aisecurity.llc
hello@aisecurity.llc
Legal Agreement · Negotiation Draft
Penetration Test & Red Team Rules of Engagement
Rules of engagement for scoped penetration testing and adversarial red team work — authorization, targets, allowed and prohibited techniques, testing window, access plan, evidence handling, emergency stop, and reporting. Covers web/API, cloud, authenticated, business-logic, and AI/agentic testing.
1. Engagement Summary
| Field | Value |
|---|---|
| Client | Client |
| Provider | aisecurity.llc |
| Engagement Name | the engagement agreed during scoping |
| Engagement Type | as specified in the applicable SOW |
| Related SOW | the applicable Statement of Work |
| Test Window | the engagement start date confirmed during scoping to to be specified during scoping |
| Client Security Contact | the Client security contact |
| Provider Test Lead | David Wolf · hello@aisecurity.llc |
This Rules of Engagement document governs scoped security testing, which may include web/API/application penetration testing, cloud/infrastructure testing, authenticated and business-logic testing, adversarial red team activity, and AI/agentic red teaming, as identified in the Statement of Work.
2. Authorization
Testing proceeds only against systems the Client owns, controls, or is explicitly authorized to assess. The Client confirms, by signing below, that it has the authority to authorize testing of every target listed in Section 3 and that any third-party-owned target has separate written authorization on file.
Where the targets include cloud infrastructure or third-party platforms, the Client is responsible for confirming that testing is permitted under the applicable provider terms and for completing any provider notification or approval process. See the Cloud Testing Boundary Addendum where applicable.
3. Authorized Targets
Testing is authorized against the following targets only:
- The specific AI systems, endpoints, models/providers, RAG corpora, and agent workflows enumerated and confirmed in writing during scoping.
- No system, endpoint, account, or data source outside that confirmed list is in scope.
Any system, endpoint, account, network range, or data source not listed here is out of scope. Discovery of an unlisted asset does not authorize testing of it.
4. Authorized Techniques
The following technique families are authorized within safe limits:
- Prompt injection (direct and indirect)
- Jailbreak and policy-bypass attempts
- Context-window manipulation
- RAG corpus poisoning simulation (read-only unless separately authorized)
- Tool misuse and function-call abuse
- Unsafe action-path exploration
- Output-handling and data-exfiltration-via-output testing
- Agent goal hijacking
- Additional technique families only as confirmed in writing during scoping
Prohibited Actions
The following are prohibited regardless of technical capability, unless separately authorized in writing (and, where applicable, under the Special Approval Addendum):
- Accessing, modifying, exfiltrating, or destroying production data not in the authorized targets
- Attacking systems, endpoints, or accounts not in the authorized targets
- Social engineering of Client personnel unless separately authorized
- Denial of service or load testing unless separately authorized
- Introducing persistent artifacts (backdoors, modified prompts) into any environment
- Sharing test artifacts, prompts, or findings outside the named delivery contacts
- Publishing or referencing Client systems or findings without written consent
5. Testing Window and Scheduling
| Window | Dates / Times |
|---|---|
| Primary test window | the period confirmed in the applicable SOW |
| Authorized testing hours | the agreed testing hours |
| Blackout dates | any blackout dates identified by the Client |
| Coordination cadence | an agreed coordination cadence |
Provider notifies the Client security contact at the start and end of each active testing session.
6. Access Plan
- Access is provisioned by the Client through an approved secure channel after this document and the related NDA/SOW are signed.
- Credentials, keys, and tokens are never exchanged through public forms or email; they are delivered through the agreed secure channel.
- Authenticated and role-based testing uses Client-provided test accounts for the roles identified during scoping.
- Tester source addresses are allowlisted by the Client where required; Provider supplies the allowlist on request.
7. Evidence and Data Handling
- All test artifacts (requests, outputs, screenshots, logs) are treated as confidential Client information.
- Evidence is stored in an access-controlled, encrypted store available only to named delivery contacts accessible only to named delivery contacts.
- Outputs containing secrets or sensitive data are masked or redacted before inclusion in reports.
- Evidence is retained for 30 days or until final delivery, whichever is later and then deleted or returned per Client instruction.
- Provider does not use test artifacts to train AI models or for any purpose beyond this engagement. See the Evidence Handling Policy.
8. Emergency Stop Procedure
If testing causes unexpected production impact, discovery of a critical exposure, or exposure of regulated data:
- Provider immediately stops all test activity and notifies the Client stop-testing contact via the agreed secure channel.
- The Client contact confirms receipt within fifteen (15) minutes.
- Both parties jointly assess impact before testing resumes.
- If the Client cannot be reached within fifteen (15) minutes, Provider halts all testing until contact is re-established.
Emergency / stop-testing contact (Client): the Client emergency contact
Emergency contact (Provider): David Wolf · hello@aisecurity.llc
9. Communication, Severity, and Reporting
| Severity | Response |
|---|---|
| Critical | Immediate notification to the Client security contact. Pause testing pending acknowledgment. |
| High | Notification within 24 hours. Continue testing unless the Client requests a pause. |
| Medium / Low / Info | Included in the report. No pause required. |
Reports include scenarios executed, findings with evidence, severity and exploitability notes, and remediation guidance. Retesting of remediated findings is available where agreed in the SOW.
10. Caveats
- This engagement is time-bound and scope-bound. It does not guarantee exhaustive vulnerability discovery.
- Findings are limited to the authorized targets and techniques listed above.
- Results reflect the state of the systems at the time of testing. Later changes may affect the validity of findings.
- No certification, compliance approval, or formal audit opinion is provided.
- Public disclosure of findings requires written agreement from both parties. See the Publication & Claim-Readiness Policy.
11. Signatures
Testing must not begin until both parties have signed.
These materials are provided for transparency and scoping. They are not legal advice and do not replace a final signed agreement. Consult qualified legal counsel before execution.