Core principle
LawKade Security will only perform active security assessment, testing, scanning, or investigation activity against targets for which we hold documented, signed authorization from the owner or authorized representative of those assets.
This principle is not a legal formality. It is the foundation of our operating model. Unauthorized security testing — regardless of intent — causes real harm to individuals, organizations, and broader infrastructure. We will not perform it, facilitate it, or look the other way when it is proposed.
What authorization means
For any LawKade engagement involving active assessment activity, authorization must include:
- Written documentation signed by the asset owner or their authorized representative
- Explicit identification of in-scope targets — domains, IP ranges, cloud accounts, or systems
- Explicit identification of out-of-scope systems and prohibited techniques
- An approved testing window specifying start and end times
- Emergency contact procedures and stop-work authority
- Data-retention and handling agreement for assessment findings and evidence
Technical enforcement
Authorization requirements are enforced technically in the ARGUS platform, not only contractually.
- Every target submitted to an assessment job is validated against the approved scope before dispatch
- Private network ranges, loopback addresses, and cloud-metadata endpoints are blocked at the platform level
- Scan jobs cannot be dispatched if the engagement is in a non-approved state
- All activity is attributed to a LawKade-operated infrastructure node with logged timestamps and actor identity
- Emergency stop capability is available at all times to both client and LawKade analyst
When we decline
LawKade will decline any engagement, request, or instruction that would require us to perform active assessment activity without documented authorization, to target systems outside an approved scope, or to facilitate unauthorized access to systems or data. This applies without exception, regardless of the stated purpose or the identity of the requester.
Questions
Questions about authorization requirements for a specific engagement should be directed to your assigned LawKade analyst or through our contact form.