BrokenIntent

Legal

Testing Policy

Last updated: June 11, 2026

This page describes how we test — the rules we follow on every engagement and in the free scanner. It exists so that your security lead, compliance owner, and legal team can all see the same answer.

Authorization first, always

  • We test only with written authorization, against a scope defined and signed before kickoff.
  • Scope changes mid-engagement require explicit sign-off — we never “wander” into adjacent systems.
  • Third-party-hosted assets are included only when you confirm you are entitled to have them tested.

The free scanner

  • Passive and non-intrusive: it inspects publicly observable signals — response headers, TLS configuration, exposed metadata. It does not exploit, brute-force, or attempt to bypass authentication.
  • It requires you to confirm you are authorized to scan the domain, and it is rate-limited to prevent abuse.

Production-safe by default

  • No destructive payloads, no data deletion or modification beyond agreed proof-of-concept markers.
  • Denial-of-service testing is excluded unless explicitly contracted and scheduled.
  • Potentially disruptive checks (mass enumeration, race conditions, anything load-bearing) are coordinated with you in advance and can be scheduled into agreed windows.
  • We prefer dedicated test accounts and environments where they exist; we work production-safe where they don’t.

During the engagement

  • Critical findings don’t wait for the report. If we confirm something actively dangerous, we notify your designated contact immediately.
  • You get an emergency-stop contact: say the word and testing halts.
  • All testing traffic can be source-identified on request so your team can distinguish us from a real attack.

Data handling

  • We collect the minimum evidence needed to prove each finding — proof of access, not bulk data.
  • Findings, evidence, and reports are confidential, access-controlled, and shared only with your named contacts.
  • An NDA is standard; engagement data is retained or destroyed per the engagement contract.

Methodology

Testing follows established frameworks — OWASP Top 10 and ASVS, OWASP LLM Top 10 for AI systems, PTES, NIST SP 800-115, MITRE ATT&CK — executed by OSCP / OSWE-certified researchers with AI-led breadth testing. Every finding is manually validated before it reaches you, with a proof-of-concept and a fix path. Fixes are retested free until closed.

Questions

Security teams and auditors are welcome to ask for more detail: hello@brokenintent.com.