These terms govern how Truevector engages. They exist to keep our work lawful and to protect both sides.
We conduct security assessments exclusively on systems, networks and applications that you own, or for which you have obtained explicit written authorisation from the system owner. We require a signed scope-of-work agreement before any testing begins. We do not access, probe or test any system without documented consent.
By engaging Truevector you warrant that you own, or have obtained explicit written authorisation to test, all systems in the agreed scope, including any approvals required from cloud providers and third-party vendors. You will clearly identify production systems and any out-of-scope assets.
We do not access accounts or systems without the owner's consent, monitor or surveil individuals, recover access to accounts that are not yours, or undertake any activity that would breach the Computer Fraud and Abuse Act, the Computer Misuse Act, or equivalent laws. Requests of that kind are declined.
We sign your NDA as standard, report findings only to you, and retain nothing after delivery.