General Engagement Framework & Security Auditing Rules of Engagement
elsiddik Cybersecurity provides offensive security auditing, penetration testing, ISO 27001 advisory, cloud security assessments, and white-label MSP subcontracting services as governed by mutually executed Statements of Work (SoW) and Rules of Engagement (RoE).
All penetration testing, adversary emulation, and vulnerability scanning activities require explicit written authorization signed by an authorized representative of the target infrastructure owner.
All client data, source code, network architecture diagrams, vulnerability findings, and executive reports are classified as strictly confidential and protected by formal Non-Disclosure Agreements (NDAs).
These terms and any security service agreements shall be governed by and construed in accordance with the laws of the Federal Republic of Germany.
We process data in accordance with German DSGVO & GDPR. We use essential security tokens to protect your session and audit requests. Learn more in our Privacy Policy and Impressum.