aisecurity.llc
hello@aisecurity.llc
Legal Agreement · Negotiation Draft
Special Approval Addendum
Explicit authorization gate for high-impact activities (DoS/stress, phishing, social engineering, physical, malware/C2, third-party/shared-tenant). Excluded from standard scope unless signed here and separately approved.
1. Purpose
Some testing activities carry elevated impact or legal sensitivity and are therefore excluded from standard scope. This addendum is the single place where such activities, if any, are explicitly authorized for engagement the engagement agreed during scoping under the applicable Statement of Work.
If this addendum is not signed, none of the activities below are authorized, regardless of anything implied elsewhere.
2. Special-Approval Activities
The following activities are authorized only where marked and only within the stated limits:
- No special-approval activities are authorized unless explicitly listed and marked here during scoping.
- Any activity not marked as authorized remains prohibited regardless of technical capability.
Standard exclusions that remain in force unless separately authorized include:
- Denial-of-service, stress, or protocol-flooding testing
- DNS zone walking and large-scale enumeration that could degrade service
- Social engineering and phishing of Client personnel
- Physical testing
- Malware, command-and-control (C2) simulation, and persistence
- Third-party or shared-tenant testing
- Any activity with a realistic possibility of production disruption
3. Conditions for Authorized Special Activities
For any activity authorized above:
- The Client confirms it has the authority to authorize the activity, including any third-party or provider approvals required.
- The activity is confined to the authorized targets, the agreed window, and the stated limits.
- A named Client contact is reachable throughout the activity for immediate stop.
- Evidence handling, retention, and deletion follow the Rules of Engagement and the Evidence Handling Policy.
- Provider may decline or pause any authorized special activity if it observes unexpected impact.
4. Warning
These activities can affect availability, third parties, and personnel. They are documented here precisely so that nothing high-impact happens by assumption. Anything not explicitly marked as authorized is prohibited.
5. Signatures
Client (authorizing the marked special activities):
Signature: ______________________________ Name: ______________________________ Title: ______________________________ Date: ____________
Provider (aisecurity.llc):
Signature: ______________________________ Name: David Wolf Title: Principal Date: ____________
These materials are provided for transparency and scoping. They are not legal advice and do not replace a final signed agreement. Consult qualified legal counsel before execution.