01Compliance

Compliance and rules of engagement.

Written authority comes before any offensive work.

Updated 1 October 2026

Authority before action

Kestrel runs with prior written authorisation from a person entitled to grant it for the named systems.

The authorisation and the rules of engagement name the targets, the time window, the objectives, the methods that are out of bounds, and the emergency contact. Work outside that document stops.

A completed scoping pack, a service selection, and a quotation are not that authorisation. Work outside the lab starts only when the authorising instrument is on file and the conditions marked before activity are resolved.

The same documents name how much the tester is told: black box, grey box, or white box, including any phased change. That declaration does not replace the authorisation. A black-box test still needs named targets. Credentials are not written into the scoping pack.

What will be refused

Requests to test systems the requester does not control. Requests to “see what you can get” with no objective and no boundary. Requests that ask for denial-of-service, destruction of data, or extortion theatre. Requests that treat a third-party platform as in scope because the client has an account there, unless that third party has authorised the test in writing.

ScaryByte will also stop an engagement already underway if authority becomes unclear, if the emergency contact cannot be reached when the rules say they must, or if continuing would break the law.

Evidence and personal information

An engagement can encounter personal information inside a target environment. The rules of engagement say what is collected as proof, what is minimised, and how long evidence is kept. Proof is limited to what shows the path.

If the work uncovers signs of a real incident, the client’s own legal duties still apply, including any notice the client must give. Kestrel does not take over those duties by finding the issue.

The deliverable

The deliverable is the engagement record: the path, the proof, and the readout. Certificates, attestation letters, and control-framework reports sit outside that record.

Clients remain responsible for their own laws, contracts, and notifications. ScaryByte is responsible for staying inside the agreed rules and for the quality of the evidence.

Operator

Kestrel.ICU is developed and operated by ScaryByte.

The programme

05Developer

Kestrel.icu is developed by ScaryByte.

Contact ScaryByte
ScaryByte
Loading Kestrel.icu