is a pentest legal to run on our own systems?
yes, with written authorisation from whoever owns the system. we agree a scope, the testing window, and the rules of engagement in writing before anything starts, and we get sign-off from your hosting provider where they require it. we only ever test what's on that signed scope.
the question usually comes from a sensible place: testing looks a lot like attacking, and you don't want to find out afterwards that your hosting provider, or a supplier's terms of service, saw it that way. authorisation is what separates the two, and we don't start without it in writing.
what gets agreed before anything runs
- the scope: which domains, applications, APIs and accounts are in. anything not on the list is out, even if we could reach it.
- the testing window: when testing happens, so your team knows any odd activity in that window is us, and can tell us if it isn't.
- the rules of engagement: what we will and won't do, and who to call on each side if something needs pausing.
- the signature, from whoever actually owns the system. if that isn't you, say an app another company built and hosts for you, we sort that out first.
hosting providers
some cloud and hosting providers ask to be notified, or to approve, before anyone tests on their infrastructure. where yours does, we get that sign-off during scoping. it's one more form in the paperwork, and it doesn't hold the work up.
the same document protects you, too: if a client or insurer later asks what was tested and on whose authority, you hand it over. it sits alongside your NDA if you have one. when you're ready, send us the systems you have in mind and we'll draft the scope.