01
Written authority
The customer must identify the asset owner and provide written authority sufficient for the defined testing activity. Connected third-party systems are excluded unless separately authorized.
AUTHORIZED SECURITY VALIDATION
Requesting access starts a scope discussion. It does not authorize testing. Active validation begins only after written authorization, explicit target boundaries, and Rules of Engagement are accepted.
01
The customer must identify the asset owner and provide written authority sufficient for the defined testing activity. Connected third-party systems are excluded unless separately authorized.
02
Domains, IP ranges, APIs, applications, cloud resources, repositories, identities, testing windows, allowed methods, impact limits, and escalation contacts are recorded before active probing.
03
Anything not expressly included is out of scope. If target, method, timing, or authority becomes ambiguous, testing stops until the boundary is clarified in writing.
TESTING BOUNDARY
Depending on the executed scope, authorized validation can include web and API behavior, tenant isolation, TLS and configuration posture, AI-agent tools and approval gates, repository/configuration exposure, infrastructure exposure, evidence capture, remediation guidance, and retest.
Login attempts, fuzzing, exploit proof beyond minimal validation, authentication bypass, extraction, persistence, pivoting, disruption, or social engineering require explicit written permission when permitted at all. Cold intrusion, credential theft, credential stuffing, covert persistence, and out-of-scope extraction are not implied by a public request.
AUTHORITY
These are customer-facing website terms. The internal testing authority, engagement-control logic, and Rules of Engagement requirements are maintained by FANG inside BASILISK. BLACKBOX SYSTEMS may preserve evidence and verification material produced by an authorized engagement, but BLACKBOX does not grant testing authority.
A security finding, remediation retest, or evidence packet is not a certification that a system is free of vulnerabilities.