These terms govern how Apex Offensive engages. They exist to keep the work lawful, and to protect both sides of the engagement.
We conduct security assessments exclusively on systems, networks and applications that you own, or for which you have obtained explicit written authorisation from the system owner. A signed scope of work is required before any testing begins. We do not access, probe or test any system without documented consent.
Every engagement runs on a scope of work, a written authorisation signed by the system owner, and an agreed set of rules of engagement covering permitted techniques, testing windows, escalation contacts and evidence handling. Testing does not start until all three exist.
By engaging Apex Offensive you warrant that you own, or have obtained explicit written authorisation to test, every system in the agreed scope. That includes approvals required from cloud providers, hosting partners and third-party vendors. You will identify production systems and any out-of-scope assets before work starts.
We do not access accounts or systems without the owner's consent, monitor or surveil individuals, recover access to accounts that are not yours, alter records held by another party, trace or retaliate against an attacker, or undertake any activity that would breach the Computer Fraud and Abuse Act, the Computer Misuse Act, or equivalent legislation. Requests of that kind are declined and receive no reply.
Engagements are quoted as a fixed fee after a scoping call, and that fee does not change during the project. We do not bill hourly and we do not raise change orders against an agreed scope.
We sign your non-disclosure agreement as standard, report findings only to you, and destroy evidence and findings once the project closes.