1.Authorisation
1.1
We test a system only with the written authorisation of its owner, or within a program published by its owner and by the rules of that program.
1.2
We stay within the agreed scope. A path that leads outside the scope is reported and not followed.
1.3
We verify that the person who authorises a test is entitled to authorise it.
2.Care
2.1
We choose the least intrusive action that proves the point.
2.2
We stop when continuing would put data, availability or people at risk.
2.3
We remove what we have created and report every change we have made.
3.Confidentiality
3.1
What we learn about a client stays with the team of the engagement. The fact that a company is our client is itself confidential.
3.2
We access personal data only as far as the proof of a finding requires and do not keep it.
3.3
Findings are disclosed to the owner of the system. With the written consent of the owner they are also disclosed to those who remedy the vulnerability or coordinate its remedy, such as the vendor of the affected software, or are published. They are disclosed to no one else.
4.Honesty
4.1
We report what we have reproduced. We do not inflate the severity of a finding and do not conceal what we were unable to test.
4.2
We promise no result that cannot be promised: nobody finds every vulnerability.
4.3
We say plainly when a request is outside our competence, and we decline it.
5.Fair price
5.1
The terms on which we are paid are known to the client before the work starts. For the free website check they are set by the Terms of the Free Website Security Check.
5.2
We never examine a system first and name a price afterwards to an owner who did not ask for the examination.
5.3
A client who does not buy a report owes us nothing, and what we have found stays confidential.
5.4
Signs that a system has already been compromised are reported to its owner at once and free of charge.
6.Independence and conflicts of interest
6.1
We take no commission from the vendors and the platforms whose products we recommend.
6.2
We submit no reports to the programs of our own bug bounty platform and to the programs that we manage or have prepared.
6.3
We use the knowledge gained in an engagement for no purpose other than that engagement.
7.What we never do
7.1
We never:
- (a)demand payment for a vulnerability found without the request of the owner, or set conditions for reporting it;
- (b)develop or sell malicious software or exploits for use outside an authorised test;
- (c)access the accounts, the devices or the correspondence of private individuals;
- (d)exploit fear, personal hardship or health in scenarios of social engineering;
- (e)name a person in a report as the cause of a finding.
8.Breach of the Code
8.1
Anyone who has noticed a breach of this Code, inside or outside our team, can report it to info@securitytest.team.
8.2
A breach of the Code ends the cooperation with the person responsible, and the client concerned is informed.