Legal
Rules of Engagement
Last updated: 22 August 2026
These are the default operating rules for an ExploitLab assessment. They are confirmed, and where necessary adjusted, in writing before testing starts.
This document is a working draft provided for transparency. Actual legal wording must be reviewed and approved by qualified counsel before launch.
Testing window
- Testing runs inside an agreed window, with dates and hours fixed in advance.
- Higher-impact activity is scheduled for a period you nominate.
- We notify your contact at the start and end of each testing day on request.
Intensity and safety
- Request rates are kept at levels that should not degrade service availability.
- Denial-of-service, volumetric and stress testing are excluded by default.
- We avoid destructive actions: no deletion, corruption or mass modification of data.
- Exploitation is carried out to the minimum depth needed to demonstrate impact, then stopped.
Excluded by default
- Social engineering of your staff, customers or suppliers.
- Physical intrusion.
- Testing of third-party services outside your control.
- Any activity against assets not on the in-scope list.
Sensitive findings
If we encounter real customer data, credentials or other sensitive material, we stop, record the minimum necessary evidence, and notify your escalation contact. We do not exfiltrate or retain such material.
If we find evidence suggesting a pre-existing compromise, we notify your escalation contact immediately and pause activity that could disturb forensic evidence.
Communication
- A named engagement lead is your single point of contact throughout.
- Critical findings are reported as soon as they are validated, not held for the report.
- You can request an immediate stop at any point; testing halts on receipt.
Source identification
We provide the source addresses we test from so your team can distinguish our activity from a genuine attack, and we log the timing of each test phase for correlation with your monitoring.
Questions about this document?
Write to hello@exploitlab.io.