Skip to content
HACKTECH

Policies

Offensive work, practised responsibly.

We break things for a living, which only works if everyone trusts the lines we hold. This is how we scope engagements, how we handle what we find, and where the boundaries are.

Coordinated disclosure

When we find a vulnerability during an engagement, it goes to the client first — critical issues immediately, under the escalation clause of the rules of engagement, rather than being saved for the final report.

If in the course of authorised testing we encounter a flaw in a third-party product, we report it to that vendor privately and give them reasonable time to remediate before any public detail is shared. We do not publish exploit code for unpatched issues.

Rules of engagement

Nothing starts without written authorisation naming the in-scope targets, the testing windows, and a traffic identifier your team can filter our activity on. Anything not explicitly in scope is out of scope.

  • We test only the assets you own or are contractually permitted to authorise.
  • We agree escalation contacts before testing, and page them the moment a critical issue is confirmed.
  • We avoid denial-of-service and destructive techniques unless they are explicitly scoped and scheduled.
  • We handle any data we encounter as confidential, minimise what we retain, and destroy it on engagement close.