1. Requirement of Written Authorization
Under no circumstances does SurfaceShield Security perform security testing, port scanning, or vulnerability evaluation without a fully executed, bilateral Authorization to Test and Rules of Engagement agreement signed by an authorized corporate representative of the client.
2. Scope Boundaries and Authority
The client warrants that it possesses the requisite ownership, legal authority, and permissions to authorize security evaluation of all domain names, hostnames, IP addresses, and services specified in the agreed Target Schedule.
SurfaceShield shall not be held liable for testing systems that were improperly represented by the client as owned or authorized.
3. Non-Destructive Standard of Care
SurfaceShield exercises professional diligence to perform observational, non-destructive evaluations. However, external assessments involve interacting with live network protocols. While outages are extraordinarily rare due to polite rate limits, the client acknowledges that security testing inherently carries non-zero risk on fragile legacy systems.
4. Independent Assessment & Limitations
An external exposure assessment represents a point-in-time observational evaluation of authorized public perimeters. It does not constitute a guarantee of invulnerability, an internal network audit, or a warranty against all future cyber threats or zero-day exploits.
5. Governing Law & Dispute Resolution
All engagement agreements, confidentiality stipulations, and services provided by SurfaceShield Security shall be governed by the standard commercial laws and jurisdiction designated in the bilateral engagement schedule.