Responsible Disclosure & Rules of Engagement
Penetration testing only stays lawful and ethical when it's explicitly authorized and carefully controlled. This page sets out the commitments that govern every engagement we perform.
Written Authorization, Always
We do not test any system, network, application, or person without prior written authorization from someone with the legal authority to grant it. Every engagement begins with a signed scope of work naming the exact assets in scope, the testing window, and a named point of contact able to verify our testers in real time if needed.
Confidentiality
Every engagement is covered by a mutual non-disclosure agreement, signed before any technical details are shared in either direction. We do not disclose that a company is a client, the systems tested, or any findings, without explicit written permission.
No Destructive Techniques
Denial-of-service testing, data destruction, and other high-risk techniques are excluded from every engagement by default, and are only performed if specifically requested and separately authorized in writing.
Handling of Findings
Vulnerabilities discovered during an engagement are reported only to the client, through the agreed secure channel. We do not publicly disclose, sell, or otherwise use findings from a client engagement.
Data Handling During Testing
Where testing exposes real customer or business data (for example, through a successful access-control bypass), we access only what's necessary to prove and document the finding, and do not copy, exfiltrate, or retain that data beyond what's needed for the report.
Reporting a Vulnerability in Our Own Systems
If you've found a security issue in cybersecuritypentest.com itself, we'd genuinely like to know. Email security@cybersecuritypentest.com with details and we'll acknowledge and address it. Please give us a reasonable window to fix an issue before discussing it publicly.
Questions
For questions about how a specific engagement would be scoped or authorized, contact us at info@cybersecuritypentest.com.