Authorization & Safety

Authorization & Safety

SiegePoint never tests without written authorization. Two documents govern every engagement:

The guardrail layer

A guardrail layer keeps authorized testing from becoming an actual incident: destructive actions require an explicit, named approval; social-engineering "actions" (rung S3) run only inside an agreed, reversible blast radius; and the Authorization Ceiling is a hard stop the tester will not cross. Voice-based testing defaults to dry-run and is limited to consented, allowlisted numbers.

The template authorization letter and SOW/MSA clauses provided in an engagement are starting points. Your attorney and insurer should review them before signature.