Authorized Security Testing Terms
Version 1.0 · effective 12 August 2026
Every active test requires separate Rules of Engagement. An account, corporate ownership, administrator access or general terms acceptance is not exact authorization.
Authorization and scope
- the customer must control each asset or provide explicit owner permission;
- cloud, hosting, SaaS and other third-party approvals remain the customer’s duty;
- the RoE states exact assets, methods, time, limits, exclusions and emergency contacts;
- scope changes require explicit approval from both parties; silence is not consent.
Default exclusions
Without expanded RoE, DoS/stress testing, social engineering, malware, persistence, destructive actions, collection beyond minimum proof, password attacks, out-of-scope pivoting, and life-safety, OT/ICS or critical-infrastructure testing are forbidden. Synthetic/rehearsal functions cannot be treated as production execution.
Evidence and stop-test
Access is minimized, secrets redacted and whole databases are never copied merely as proof. Either party may stop testing immediately. Outage, data loss, unexpected access, third-party impact, an active incident or ambiguity requires a pause until named contacts explicitly resume.
Legal boundary
Authorization binds only the parties and exact RoE. It cannot bind an owner, provider or authority that did not consent. Security-research exemptions are not blanket safe harbor. Doubt always pauses testing.
AISeeRisk operator
9ne.pl Jarosław Staroń
NIP 8942787122
ul. Starobielawska 32a
54-061 Wrocław, Polska
Contact: kontakt@aiseerisk.pl