~/legal
Authorized security testing statement
Non-negotiable boundaries for VAPT, scanning, patching, and production changes.
All security testing, scanning, patching, and production changes require written authorization, an agreed scope, and an approved change window.
BetterCallDevOps does not perform unsolicited scanning, exploitation, or production changes. Rules of engagement, emergency contacts, and in-scope assets must be documented before security work begins.
Clients are responsible for confirming legal authority over systems included in scope and for providing accurate ownership information.
Last updated: 2026-08-11