The entire agreement. One target, read-only rules, one signature, one report, one retest. Everything in [brackets] is a placeholder — your engagement signs this same page, filled in.
The scope is exactly one public application or API together with its domain. Everything at or below the declared origin is in scope; everything else is out. Black-box: we never need your code, your repository, or your credentials.
The run simulates an external attacker against the declared origin: passive reconnaissance, endpoint probing, proof-of-concept execution. Every payload is non-destructive by design.
What we may create while testing: test accounts and synthetic requests to reach authenticated flows. Every account, request, and record we create is declared here in advance and itemized in the final report — contamination is a line item, never a surprise.
This page must be signed by someone with authority over the target domain — an owner or an authorized technical lead. Payment does not authorize the run; this signature does. By signing, the client declares ownership of the declared domain and authorizes exactly this page.
The run starts on the date agreed at signature. The full report — validated findings with PoCs, a verified-resistances certificate, and remediation guidance — is delivered within 48 hours of signature. Your code and data stay yours: black-box means we handle none of your source; the report is confidential by default.
One price for the whole engagement. Quoted before signature and fixed on this page when you sign it — nothing metered, nothing surprises you later.
Retest included: after you remediate, we re-attack every finding once — included in the price, until each one reads fixed or formally contested.
Abort channel: a direct channel (email and phone) to the operator is declared at signature. Either side can stop the run at any moment with a single message — no justification required. Work performed up to that point is delivered as-is.