1. Parties and authorization
Names of the customer and CyberZ, the authorized signatory on the customer side who is entitled to grant testing permission, and confirmation that the customer owns or has the right to authorize testing of every in-scope target.
2. Authorized targets
Exact hostnames, IP addresses or ranges, applications, APIs, cloud accounts, environments and test accounts that may be tested.
3. Prohibited targets
Systems explicitly excluded, including third-party services, shared infrastructure and any production data stores excluded by the customer.
4. Testing window
Dates and hours during which testing may occur, blackout periods, and the time zone that applies.
5. Source IP addresses
Addresses from which testing traffic originates, where applicable, so it can be identified and allowlisted or monitored.
6. Testing methods
Permitted techniques: manual testing, automated scanning, credentialed testing, and any methods excluded by agreement.
7. Exploitation limits
How far a confirmed vulnerability may be exploited: proof-of-concept only, limits on data access, no persistence, no modification of production data unless expressly agreed.
8. Social engineering
Whether phishing or other social engineering is included, and if so, the permitted targets, pretexts and approvals required. Excluded unless stated.
9. Denial-of-service restrictions
Denial-of-service and resource-exhaustion testing are excluded by default and performed only with explicit written agreement and controls.
10. Data handling
How data encountered during testing is minimized, captured as evidence, stored, transferred and destroyed, and the retention period that applies.
11. Emergency contacts
Named contacts on both sides reachable during the testing window, with escalation paths.
12. Stop conditions
Events that pause or end testing immediately: system instability, unexpected exposure of sensitive data, detection of a third-party compromise, or a request from the customer.
13. Communication channels
Where status updates, critical findings and questions are exchanged, and how those channels are secured.
14. Reporting and retest
Report delivery method, retest window and the conditions under which a CyberZ Penetration Testing Certificate is issued.
Contact
Questions about this document: contact@cyberz.net.