Client Authorization

Penetration Testing Authorization Requirements

Active security testing begins only after the client confirms that they own the target or have authority from the owner to authorize testing.

Before Testing Starts

  1. Identify the legal entity/client and authorized contact.
  2. List every domain, IP address, application, API, cloud resource or environment included in scope.
  3. Confirm ownership or documented authority to test each asset.
  4. Define testing dates, time zone and emergency stop contact.
  5. Define allowed and prohibited techniques.
  6. Define how test accounts and credentials will be supplied and protected.
  7. Confirm how findings and evidence will be securely delivered.

Authorization Statement

By signing the engagement authorization, the client confirms that the client has the legal right or documented authority to authorize the specified security testing and that the listed assets are within the approved scope. The client understands that authorized security testing can generate alerts, logs, temporary performance impact or other normal testing artefacts.

The client agrees to provide an emergency contact and to promptly notify 8X Securities if an asset is removed from scope or if testing must stop.

Minimum Engagement Record

ItemRequired record
ClientLegal/business name and authorized representative
ScopeExact domains, IPs, URLs, APIs, applications and environments
WindowStart/end date and time zone
AuthorizationSigned approval or equivalent written authorization retained with engagement records
ContactsPrimary technical contact and emergency stop contact
RestrictionsExplicit exclusions and safe-testing limits
Do not use this page as a substitute for a signed engagement document. For each real engagement, keep the authorization, scope and rules of engagement as a separate client record.