Authorised testing
Before any security testing begins, we require written authorisation from the person or organisation that owns the system. That authorisation names the systems in scope, the systems explicitly out of scope, the testing window, and a contact who can be reached if something unexpected happens during the engagement.
This is not a formality we can waive to move faster. If the authorisation is not in place, the work does not start — regardless of deadline pressure or how straightforward the request seems.
Client permission and scope
Scope is agreed in writing and we stay inside it. If we find something during testing that suggests a problem outside the agreed scope, we report the observation and ask whether you want to extend the engagement. We do not simply keep going because it seemed interesting.
Where a system is hosted or operated by a third party — a hosting provider, a SaaS platform, a payment processor — we will tell you what additional permission is needed before that component can be tested.
Responsible disclosure
Findings go to the system owner first, with enough detail to reproduce and fix them. We agree a remediation window before anything is disclosed more widely, and we do not publish details of a client's vulnerabilities without written consent.
If we identify a vulnerability in third-party software during an engagement, we coordinate disclosure with the vendor through their published security contact, and we keep the client informed throughout.
Data confidentiality
Engagement material — findings, evidence, screenshots, logs — is handled as confidential and is accessible only to the team working on that engagement. We sign NDAs on request, and we can agree a destruction schedule for evidence once the engagement and any retest are complete.
Where testing might touch production data, we agree in advance how it will be handled. Our default is to prove access without extracting data, and to redact anything that does end up in the report.
Privacy protection
We avoid collecting personal data we do not need. Where an assessment involves systems holding personal data, we work with your team to keep exposure minimal and to document what was accessed so you can meet your own regulatory obligations.
Legal compliance
Unauthorised access to computer systems is a criminal offence in most jurisdictions, including under India's Information Technology Act, the UK's Computer Misuse Act and the US Computer Fraud and Abuse Act. Written authorisation from the system owner is what separates our work from that. We operate within the law of the jurisdictions our clients and their systems sit in.
Controlled testing environments
All training exercises run in isolated lab ranges built for the purpose. Lab targets are owned and operated by us, segmented from the public internet and from other students, and reset to a clean state on request. Exercise briefs state the scope explicitly, and testing outside that range ends lab access.
Responsible security education
We teach offensive technique because you cannot defend against something you do not understand. Every course covers the legal context alongside the technical material, and assessment weights remediation and reporting at least as heavily as exploitation.
Course material is designed for authorised assessment work and for defending systems you are responsible for. It is not designed for, and does not support, attacks on systems you do not own.
Requests we decline
To be explicit, we do not accept work that involves:
- Accessing accounts, devices, messages or data belonging to another person
- Recovering access to an account that is not yours, however the situation is described
- Testing systems where the requester cannot demonstrate ownership or authorisation
- Deploying malware, ransomware or surveillance tooling against any target
- Monitoring, tracking or de-anonymising individuals
- Removing, altering or suppressing evidence, records or lawful content
These requests reach us regularly. The answer is always no, and we will not suggest someone else who might say yes.