// Authorization

Authorization Letter

Last updated:

This page is a public authorization checklist and copyable template, not a signed authorization and not permission to start. One fully executed agreement may authorize every bounded assessment it expressly names and schedules when it contains the applicable targets, exclusions, Rules of Engagement, test windows, stop contact, safety limits, and data terms. No separate per-assessment signature, Work Order, or human execution release is required. Anything outside that signed authorization envelope needs a signed amendment or new agreement before testing.

1. Parties and authority

The signed record identifies the customer's legal entity, asset owner, authorized signatory and contact details, together with Loki Intelligence B.V. If an agency, hosting provider or other third party is involved, the record explains each party's role and attaches the asset owner's written authorization. The signatory confirms they have authority to grant the exact permission recorded.

2. Covered-assessment identity

The agreement gives each covered assessment a unique assessment ID and records its purpose, environment, schedule or bounded test window, requested deliverables, applicable scope, Rules of Engagement and data terms, and whether it is a new assessment or scoped retest. One agreement may list multiple planned assessments. A monthly plan by itself never authorizes testing.

3. Authorized assets and exclusions

The signed record lists exact domains, subdomains, URLs, API endpoints, IP ranges, application identifiers and environments that may be tested, plus supplied test roles or accounts. It separately lists excluded hosts, third-party services, cloud accounts or resources, OT, payment execution and fragile flows. Anything not explicitly included is out of scope.

4. Window, source and stop contacts

The Rules of Engagement record the approved start and end time with timezone, any maintenance or blackout period, Loki's agreed source IPs or other test-origin identifiers, customer monitoring expectations, and a primary and backup stop contact for both parties. The stop path must allow the customer or Loki to pause testing promptly if unexpected risk appears.

5. Allowed techniques and safety limits

Allowed activities can include non-destructive discovery, authenticated checks with supplied test accounts, safe controlled validation, minimum necessary evidence collection and one scoped retest. The record sets rate limits, cost ceilings, production restrictions, prohibited data, escalation conditions and any technique-specific approval. Destructive testing, persistence, malware, denial of service, payment execution, social engineering, cloud-account or OT assessment and unsafe production changes are outside the current service and are not authorized by this template.

6. Evidence, data and reporting

The signed data terms identify what evidence may be captured, how it is minimized and redacted, where it is delivered, who may receive it, and when it is returned or deleted. Evidence may include limited screenshots, redacted requests and responses, logs, metadata and reproduction notes needed to explain a finding. Reports remain held until human review and release.

7. Signatures and release gate

The customer signatory and Loki signatory date and sign the agreement that contains the authorization record. Every execution is then immutably bound internally to one assessment covered by that agreement and claimed once. This internal execution control is not a new customer signature, Work Order, or human execution release. Findings and reports remain held until human review and publication approval.

// LOCAL TEMPLATE

Authorization-to-Test and Rules of Engagement template

Copy or download this plain-text checklist, complete it with both parties, and place the signed version with the agreement and data terms. It may cover multiple assessments when each one is expressly named and scheduled. Downloading or completing an unsigned copy does not start a test.

LOKI AUTHORIZATION-TO-TEST / RULES OF ENGAGEMENT TEMPLATE

STATUS
This is an unsigned template. It is not authorization and does not start testing.

1. PARTIES AND AUTHORITY
Customer legal name: [complete]
Registration number and address: [complete]
Asset owner, if different: [complete]
Authorized customer signatory, title and email: [complete]
Agency or other intermediary and role, if any: [complete]
Third-party or hosting approval attached, if required: [yes/no/not applicable]
Service provider: Loki Intelligence B.V., KvK 42116362
LOKI signatory and contact: [complete]

2. AGREEMENT AND AUTHORIZATION ENVELOPE
Agreement ID and version: [complete]
Effective date and term: [complete]
Commercial schedule ID and version: [complete]
Data terms / DPA ID and version: [complete]
Number of assessments authorized by this agreement: [complete]

3. COVERED ASSESSMENTS — REPEAT FOR EACH ASSESSMENT
Assessment ID: [complete]
Assessment type: [new web/API assessment or scoped retest]
Purpose and expected deliverables: [complete]
Environment: [production/staging/other]
In-scope domains, subdomains, URLs and API endpoints: [complete]
In-scope IP ranges/application IDs: [complete]
Approved test roles or accounts: [complete]
Explicit exclusions and third-party assets: [complete]
Start date/time/timezone: [complete]
End date/time/timezone: [complete]
Blackout or maintenance periods: [complete]
Approved LOKI source IPs or test-origin identifiers: [complete before execution]
Customer monitoring or allow-list instructions: [complete]

4. RULES OF ENGAGEMENT
State whether each rule applies to all covered assessments or only named assessment IDs.
Allowed techniques and validation limits: [complete]
Prohibited techniques/actions: [complete]
Rate limits and concurrency: [complete]
Cost ceiling and paid-action restrictions: [complete]
Fragile workflows, production restrictions and prohibited data: [complete]
Conditions that require pause or escalation: [complete]

5. STOP AND ESCALATION CONTACTS
Customer primary stop contact and live channel: [complete]
Customer backup stop contact and live channel: [complete]
LOKI primary and backup stop contacts: [complete]
Pause instruction and acknowledgement path: [complete]

6. EVIDENCE AND DATA
Permitted evidence categories: [complete]
Redaction or minimization requirements: [complete]
Approved delivery recipients/channel: [complete]
Retention, return and deletion instructions: [complete]
Approved providers, locations and transfer terms: [complete]

7. AUTHORIZATION GRANT
The customer confirms it owns the listed assets or holds documented authority from the asset owner and authorizes Loki Intelligence B.V. to perform every bounded assessment expressly named and scheduled in this agreement, only within its applicable scope, window, Rules of Engagement, stop contacts, safety limits and data terms. One fully executed agreement may authorize multiple assessments. No separate per-assessment signature, Work Order or human execution release is required. Anything outside this signed authorization envelope is out of scope and requires a signed amendment or new agreement before testing.

8. SIGNATURES
For the customer / asset owner
Name and title: [complete]
Signature: [sign]
Date/time/timezone: [complete]

For Loki Intelligence B.V.
Name and title: [complete]
Signature: [sign]
Date/time/timezone: [complete]

9. LOKI INTERNAL EXECUTION BINDING — NOT A CUSTOMER APPROVAL
Execution ID: [complete internally]
Covered assessment ID: [complete internally]
Signed agreement ID, version and digest: [complete internally]
Bound target, source and window: [complete internally]
Single-claim record and timestamp: [complete internally]

10. HUMAN REPORT REVIEW AND PUBLICATION
Reviewer and decision: [complete internally]
Reviewed assessment and report ID: [complete internally]
Publication decision timestamp: [complete internally]