Brand logo of nubesti
  • Home
  • AI Red Team
    • Autonomous Agents

      After KYC and authorization, agents can run scheduled assessments on assets you designate.

    • MITRE ATT&CK mapping

      Testing workflows mapped to MITRE ATT&CK techniques. Mapping is not a claim that every technique ran.

    • OWASP mapping

      Checks mapped to OWASP risk classes, with evidence a reviewer can accept or reject.

    • Integration

      Connect seamlessly with your existing tools and workflows.

    Experience AI Red Team Testing

    See how our autonomous AI agents identify vulnerabilities in your systems.

    Book a Demo
  • Resources
    • Trust Center
    • Methodology
    • Pricing
    • FAQ
    • Blog
  • Contact
    • french
    • spanish
    • portuguese
  • Sign in
  • french
  • spanish
  • portuguese
Sign in
  1. Home
  2. /
  3. Legal
  4. /
  5. Authorization Letter

Authorization Letter

The written authorization customers must give before Nubesti may test in-scope systems, including a copy-ready letter.

Last updated: September 21, 2026

Nubesti

1111B S Governors Ave STE 23840
Dover, DE 19904, USA

[email protected]

On this page

  1. 1. What you authorize
  2. 2. Safe harbor (in-scope only)
  3. 3. Your duties
  4. 4. Copy-ready letter
  5. 5. Withdrawal

Nubesti will not launch tests until KYC is approved and you confirm written authorization for the scope. This page is the standard authorization. It supplements the Rules of Engagement and Acceptable Use Policy.

By checking the authorization box in the portal, signing an order form, or sending the letter below, you represent that you can bind the owner of the targets.

1. What you authorize

You authorize Nubesti LLC and its automated agents to perform security testing only against assets you designate in the product or in a statement of work, during the period the account is active or the SOW states.

You confirm that you own those systems or have explicit written permission from the owner, and that any cloud or ISP notice required by that provider has been given.

2. Safe harbor (in-scope only)

For in-scope activity performed through Nubesti, you agree to treat that activity as consented security testing. You will not treat it as unauthorized access provided we stay inside the scope and Rules of Engagement.

This does not authorize testing of third-party systems you do not control.

3. Your duties

  • Complete and pay KYC
  • Keep an emergency contact reachable while tests run
  • Stop or resize tests if production impact appears
  • Keep findings confidential except as needed to remediate or as law requires

4. Copy-ready letter

You may send this on company letterhead to [email protected] or upload it during KYC:

I, [name / title], am authorized to bind [legal entity]. I authorize Nubesti LLC to perform security testing, including automated and AI-assisted testing, against the assets we designate in the Nubesti portal or in an attached scope list, for the term of our agreement. We own those assets or have written permission from the owner. We have completed (or will complete and pay for) Nubesti KYC before tests launch. Emergency contact: [name, email]. Signed: [name], [date].

5. Withdrawal

You may revoke authorization by stopping tests in the portal and emailing [email protected]. Already-running jobs will be halted as soon as reasonably possible. Fees already paid follow the Refund Policy and KYC Policy.

Back to legal center ↗

Brand logo of nubesti

Nubesti LLC provides continuous autonomous security testing against customer-authorized assets. Tests require paid KYC.

  • linkedin

Product

  • Platform
  • Methodology
  • Pricing
  • Demo

Trust

  • Trust Center
  • Platform security
  • Customers
  • Vulnerability disclosure

Legal

  • Legal center
  • Privacy
  • DPA
  • Subprocessors
  • Legal notice
  • About
  • Legal
  • Privacy Policy
  • Legal Notice
  • © 2026 Nubesti LLC
  • All rights reserved