Security Boundaries & Ethical Charter
Cybersecurity assessments demand absolute ethical discipline. SurfaceShield operates under an uncompromised ethical charter designed to safeguard your uptime, data privacy, and legal integrity.
- ✓Passive DNS resolution & WHOIS correlation
- ✓Rate-limited TCP/UDP port probing on agreed IPs
- ✓Web application header & cookie configuration review
- ✓Email SPF, DKIM, and DMARC record verification
- ✓Publicly exposed directory & file disclosure checks
- ×Denial-of-Service (DoS / DDoS) testing
- ×Social engineering, phishing, or pretexting staff
- ×Physical security or lock bypassing
- ×Destructive payloads or data manipulation
- ×Probing unauthorized third-party infrastructure
Explicit Written Authorization
Security testing is only initiated after both parties have executed a legally binding Authorization to Test agreement specifying in-scope targets, authorized IP ranges, and designated testing windows.
Non-Destructive Methodology
We strictly perform observational, read-only reconnaissance and non-destructive service queries. We do not perform denial-of-service tests, corrupt databases, or compromise production availability.
Strict Scope Adherence
We never cross defined perimeter boundaries. If a client uses multi-tenant cloud software, we only inspect the client's direct configuration, never third-party provider infrastructure without consent.
Data Minimization & Encryption
When capturing technical evidence, we record only the minimum bytes required to prove the vulnerability (e.g. HTTP status headers or masked configuration text). All evidence is stored on encrypted storage.
Mandatory Data Destruction (60-Day Policy)
All client test notes, raw HTTP captures, and finding draft files are cryptographically shredded 60 days following the completion of post-remediation verification.
Strict Confidentiality & Non-Disclosure
SurfaceShield never publishes, sells, or references client assessment outcomes, vulnerabilities, or identities in marketing materials without express, uncoerced written permission.
If during the course of an authorized assessment we identify an undisclosed zero-day vulnerability in third-party commercial software powering your perimeter, we coordinate responsibly with the affected vendor through an appropriate vulnerability disclosure process before any public discussion.
Questions Regarding Our Rules of Engagement?
We provide our complete bilateral legal agreement for your legal counsel to review prior to any assessment commitment.