Scope of Work (SOW) & Rules of Engagement (ROE)
Definitive technical contract establishing target boundaries, allowed attack methodologies, testing windows, and emergency halt protocols.
EXPLOITX DEFENCE
TECHNICAL RULES OF ENGAGEMENT
SCOPE OF WORK & RULES OF ENGAGEMENT CONTRACT
This Scope of Work ("SOW") governs the technical vulnerability assessment and penetration testing services performed by ExploitX Defence Operations for [CLIENT NAME].
1. Target Assets In-Scope
| Target Type | Target Domain / IP Subnet | Testing Window |
|---|---|---|
| Web Application | https://app.clientdomain.com | Off-peak (22:00 - 06:00 EST) |
| REST & GraphQL APIs | https://api.clientdomain.com/v2 | Business Hours (09:00 - 18:00) |
| External Subnet | 192.0.2.0/24 Subnet IPs | Continuous 24/7 Window |
2. Explicit Out-of-Scope Boundaries
The following actions are STRICTLY PROHIBITED unless explicitly authorized in writing:
- Volumetric Denial of Service (DoS / DDoS) flooding attacks.
- Physical breaking and entering of client facility buildings.
- Social engineering or phishing targeting non-IT staff members.
- Permanent destruction or wiping of client production databases.
3. Emergency Halt Protocols
In the event that an exploit accidentally destabilizes a production server or disrupts client business services, ExploitX shall immediately invoke Emergency Halt protocols, cease active testing, and notify the Client Emergency Incident Manager at +91 7283810400.
// EXPLOITX TECHNICAL LEAD
Signature: Vedanshi Pandya
Date: July 26, 2026
// CLIENT AUTHORIZED TECHNICAL CISO
Signature: ________________________
Date: ________________________