What this page is
This page describes GreyNod Labs' general approach to vulnerability assessment and penetration testing (VAPT). It is not an authorisation. A VAPT engagement happens only under a project-specific agreement and a signed written authorisation, which together set the real scope and rules for that engagement and take priority over this page.
Written authorisation first
We do not begin testing until we hold written authorisation from the owner of every system in scope. You confirm that you own the systems, or are authorised to instruct us to test them, including systems operated by hosting or platform providers where their rules require notice or approval.
What the scope document records
- the targets in scope, such as domains, applications, APIs or network ranges;
- the testing window;
- the methods and techniques that are permitted, and the accounts or access we will use;
- exclusions;
- emergency contacts for both sides;
- stop conditions, which say when testing must pause or end.
Your responsibilities
- Give accurate scope information and the access we need, such as test accounts, VPN or network access, and documentation.
- Make sure the right people know when testing is happening, and be reachable on the agreed emergency contact.
- Take backups, and tell any providers who need notice.
- Review the report and arrange remediation of any issues found.
Excluded unless separately authorised in writing
- Denial-of-service and load testing.
- Phishing and other social engineering.
- Destructive actions, such as deleting or corrupting data.
- Persistence, meaning leaving access behind, and malware.
- Physical testing.
- Third-party systems that are not covered by the authorisation.
How we test
Depending on the authorised scope, we combine manual testing and verification with automated tools such as Burp Suite, Nmap, Nuclei, OWASP ZAP, Nessus and SQLmap, and other suitable tools. Not every tool is used in every engagement. We aim to keep our impact on your systems and our access to sensitive data to the minimum needed to verify a finding.
Stop conditions and incident escalation
We pause and contact you straight away if we see signs of a live compromise or an unrelated incident, if we reach data outside the agreed scope or sensitive data we did not expect, or if our testing appears to be affecting a system's availability. We resume only when you confirm. Critical findings may be reported to you before the final report, so you can act quickly.
Evidence handling
We keep evidence to what is needed to demonstrate each finding, avoid copying sensitive data where possible, and treat all evidence as confidential. How long evidence is kept, and how it is deleted or returned, is agreed in the engagement documents.
Reporting
Our reports contain verified findings with supporting evidence, a severity rating where it can be justified, the impact, and recommended remediation. We can explain the findings to your developers.
Remediation and retesting
Fixing the issues is your responsibility, and we can advise. Retesting to check that fixes work is optional, is agreed separately, and is not automatically included.
Limitations
A VAPT engagement covers the agreed scope at a particular point in time. It reduces risk, but we cannot guarantee that all vulnerabilities will be found, or that your systems cannot be compromised afterwards. New vulnerabilities can appear as systems change.
Commercial terms are in our Terms of Service and your quotation. To discuss an engagement, contact greynodlabs@gmail.com.
