Legal & Trust
We never test without permission
Penetration testing without authorization is illegal in most jurisdictions. Here's exactly how we make sure that never happens with your engagement.
Written authorization comes first
Before any testing begins, we send a scope and authorization agreement that spells out exactly what will be tested, what won't, and the testing window. It has to be signed by someone authorized to approve testing on the target system before we do anything. Phishing simulations also need written sign-off from your leadership.
We stay inside the agreed scope
We only test the systems, domains, and testing windows named in the signed agreement. Anything discovered outside that scope is reported, not touched. There is no live "test your site now" tool on this website. All testing happens off-site, after authorization, by us.
For example: if your agreement covers admin.example.com and, while testing it, we notice that a linked third-party service or a sibling domain like marketing.example.com also looks vulnerable, we don't touch it. We note it in the report as an out-of-scope observation so you can decide whether to authorize a follow-up engagement to cover it.
Takedowns stay within the law
When we find a scam site, we report it as phishing or fraud to the hosting provider, the registrar, and browser and email blocklists. Anyone can file these reports, and we then notify the brand being impersonated. We only file formal requests on a brand's behalf, such as trademark or copyright claims, with its written go-ahead. We never hack, attack, or disrupt a scam site ourselves.
Your data stays confidential
Findings, reports, and anything discovered during testing or takedown work are treated as confidential and are only shared with people you authorize.
Our full Privacy Policy and Terms of Service are in development and will be published here before we take on paid engagements.
Questions in the meantime? Reach us at support@stillhooklabs.co.za.