Rules of Engagement
Scope, authorization, responsibilities, and limits for Nubesti security assessments and onboarding.
Last updated: September 21, 2026
These Rules of Engagement (“RoE”) apply when you run tests through Nubesti or when we provide onboarding or professional-services assistance. They replace “migration terms” you might see at a hosting company: our equivalent is a clear, authorized security assessment.
They supplement the Terms of Service and Acceptable Use Policy.
1. Purpose
The purpose of an engagement is to identify vulnerabilities and improve your security posture—not to cause outages, exfiltrate data for its own sake, or test systems outside the agreed scope.
2. Authorization
Before testing starts, you confirm that:
- KYC is approved and paid for the organization and the users who will launch tests
- You own the targets or have written authorization from the owner (use the Authorization Letter)
- The named contacts can halt or resize the test
- Any third-party providers (cloud, ISP, MSSP) that require notice have been notified when needed
We will not launch tests, and we may pause work, if KYC or authorization is unclear.
3. Scope
Scope is whatever you configure in the product or we list in a statement of work: URLs, APIs, IP ranges, cloud accounts, or applications.
Out of scope by default:
- Denial-of-service or traffic floods
- Physical security and office intrusion
- Attacks on third-party SaaS you do not control
- Social engineering of Nubesti staff or your employees, unless a written add-on says otherwise
- Intentional destruction of data
- Testing after you revoke authorization
4. Timing and communication
You should schedule high-impact tests outside critical business windows when possible. Provide an emergency contact who can be reached while tests run.
If a test causes unexpected production impact, stop it and notify both sides. Emergency halt requests from you will be honored as quickly as reasonably possible.
5. Customer responsibilities
You remain responsible for:
- Backups and rollback plans
- Staging vs. production decisions
- Legal notices to your users or regulators if your program requires them
- Reviewing findings and remediating your systems
- Verifying that reports do not leave your control in an unsafe way
Onboarding help (connecting integrations, importing targets, walking through the portal) is provided on a commercially reasonable basis. You must validate the configuration before production use.
6. Evidence and data handling
We collect only the evidence needed to demonstrate a finding. You should avoid placing live secrets, real customer databases, or special-category data in scope unless necessary and agreed.
Findings are confidential to your organization, subject to law and the Terms.
7. Limits of assistance
We do not guarantee a particular number of critical findings, a clean report, or passage of a third-party audit. Professional-services hours unused at the end of a fixed package expire unless an order form says they roll over.
8. Safe harbor between the parties
For in-scope, authorized activity performed through the platform, Nubesti will treat the test as consented security research on your systems. This safe harbor does not cover activity you run outside Nubesti or against unauthorized targets.
9. Contact
Engagement questions: [email protected]
Security incidents involving the platform: [email protected]