Rules of engagement for security tests
They are the pact signed before starting: where work may be done, when, what is never done, and what happens if something stops. We publish them here so that whoever is evaluating can read them before, not after.
Version 1.9 — 13/09/2026. The accepted version is recorded together with the signature: it tells, even two years from now, exactly which text was shown.
1. We work only where you wrote it down
Only the systems you listed in this form are tested. Whatever is not written down is not touched, even if it is reachable from the authorised ones. Connected third-party services — payments, email, analytics, legal documents — are always out of scope.
2. We work only when you said so
Tests run within the dates and time band you indicated, in your time zone: times are written in 24-hour format and always with the time zone next to them, so nobody has to wonder "8 pm for whom". Outside that window nothing is executed. If more time is needed it is agreed in writing: this form does not extend itself.
3. We work remotely, unless agreed otherwise
The work is done remotely, over the network, on the systems you listed and nothing else. If physical presence on site is needed — for an internal network or workstations not reachable from outside — it is agreed separately and in writing: travel has an additional cost, stated in the quote, and never starts on its own.
4. What is never done
No tests aimed at bringing down or slowing your systems. No deletion, alteration or encryption of data. No deceptive phone calls or emails to your staff: we do not perform tests against people, not even on request. Load tests or data deletions, if you need them, are agreed separately and in writing.
5. If something stops, everything stops
If during the work a system freezes or slows down, tests stop immediately and the contact you indicated is called. That is why that number must be reachable for the whole window.
6. No exploits, ransomware or malware delivered, in any way
Exploits, ransomware or malware are not delivered in any way: not to you, not to third parties, not left on your systems. Whatever is needed to demonstrate a flaw is deleted once the tests are over and does not appear in any report. You receive a before-and-after account: what was exposed, what was demonstrated, how severe it is, how to close it — never what was used to do it.
7. Cryptography is always checked, not by chance
In every test we check how data and access are protected: keys or passwords written inside the code, protection methods that are old or considered superseded, certificates expired or badly configured, user passwords kept in plain text or with methods that are no longer enough. It is a fixed step of the work, not an extra: it is where the flaws that make no noise on their own are found — the ones that open the door to everything else. We tell you what we found and how it is closed: we do not issue certifications and do not declare conformity to any standard, because that is attested by an accredited body and is a different trade.
8. What we see stays between us
During a test one comes across confidential data. It stays confidential without time limit, is not copied out beyond the minimum needed to demonstrate the problem, and is redacted in the report.
9. The report is yours
The final document — flaws found, severity, risk, how to fix them — is your property. It is not used as a case study, it is not quoted and your name does not appear in any marketing material without your separate written authorisation.
10. A backup is recommended
We recommend a recent, verified backup of the systems listed: a security test carries a risk that cannot be reduced to zero, and the backup is what makes it bearable. It is not a blocker: if you declare you do not have one, we work with maximum caution and you bear that risk.
11. What this work is not
A security test states what was found within the agreed scope and time. It is not a guarantee that the system is unassailable, and it is not a certification.
12. Whoever signs must be entitled to
By signing you declare that you own the systems listed, or have the written permission of whoever does, and that you have the power to bind the company. If the systems sit with a third-party provider — hosting, management software, online shop — that provider's permission is needed too.
How to start
1. Read
These are the rules above. They do not change midway: the version you accept is recorded with the signature.
2. Fill in
Write which systems may be tested, on which dates and hours, and what must be left out. Whom to call if something stops.
3. Sign
With your finger, at the bottom of the form. These rules are part of it and you accept them by signing. At the end you get a receipt code to download and keep.
4. Pay
Right after signing, on the same page. Work starts once payment is received, within the dates you wrote. No subscription and no recurring charge.
Or write to us at assistenzaopexscore@protonmail.com — or go back to cybersecurity.