Brand logo of nubesti
  • Home
  • AI Red Team
    • Autonomous Agents

      AI-powered autonomous agents eliminate manual testing by conducting comprehensive security assessments automatically.

    • MITRE ATT&CK Coverage

      Full coverage of MITRE ATT&CK framework tactics and techniques to simulate real-world attack scenarios.

    • OWASP Top 10 Coverage

      Complete testing coverage for all OWASP Top 10 vulnerabilities including injection attacks, broken authentication, and security misconfigurations.

    • Integration

      Connect seamlessly with your existing tools and workflows.

    Experience AI Red Team Testing

    See how our autonomous AI agents identify vulnerabilities in your systems.

    Book a Demo
  • Resources
    • Pricing
    • Faq
    • Integration
    • Blog
  • Contact
    • french
    • spanish
    • portuguese
  • Sign In
  • french
  • spanish
  • portuguese
Sign In
  1. Home
  2. /
  3. Legal
  4. /
  5. Rules of Engagement

Rules of Engagement

Scope, authorization, responsibilities, and limits for Nubesti security assessments and onboarding.

Last updated: September 21, 2026

Nubesti

1111B S Governors Ave STE 23840
Dover, DE 19904, USA

[email protected]

On this page

  1. 1. Purpose
  2. 2. Authorization
  3. 3. Scope
  4. 4. Timing and communication
  5. 5. Customer responsibilities
  6. 6. Evidence and data handling
  7. 7. Limits of assistance
  8. 8. Safe harbor between the parties
  9. 9. Contact

These Rules of Engagement (“RoE”) apply when you run tests through Nubesti or when we provide onboarding or professional-services assistance. They replace “migration terms” you might see at a hosting company: our equivalent is a clear, authorized security assessment.

They supplement the Terms of Service and Acceptable Use Policy.

1. Purpose

The purpose of an engagement is to identify vulnerabilities and improve your security posture—not to cause outages, exfiltrate data for its own sake, or test systems outside the agreed scope.

2. Authorization

Before testing starts, you confirm that:

  • KYC is approved and paid for the organization and the users who will launch tests
  • You own the targets or have written authorization from the owner (use the Authorization Letter)
  • The named contacts can halt or resize the test
  • Any third-party providers (cloud, ISP, MSSP) that require notice have been notified when needed

We will not launch tests, and we may pause work, if KYC or authorization is unclear.

3. Scope

Scope is whatever you configure in the product or we list in a statement of work: URLs, APIs, IP ranges, cloud accounts, or applications.

Out of scope by default:

  • Denial-of-service or traffic floods
  • Physical security and office intrusion
  • Attacks on third-party SaaS you do not control
  • Social engineering of Nubesti staff or your employees, unless a written add-on says otherwise
  • Intentional destruction of data
  • Testing after you revoke authorization

4. Timing and communication

You should schedule high-impact tests outside critical business windows when possible. Provide an emergency contact who can be reached while tests run.

If a test causes unexpected production impact, stop it and notify both sides. Emergency halt requests from you will be honored as quickly as reasonably possible.

5. Customer responsibilities

You remain responsible for:

  • Backups and rollback plans
  • Staging vs. production decisions
  • Legal notices to your users or regulators if your program requires them
  • Reviewing findings and remediating your systems
  • Verifying that reports do not leave your control in an unsafe way

Onboarding help (connecting integrations, importing targets, walking through the portal) is provided on a commercially reasonable basis. You must validate the configuration before production use.

6. Evidence and data handling

We collect only the evidence needed to demonstrate a finding. You should avoid placing live secrets, real customer databases, or special-category data in scope unless necessary and agreed.

Findings are confidential to your organization, subject to law and the Terms.

7. Limits of assistance

We do not guarantee a particular number of critical findings, a clean report, or passage of a third-party audit. Professional-services hours unused at the end of a fixed package expire unless an order form says they roll over.

8. Safe harbor between the parties

For in-scope, authorized activity performed through the platform, Nubesti will treat the test as consented security research on your systems. This safe harbor does not cover activity you run outside Nubesti or against unauthorized targets.

9. Contact

Engagement questions: [email protected]
Security incidents involving the platform: [email protected]

Back to legal center ↗

Brand logo of nubesti

Nubesti is a cutting-edge cybersecurity platform that leverages artificial intelligence to deliver comprehensive red team operations. Our mission is to revolutionize enterprise security through autonomous AI-powered testing and advanced threat simulation.

  • facebook
  • twitter
  • instagram
  • linkedin

Quick Links

  • Pricing
  • Integration
  • AI Red Team
  • Faq

Resources

  • Blog
  • Integration

Legal

  • Legal center
  • Terms of Service
  • Privacy Policy
  • Security
  • KYC & Verification
  • Legal Notice

Subscribe to our newsletter

gats-upstart
  • Legal
  • Privacy Policy
  • Legal Notice
  • Copyright 2026
  • All Rights Reserved By Nubesti