These terms govern how Cipher Bridge engages. They exist to keep the work lawful, and to protect both sides of the engagement.
We conduct security assessments exclusively on systems, networks and applications that you own, or for which you have obtained explicit written authorisation from the system owner. A signed scope of work is required before any testing begins. We do not access, probe or test any system without documented consent.
By engaging Cipher Bridge you warrant that you own, or have obtained explicit written authorisation to test, every system in the agreed scope. That includes approvals required from cloud providers, hosting partners and third-party vendors. You will identify production systems and any out-of-scope assets before work starts.
The learning material published here is general information, not legal advice and not a licence to test anything. Practise only on systems you own, on a lab you built, or on platforms that explicitly invite testing. Pointing tools at a system you were not invited to test may be a criminal offence even where no damage results.
We do not access accounts or systems without the owner's consent, monitor or surveil individuals, recover access to accounts that are not yours, alter records held by another party, trace or retaliate against an attacker, or undertake any activity that would breach the Computer Fraud and Abuse Act, the Computer Misuse Act, or equivalent legislation. Requests of that kind are declined and receive no reply.
We sign your non-disclosure agreement as standard, report findings only to you, and destroy evidence and findings once the project closes.