Stillhook Labs

Legal & Trust

We never test without permission

Penetration testing without authorization is illegal in most jurisdictions. Here's exactly how we make sure that never happens with your engagement.

Written authorization comes first

Before any testing begins, we send a scope and authorization agreement that spells out exactly what will be tested, what won't, and the testing window. It has to be signed by someone authorized to approve testing on the target system before we do anything. Phishing simulations also need written sign-off from your leadership.

We stay inside the agreed scope

We only test the systems, domains, and testing windows named in the signed agreement. Anything discovered outside that scope is reported, not touched. There is no live "test your site now" tool on this website. All testing happens off-site, after authorization, by us.

For example: if your agreement covers admin.example.com and, while testing it, we notice that a linked third-party service or a sibling domain like marketing.example.com also looks vulnerable, we don't touch it. We note it in the report as an out-of-scope observation so you can decide whether to authorize a follow-up engagement to cover it.

Takedowns stay within the law

When we find a scam site, we report it as phishing or fraud to the hosting provider, the registrar, and browser and email blocklists. Anyone can file these reports, and we then notify the brand being impersonated. We only file formal requests on a brand's behalf, such as trademark or copyright claims, with its written go-ahead. We never hack, attack, or disrupt a scam site ourselves.

Your data stays confidential

Findings, reports, and anything discovered during testing or takedown work are treated as confidential and are only shared with people you authorize.

Our full Privacy Policy and Terms of Service are in development and will be published here before we take on paid engagements.

Questions in the meantime? Reach us at support@stillhooklabs.co.za.