Brand logo of nubesti
  • Home
  • AI Red Team
    • Autonomous Agents

      After KYC and authorization, agents can run scheduled assessments on assets you designate.

    • MITRE ATT&CK mapping

      Testing workflows mapped to MITRE ATT&CK techniques. Mapping is not a claim that every technique ran.

    • OWASP mapping

      Checks mapped to OWASP risk classes, with evidence a reviewer can accept or reject.

    • Integration

      Connect seamlessly with your existing tools and workflows.

    Experience AI Red Team Testing

    See how our autonomous AI agents identify vulnerabilities in your systems.

    Book a Demo
  • Resources
    • Trust Center
    • Methodology
    • Pricing
    • FAQ
    • Blog
  • Contact
    • french
    • spanish
    • portuguese
  • Sign in
  • french
  • spanish
  • portuguese
Sign in
  1. Home
  2. /
  3. Legal
  4. /
  5. Rules of Engagement

Rules of Engagement

Scope, authorization, responsibilities, and limits for Nubesti security assessments and onboarding.

Last updated: September 21, 2026

Nubesti

1111B S Governors Ave STE 23840
Dover, DE 19904, USA

[email protected]

On this page

  1. 1. Purpose
  2. 2. Authorization
  3. 3. Scope
  4. 4. Timing and communication
  5. 5. Customer responsibilities
  6. 6. Evidence and data handling
  7. 7. Limits of assistance
  8. 8. Safe harbor between the parties
  9. 9. Contact

These Rules of Engagement (“RoE”) apply when you run tests through Nubesti or when we provide onboarding or professional-services assistance. They replace “migration terms” you might see at a hosting company: our equivalent is a clear, authorized security assessment.

They supplement the Terms of Service and Acceptable Use Policy.

1. Purpose

The purpose of an engagement is to identify vulnerabilities and improve your security posture—not to cause outages, exfiltrate data for its own sake, or test systems outside the agreed scope.

2. Authorization

Before testing starts, you confirm that:

  • KYC is approved and paid for the organization and the users who will launch tests
  • You own the targets or have written authorization from the owner (use the Authorization Letter)
  • The named contacts can halt or resize the test
  • Any third-party providers (cloud, ISP, MSSP) that require notice have been notified when needed

We will not launch tests, and we may pause work, if KYC or authorization is unclear.

3. Scope

Scope is whatever you configure in the product or we list in a statement of work: URLs, APIs, IP ranges, cloud accounts, or applications.

Out of scope by default:

  • Denial-of-service or traffic floods
  • Physical security and office intrusion
  • Attacks on third-party SaaS you do not control
  • Social engineering of Nubesti staff or your employees, unless a written add-on says otherwise
  • Intentional destruction of data
  • Testing after you revoke authorization

4. Timing and communication

You should schedule high-impact tests outside critical business windows when possible. Provide an emergency contact who can be reached while tests run.

If a test causes unexpected production impact, stop it and notify both sides. Emergency halt requests from you will be honored as quickly as reasonably possible.

5. Customer responsibilities

You remain responsible for:

  • Backups and rollback plans
  • Staging vs. production decisions
  • Legal notices to your users or regulators if your program requires them
  • Reviewing findings and remediating your systems
  • Verifying that reports do not leave your control in an unsafe way

Onboarding help (connecting integrations, importing targets, walking through the portal) is provided on a commercially reasonable basis. You must validate the configuration before production use.

6. Evidence and data handling

We collect only the evidence needed to demonstrate a finding. You should avoid placing live secrets, real customer databases, or special-category data in scope unless necessary and agreed.

Findings are confidential to your organization, subject to law and the Terms.

7. Limits of assistance

We do not guarantee a particular number of critical findings, a clean report, or passage of a third-party audit. Professional-services hours unused at the end of a fixed package expire unless an order form says they roll over.

8. Safe harbor between the parties

For in-scope, authorized activity performed through the platform, Nubesti will treat the test as consented security research on your systems. This safe harbor does not cover activity you run outside Nubesti or against unauthorized targets.

9. Contact

Engagement questions: [email protected]
Security incidents involving the platform: [email protected]

Back to legal center ↗

Brand logo of nubesti

Nubesti LLC provides continuous autonomous security testing against customer-authorized assets. Tests require paid KYC.

  • linkedin

Product

  • Platform
  • Methodology
  • Pricing
  • Demo

Trust

  • Trust Center
  • Platform security
  • Customers
  • Vulnerability disclosure

Legal

  • Legal center
  • Privacy
  • DPA
  • Subprocessors
  • Legal notice
  • About
  • Legal
  • Privacy Policy
  • Legal Notice
  • © 2026 Nubesti LLC
  • All rights reserved