aisecurity.llc
hello@aisecurity.llc
Legal Agreement · Negotiation Draft
AI Red Team Rules of Engagement
Rules of engagement for authorized AI red-team validation, including targets, test windows, allowed techniques, prohibited actions, safety controls, evidence handling, escalation paths, and stop conditions.
Commercial placement
Where this document is typically used
1. Engagement Summary
| Field | Value |
|---|---|
| Client | Client |
| Provider | aisecurity.llc |
| Engagement Name | the engagement agreed during scoping |
| Related SOW | the applicable Statement of Work |
| Test Window | the engagement start date confirmed during scoping to to be specified during scoping |
| Client Security Contact | the Client security contact |
| Provider Test Lead | David Wolf · hello@aisecurity.llc |
2. Authorized Targets
Testing is authorized against the following systems, endpoints, and interfaces only:
- The specific AI systems, endpoints, models/providers, RAG corpora, and agent workflows enumerated and confirmed in writing during scoping.
- No system, endpoint, account, or data source outside that confirmed list is in scope.
Testing is explicitly limited to the above. Any system, endpoint, account, or data source not listed here is out of scope.
3. Authorized Attack Techniques
The following attack technique families are authorized:
- Prompt injection (direct and indirect)
- Jailbreak and policy-bypass attempts
- Context-window manipulation
- RAG corpus poisoning simulation (read-only unless separately authorized)
- Tool misuse and function-call abuse
- Unsafe action-path exploration
- Output-handling and data-exfiltration-via-output testing
- Agent goal hijacking
- Additional technique families only as confirmed in writing during scoping
Prohibited Actions
The following are explicitly prohibited regardless of technical capability:
- Accessing, modifying, exfiltrating, or destroying production data not in the authorized targets
- Attacking systems, endpoints, or accounts not in the authorized targets
- Social engineering of Client personnel unless separately authorized
- Denial of service or load testing unless separately authorized
- Introducing persistent artifacts (backdoors, modified prompts) into any environment
- Sharing test artifacts, prompts, or findings outside the named delivery contacts
- Publishing or referencing Client systems or findings without written consent
4. Test Windows and Scheduling
| Window | Dates / Times |
|---|---|
| Primary test window | the period confirmed in the applicable SOW |
| Authorized testing hours | the agreed testing hours |
| Blackout dates | any blackout dates identified by the Client |
| Coordination cadence | an agreed coordination cadence |
Provider will notify Client security contact at the start and end of each active testing session.
5. Evidence and Data Handling
- All test artifacts (prompts, outputs, screenshots, logs) are treated as confidential Client information.
- Evidence will be stored in a an access-controlled, encrypted store available only to named delivery contacts accessible only to named delivery contacts.
- Raw test outputs containing sensitive data will be redacted before inclusion in reports.
- Evidence will be retained for 30 days or until final delivery, whichever is later and then deleted or returned per Client instruction.
- Provider will not use test artifacts to train AI models or for any purpose beyond this engagement.
6. Emergency Stop Procedure
If testing causes unexpected production impact, discovery of a critical zero-day, or exposure of regulated data:
- Provider immediately stops all test activity and notifies Client security contact via the agreed secure channel (phone, Signal, or secure email).
- Client security contact confirms receipt within fifteen (15) minutes.
- Both parties jointly assess impact before testing resumes.
- If Client cannot be reached within fifteen (15) minutes, Provider halts all testing until contact is re-established.
Emergency contact (Client): the Client emergency contact
Emergency contact (Provider): David Wolf · hello@aisecurity.llc
7. Reporting
| Deliverable | Due Date |
|---|---|
| Daily or session status notes | at the end of each testing session |
| Preliminary findings (critical severity) | within 24 hours of discovery |
| Draft report | the date confirmed during scoping |
| Client review period | five (5) business days |
| Final report | the date confirmed during scoping |
| Readout session | the date confirmed during scoping |
Reports will include: attack scenarios executed, findings with evidence, severity and exploitability notes, and mitigation guidance.
8. Severity and Escalation
| Severity | Response |
|---|---|
| Critical | Immediate notification to Client security contact. Pause testing pending acknowledgment. |
| High | Notification within 24 hours. Continue testing unless Client requests pause. |
| Medium / Low / Info | Include in report. No pause required. |
Severity is assessed by Provider based on exploitability and impact against the AI system and any downstream systems.
9. Caveats
- This engagement is time-bound and scenario-scoped. It does not guarantee exhaustive vulnerability discovery.
- Findings are limited to the authorized targets and attack techniques listed above.
- Test results reflect the state of the system at the time of testing. Changes after the engagement may affect the validity of findings.
- No certification, compliance approval, or formal audit opinion is provided.
- Public disclosure of findings requires written agreement from both parties.
10. Signatures
Testing must not begin until both parties have signed.
These materials are provided for transparency and scoping. They are not legal advice and do not replace a final signed agreement. Consult qualified legal counsel before execution.