Skip to content

Legal

Penetration Testing Authorization

Last updated: 22 August 2026

Intrusive testing is only lawful and ethical with clear, documented permission. This document sets out what ExploitLab requires before testing begins.

This document is a working draft provided for transparency. Actual legal wording must be reviewed and approved by qualified counsel before launch.

Core principle

ExploitLab never performs intrusive testing against systems without appropriate authorization. The free automated check on this website is non-invasive and is not covered by this document.

What you must provide

  • An explicit written authorization to test, signed by someone empowered to give it.
  • Confirmation that you own the in-scope assets, or hold permission from the owner to authorize testing.
  • An itemised list of in-scope domains, applications, APIs, environments and accounts.
  • An explicit out-of-scope list, including any shared or third-party infrastructure.
  • Named technical and escalation contacts who are reachable during the testing window.

Third-party hosted assets

If your application runs on infrastructure operated by another party, that provider's own testing policy may also apply. Where their policy requires prior notification or approval, we will not begin testing until you confirm it has been obtained.

Withdrawal of authorization

You may withdraw or narrow authorization at any time by notifying your engagement lead. Testing against the affected assets stops immediately on receipt, and we confirm in writing.

Our commitments in return

  • We test only what is listed as in scope.
  • We exclude destructive techniques and denial-of-service unless separately and explicitly authorized.
  • We report critical findings to your escalation contact promptly rather than waiting for the final report.
  • We document what we tested, when, and from which source addresses.

Questions about this document?

Write to hello@exploitlab.io.