Rules of Engagement

Authorized Penetration Testing Rules

These operational rules help keep testing controlled, auditable and limited to the assets and activities approved by the client.

Stay In Scope

Do not test an asset merely because it is technically reachable. Test only explicitly authorized targets.

Minimize Impact

Prefer non-destructive validation and the minimum evidence needed to demonstrate a finding.

Protect Data

Do not unnecessarily access, copy, retain or disclose personal, financial or confidential information.

Stop on Risk

Immediately pause testing if there is unexpected service degradation, suspected data exposure or a client stop request.

Operational Rules

  • Use client-approved test accounts whenever authentication is required.
  • Do not attempt to access unrelated accounts or systems.
  • Do not intentionally destroy, alter or encrypt production data.
  • Do not conduct DoS/DDoS or stress testing unless separately and explicitly authorized with appropriate safeguards.
  • Do not deploy malware, persistent backdoors or covert access mechanisms.
  • Keep discovered vulnerabilities confidential and disclose them only to authorized recipients.
  • Record material testing activity, timestamps and relevant evidence for the final report.
  • Report critical findings promptly when the engagement rules require immediate notification.

Report Structure

A professional report should identify the scope, testing period, methodology, limitations, findings, evidence, risk context, remediation guidance and retest status. Where applicable, include timestamps, versions and evidence hashes. Avoid unnecessary customer data in screenshots or attachments.