Skip to main content
Protegon

Authorized scanning policy

Use of the platform is strictly limited to assets and infrastructures for which you have an explicit right to test. This requirement is essential to comply with applicable laws on information security and system protection.

1. General principle

Before starting any scan, you must ensure that you own the target domain, system, or application, or that you hold valid written authorization from the legitimate owner.

Use of the platform against unauthorized targets is prohibited and may expose you to civil and criminal liability.

2. Permitted cases

You may run scans when one of the following applies:

  • You hold the domain name or are an authorized representative of the owning entity.
  • You act as a contractor with a current agreement that explicitly covers security testing.
  • You have a purchase order, mission order, or amendment stating the technical scope, duration, and purpose of the scans.

To reduce legal risk and support audits, we recommend keeping the following records:

  • Signed master or service agreement including a security testing clause.
  • Scope document (domains, subdomains, IPs, applications) approved by the client.
  • Written approval from the business owner or CISO for the testing window.
  • Incident contact details at the client organization.

In a B2B context, the following clauses are recommended to protect you legally:

  • Explicit authorization to run technical tests on the defined scope.
  • Limitation of liability and cooperation clause in case of incident.
  • Confidentiality and secure handling of results.
  • Notification clause if a critical vulnerability is identified.

5. User responsibility

Checking the attestation box before a scan constitutes a declaration on your honor that you are permitted to test the target.

The platform does not replace your obligation to verify legal prerequisites. If in doubt, consult legal counsel or your organization’s compliance team.

Summary

Our goal is to provide a secure, professional testing framework. Following this policy protects system owners, your teams, and your organization.

Authorized scanning policy | Protegon