ANNEX 2 Example Pentest Waiver

(Full Client Name) (“(Client)”), with its registered office at Somestreet, Somecity, Earth, Milkyway, and duly represented by (Client's CISO)

WHEREAS:

A. (Client) wants some of its systems tested, (“”) has offered to perform such testing for (Client) and (Client) has accepted this offer. The assignment will be performed by 's core-team members, external freelancers, and/or volunteers (the “Consultants”).

B. Some of the activities performed by and the Consultants during the course of this assignment could be considered illegal, unless (Client) has given permission for these activities. and the Consultant will only perform such activities if they have received the required permission.

C. (Client) is willing to give such permission to , the Consultants, and any other person might employ or engage for the assignment.

DECLARES AS FOLLOWS:

1. (Client) is aware that will perform penetration testing services on the (Client)'s following systems, as described below. The services are intended to gain insight in the security of these systems. To do so, will access these systems, attempt to find vulnerabilities, and gain further access and elevated privileges by exploiting any vulnerabilities found. will test the following targets (the “Targets”):

2. (Client) hereby grants and the Consultants on a date to be confirmed by email the broadest permission possible to perform the assignment, including the permission to:

a. enter and use the Targets;

b. circumvent, breach, remove, and turn off any security measures protecting the Targets;

c. copy, intercept, record, amend, delete, and render unusable or inaccessible any data stored on, processed by, or transferred via the Targets; and

d. hinder the access or use of the Targets,

but (Client) only grants the permission for these activities to the extent that (i) such activities are necessary to perform the assignment and (ii) such activities do not disrupt the normal business operations of (Client).

3. The permission under Article 1 extends to all systems on which the Targets run, or which or the Consultant might encounter while performing the assignment, regardless of whether these systems are owned by third parties.

4. (Client) warrants that it has the legal authority to give the permission set out under Articles 1 and 2. It also warrants it has obtained the necessary permissions from any third parties referred to under Article 3.

5. Should the public prosecutor initiate an investigation or criminal proceedings against or any of the consultants it engaged or employed as a result of the performance of the assignment for the customer, then (Client) will co-operate fully with in defending against this investigation or proceedings, including by providing any evidence it has which relates to this investigation or these proceedings.


Signed on __________________________________
in __________________________________
by __________________________________
for (Full Client Name)