Ir al contenido
GNSIT · CYBERWORKERS AI

Penetration Testing Authorization

Rules of Engagement — please complete before any testing begins

Why this form exists. The techniques used in a penetration test are, without your written consent, indistinguishable from a real attack and unlawful. Your authorization, with a clearly defined scope, is what makes the engagement legitimate — and protects both of us.

It takes about 10 minutes. Nothing is tested until you receive and sign the final authorization document we prepare from your answers. You can stop the test at any moment with a phone call.

1. Client and Contacts

2. What May Be Tested

Tick every type you approve. Anything left unticked will not be performed.
Unannounced testing also measures how your team and monitoring detect and respond.

3. Scope

One per line. Anything not listed here will NOT be tested, even if we discover it.
For example: clinical imaging server, practice management system during clinic hours, point-of-sale during business hours, backup appliances.
Where systems are hosted by someone else, their rules also apply. GNSIT will confirm what is required.
If yes, we record only proof that access was possible — never copies of records.

4. When

For example: payroll runs, month-end close, surgery days, seasonal peak, holidays.

5. Permitted Techniques

We always use the least disruptive method that proves a finding.

6. Safety and Consent

Testing does not begin without this.
All five must be ticked before we can proceed.
This form records your intent. We then send the final authorization document for electronic signature — testing starts only after it is signed.

GNSIT LLC / CyberWorkers AI — marekg@cyberworkers.ai · +1 646-239-6680. This authorization can be withdrawn in writing at any time.