- Define how test accounts and credentials will be supplied and protected.
- Confirm how findings and evidence will be securely delivered.
Authorization Statement
By signing the engagement authorization, the client confirms that the client has the legal right or documented authority to authorize the specified security testing and that the listed assets are within the approved scope. The client understands that authorized security testing can generate alerts, logs, temporary performance impact or other normal testing artefacts.
The client agrees to provide an emergency contact and to promptly notify 8X Securities if an asset is removed from scope or if testing must stop.
Minimum Engagement Record
| Item | Required record |
|---|---|
| Client | Legal/business name and authorized representative |
| Scope | Exact domains, IPs, URLs, APIs, applications and environments |
| Window | Start/end date and time zone |
| Authorization | Signed approval or equivalent written authorization retained with engagement records |
| Contacts | Primary technical contact and emergency stop contact |
| Restrictions | Explicit exclusions and safe-testing limits |
Do not use this page as a substitute for a signed engagement document. For each real engagement, keep the authorization, scope and rules of engagement as a separate client record.
