// Authorization

Authorization Letter

Last updated:

This authorization baseline documents the permission model Loki needs before testing. The submitted scope, payment record, and any signed statement of work should be kept together as the engagement record.

1. Authorization grant

The customer authorizes Loki Intelligence to perform security testing against the scoped systems for the limited purpose of identifying, validating, documenting, and helping remediate security weaknesses.

2. Authorized targets

Authorized targets are the domains, URLs, accounts, APIs, cloud resources, and environments submitted through onboarding or confirmed in writing. Any asset not listed or clearly covered by the confirmed scope is out of scope.

3. Allowed activities

Allowed activities may include discovery, authenticated checks using test-owned accounts, configuration review, controlled exploit validation, report evidence collection, and retesting. Destructive actions require explicit written permission.

4. Customer commitments

The customer confirms that testing will not violate third-party rights, hosting policies, or internal restrictions, and that escalation contacts can pause testing if unexpected risk appears.

5. Boundaries

Loki will avoid persistence, malware, customer data extraction beyond evidence needs, denial-of-service testing, payment execution, social engineering, and unsafe production changes unless explicitly approved in a separate written scope.

6. Evidence and reporting

Loki may capture limited screenshots, requests, responses, logs, metadata, and reproduction notes required to explain findings. Evidence is shared through the agreed report or customer portal and should be treated as confidential.