01Purpose and scope
This policy applies to vulnerability reviews, authorised penetration testing, malware response, security hardening, phishing and spoofing response, spam mitigation, impersonation reporting, account recovery, incident response and related cybersecurity services supplied by TT Design & Concepts.
It supplements the quotation, statement of work and Company Terms. The specific written scope controls the authorised targets, methods, dates and deliverables.
02Proof of ownership or authority
Before work begins, the client must show that it owns the target or has permission from the owner to request the service. Evidence may include domain or DNS control, hosting access, company records, platform ownership information, an authorisation letter or confirmation from an authorised officer.
TT may contact the named owner, hosting provider or platform where verification is reasonably necessary. Refusal or inconsistent evidence may cause the request to be declined.
03Written scope and rules of engagement
The parties should document:
- Domains, applications, accounts, networks, devices, APIs or identities included and excluded.
- Testing window, time zone, emergency contacts and stop conditions.
- Allowed techniques and prohibited techniques.
- Data-handling rules, backup status and operational constraints.
- Whether production testing, social engineering, phishing simulation, denial-of-service or destructive testing is expressly authorised. These activities are excluded unless specifically agreed.
- Reporting format, retest scope and confidentiality requirements.
04Permitted defensive work
Subject to the written scope, TT may perform defensive activities such as configuration review, vulnerability scanning, controlled validation, authentication and access-control testing, WordPress/WooCommerce hardening, malware investigation, recovery readiness, phishing analysis, domain and email-authentication review, SPF/DKIM/DMARC setup, spam-abuse containment and platform takedown support.
05Prohibited instructions
TT does not provide unauthorised access, credential theft, interception, malware deployment, harassment, data destruction, hacking-back, retaliatory spoofing/phishing/spam, service disruption, surveillance without lawful authority, or evasion of platform or law-enforcement controls.
“Counter attack” means lawful defenceTT may help block, contain, preserve evidence, report abuse, request takedown, recover an authorised account and harden systems. It does not mean attacking another person’s system.
06Account recovery and impersonation
For social-media, email, website or business-account recovery, the client must be the account owner or authorised representative. TT may help organise evidence, secure connected accounts, complete official platform recovery steps, report impersonation and monitor post-recovery risk.
TT will never ask the client to surrender a payment PIN, bank OTP or unrelated private account. Platform decisions, response times and recovery outcomes are controlled by the relevant provider and cannot be guaranteed.
07Testing safety and operational risk
Security testing can cause alerts, temporary instability, lockouts or performance impact. The client is responsible for current backups, stakeholder notification and authorisation from hosting, cloud or third-party providers where required. TT will use reasonable care, follow agreed stop conditions and report material unexpected impact promptly.
08Evidence, credentials and personal data
Share only the minimum information needed. Use an approved secure channel for credentials or evidence. TT may redact reports, encrypt working files, restrict access and delete temporary credentials after the engagement.
Security evidence may include logs, screenshots, account identifiers, malicious messages and technical records. It will be used for the authorised service, incident handling, legal obligations and dispute resolution in line with the Privacy Policy.
10Findings, disclosure and takedowns
Reports are confidential to the authorised client unless disclosure is required by law or agreed for responsible vulnerability disclosure. TT may coordinate with a vendor, host, registrar, social platform or law-enforcement body where the client authorises it or where law permits or requires action.
Public disclosure, press statements, naming suspected attackers or contacting third parties will not be done on the client’s behalf unless specifically agreed.
11Fees, timelines and no guarantee
Cybersecurity quotations are based on scope, urgency, system size, evidence quality and risk. Emergency work, after-hours response, third-party fees and expanded scope may cost more. No service can guarantee that every vulnerability will be found, that an account will be recovered, that an attacker will be identified or that a third party will complete a takedown.
12Suspension and termination
TT may pause or terminate the engagement if authorisation is uncertain, instructions become unlawful, the client requests activity outside scope, required safety conditions are absent, invoices are overdue, or continued work creates unacceptable risk. TT may preserve records necessary to explain or defend that decision.
13Client authorization statement
Before production work begins, the client should sign or electronically accept a statement substantially similar to the following:
AuthorizationI confirm that I own or am authorised to act for the systems, accounts and assets identified in the statement of work. I authorise TT Design & Concepts to perform only the listed defensive activities during the agreed period. I understand the operational risks, will maintain backups, and will not use the service or findings for unauthorised access, retaliation or unlawful activity.
The WordPress cybersecurity enquiry form should capture this confirmation as a required checkbox, but a checkbox does not replace a detailed signed rules-of-engagement document for higher-risk testing.