THAGHARATVulnerability Hunter
Policy

Testing Safety Policy

Last updated: 22 September 2026

A penetration test only helps if it doesn't hurt. This policy sets out the safeguards we apply on every engagement. The rules of engagement you sign with us can make them stricter; they never make them looser without your written agreement.

01Written authorisation comes first

We test nothing until we hold a signed agreement and written authorisation from someone entitled to grant it for every system in scope.

  • Systems hosted or operated by third parties — cloud platforms, SaaS providers, managed service providers — are tested only where their policies allow it, or with their permission.
  • The authorisation names the systems, the testing window and the people who can stop the test.

02Agreed scope, nothing more

Targets — domain names, IP ranges, applications and accounts — are listed in writing before testing starts. Anything not listed is out of scope.

  • If we find an asset that appears to be yours but isn't in scope, we stop and ask rather than test it.
  • Scope changes are agreed in writing before we act on them.

03Testing windows and contacts

  • Testing runs inside agreed windows, and we tell you when each window opens and closes.
  • Both sides name escalation contacts who are reachable for the whole window.
  • You can pause or stop testing at any time through your escalation contact.

04Safe techniques by default

Unless you authorise them explicitly and in writing, we do not use:

  • Denial-of-service or load testing.
  • Actions that delete, alter or corrupt data.
  • Persistence mechanisms, backdoors or anything left running after the test.
  • Social engineering or physical access attempts.
  • Automated scanning of production at rates beyond what we agree with you.

05Stop conditions

We stop immediately and contact you if we see:

  • Instability, errors or degraded performance in a system under test.
  • Signs that someone else has already compromised the environment.
  • Access to sensitive data beyond what is needed to prove a finding.

06Critical findings within 24 hours

Anything critical is reported to your escalation contact within 24 hours of confirmation, with enough detail to act on. You don't wait for the final report.

07Handling your data

  • We access the minimum data needed to prove a finding, and redact personal and sensitive data from evidence.
  • Engagement data is stored encrypted, and access is limited to the people working on your engagement.
  • Data is kept only as long as the agreement allows and destroyed on request after closure, with written confirmation.

08Credentials and test accounts

  • We use test accounts that you provide, and store credentials in an encrypted vault.
  • At the end of the engagement we ask you to disable or rotate every credential you shared with us.

09Our people

  • Everyone who works on your engagement is bound by confidentiality before they see any detail of your environment.
  • We don't subcontract testing without your written consent.

10Clean-up

When testing ends we remove what we introduced — uploaded files, created accounts, test payloads — and list anything we could not remove in the report, so you can remove it yourselves.

11Raising a concern

During an engagement, contact your named escalation contact. At any other time, write to contactus@thagharat.com.