Rules of engagement

Authorized, scoped, and documented.

These rules protect customers, users, and audit integrity. They apply to free recon, scoped audits, and future Continuous CI/CD beta work.

  1. Testing requires authorization from the asset owner or authorized representative.
  2. Paid audit scope is confirmed manually before checkout.
  3. Rate limits, excluded systems, production constraints, and sensitive data rules are documented before testing.
  4. Findings are reported privately with evidence, impact, and remediation guidance.