Last updated 2026-09-15
Terms
These terms
These govern use of the ClearPenTest website and customer portal. A penetration testing engagement is governed by its own agreement and its rules of engagement, which take precedence over anything here for the testing work itself.
Testing authorization
We test a system only where someone with authority over it has authorized it in writing. When you sign a testing authorization through the portal, you are confirming that you have that authority for every system you have placed in scope.
You must not place in scope any system you do not own or control. Third party platforms, hosted services and infrastructure belonging to someone else are governed by their terms, not yours, and authorizing us to test them is not yours to give.
If any of that turns out not to be true, we will stop testing.
Reports
A report we deliver is yours. You may share it with your auditors, your customers and your advisors.
A report is a description of how to compromise your systems. We recommend sharing the redacted summary rather than the full report outside your organization, and keeping the distribution list for the full report short and deliberate.
What testing does not guarantee
A penetration test is a time-boxed assessment of a defined scope. It establishes what a tester found in the time available against the systems in scope. It does not establish that no other vulnerability exists, and no honest assessment claims otherwise.
A report is evidence of what was tested and what was found. It is not a certification, and it is not a warranty about the security of your systems.
The website
Content on this site describes published standards and regulations. It is written carefully and sourced to the issuing bodies, and it is not legal or compliance advice. Confirm your obligations with your auditor or counsel.
Where a rule is proposed rather than in force, the page says so. Standards change; a page reflects what we understood at the date shown on it.
Questions about this page: hello@clearpentest.com