// Authorization
Authorization Letter
Last updated:
This authorization baseline documents the permission model Loki needs before testing. The submitted scope, payment record, and any signed statement of work should be kept together as the engagement record.
1. Authorization grant
The customer authorizes Loki Intelligence to perform security testing against the scoped systems for the limited purpose of identifying, validating, documenting, and helping remediate security weaknesses.
2. Authorized targets
Authorized targets are the domains, URLs, accounts, APIs, cloud resources, and environments submitted through onboarding or confirmed in writing. Any asset not listed or clearly covered by the confirmed scope is out of scope.
3. Allowed activities
Allowed activities may include discovery, authenticated checks using test-owned accounts, configuration review, controlled exploit validation, report evidence collection, and retesting. Destructive actions require explicit written permission.
4. Customer commitments
The customer confirms that testing will not violate third-party rights, hosting policies, or internal restrictions, and that escalation contacts can pause testing if unexpected risk appears.
5. Boundaries
Loki will avoid persistence, malware, customer data extraction beyond evidence needs, denial-of-service testing, payment execution, social engineering, and unsafe production changes unless explicitly approved in a separate written scope.
6. Evidence and reporting
Loki may capture limited screenshots, requests, responses, logs, metadata, and reproduction notes required to explain findings. Evidence is shared through the agreed report or customer portal and should be treated as confidential.