Skip to content
Asuruas
Legal

Authorized Testing Policy

Version authorized-testing-2026-08-09. This policy defines the authorization and safety controls required before Asuruas assesses or changes a website.

01

1. Permission is mandatory

You may assess or change only a website, application, account, or system that you own or for which the owner has given you express authorization. Authorization must cover the exact assets, activity, dates, credentials, data access, and production-change authority involved. Asuruas registration or technical reachability does not prove permission.

If you act for a client, you are responsible for keeping written evidence of the client's authorization and for producing it promptly if Asuruas reasonably requests it after a complaint, incident, or scope dispute.

02

2. Define scope before work begins

  • Identify exact hostnames, applications, environments, accounts, and exclusions; do not treat a parent domain as permission for every subdomain or third-party service.
  • Identify the approving owner, operational contact, emergency contact, permitted dates and maintenance windows, and any required advance notice.
  • Set crawl depth, concurrency, rate, response-size, timeout, authentication, and stop limits appropriate to the system's capacity.
  • Identify destructive, financial, administrative, logout, search-amplification, order, payment, and high-cost paths that must be excluded.
  • Confirm whether backups, staging, change approvals, and rollback capability are required before any production change.
03

3. Activities not authorized by default

  • Exploitation, privilege escalation, persistence, malware, denial-of-service or stress testing, credential attacks, password spraying, phishing, social engineering, or evasion.
  • Creating, changing, deleting, purchasing, publishing, emailing, messaging, or submitting production records except through an expressly approved change workflow.
  • Testing cloud accounts, hosting providers, plugins, payment providers, analytics, identity systems, customer tenants, or other third parties merely because they are connected to the approved site.
  • Accessing personal information, confidential content, secrets, source code, backups, or administrative functions beyond the minimum evidence expressly authorized.
04

4. Safe crawling and assessment

  • Use the least intrusive method that can answer the authorized question and begin with conservative limits.
  • Honor robots directives, site-owner instructions, access controls, rate limits, retry guidance, and stop conditions unless a documented authorization specifically permits an exception.
  • Do not intentionally bypass authentication, authorization, anti-automation, tenancy, or payment controls.
  • Pause immediately if the target becomes unstable, error rates materially increase, queues or storage grow unexpectedly, or a contact asks you to stop.
05

5. Credentials and secrets

  • Use dedicated, least-privilege, time-limited credentials when authenticated assessment is necessary.
  • Do not place passwords, private keys, permanent API keys, session cookies, or unencrypted shared secrets in notes, URLs, reports, screenshots, reusable headers, or support messages.
  • Rotate or revoke credentials after the authorized activity and report suspected exposure immediately.
06

6. Data minimization and evidence

Collect and retain only the evidence reasonably necessary to document a finding or verify a result. Redact credentials and unnecessary personal, financial, health, authentication, and confidential information. Do not download or retain a complete dataset when a smaller redacted sample is sufficient.

Use the workspace's access controls, export, retention, and deletion tools for evidence. Do not copy Customer Data to unapproved personal accounts or services.

07

7. Production changes

  • Production execution requires explicit authority for the specific change, an approved target and scope, and a human review of generated instructions and evidence.
  • Use staged or reversible changes where practical, verify backups and rollback instructions, define success and failure criteria, and preserve the approval and execution record.
  • Stop, roll back where safe, and escalate when the observed result differs materially from the approved plan or creates unexpected impact.
  • Automated acceptance or a successful HTTP response does not replace post-change readback and verification.
08

8. Unexpected access, exposure, or harm

Stop the affected activity, avoid further access, preserve only minimum evidence, do not disclose the information to others, and notify the authorized owner and Asuruas promptly. Do not use an unexpected vulnerability to expand scope or establish persistence.

Suspected vulnerabilities in Asuruas itself must be reported through the Responsible Disclosure page rather than tested through a customer workspace.

09

9. Third-party terms and law

You are responsible for applicable law, contracts, platform terms, professional duties, and customer instructions. This policy does not grant a legal safe harbor, waive a third party's rights, or authorize conduct that another system owner has not approved.

10

10. Records and enforcement

Asuruas may require scope or authorization evidence, throttle or cancel unsafe work, suspend a feature or account, preserve relevant records, and cooperate with an affected owner or lawful authority when reasonably necessary. Questions and incident notices may be sent to clancaster@lancastersolutionsllc.com.

Effective August 9, 2026.