Template

Rules of engagement.

The document both sides sign before any adversarial module runs. Bracketed fields are filled per engagement. Anything not listed in it is out of scope, and any stop condition halts the work immediately.

Signed before work startsPublished so procurement can read it early

Engagement: [NAME] Client: [CLIENT LEGAL NAME] Provider: Qompute AI, Inc. Version / date: [VERSION] / [DATE] Authorization window: [START WITH TIME ZONE] through [END WITH TIME ZONE]

1. Purpose

[STATE THE BUSINESS AND SECURITY OBJECTIVE.]

2. Authorized targets

Target / environmentIdentifierOwnerPermitted windowNotes
[SYSTEM][URL/SUBSCRIPTION/TENANT/REPO][OWNER][WINDOW][NOTES]

Anything not listed is out of scope.

3. Authorized identities and source infrastructure

Identity / sourceTypePurposeOwnerExpiry
[TEST IDENTITY][USER/SERVICE/AGENT][PURPOSE][OWNER][DATE]

4. Permitted actions

  • [PASSIVE DISCOVERY]
  • [AUTHENTICATED CONFIGURATION REVIEW]
  • [CONTROLLED TOOL OR AGENT INVOCATION]
  • [SAFE CANARY READ/WRITE/EXECUTION]
  • [APPROVED NETWORK EGRESS TEST]
  • [APPROVED QUOTA OR COST TEST]

5. Prohibited actions

  • destructive changes outside isolated test resources
  • access to another customer or tenant
  • social engineering unless separately authorized
  • denial of service or uncontrolled cost generation
  • persistence outside approved test artifacts
  • collection of content beyond minimum proof
  • use of third-party AI services with customer data unless explicitly approved

6. Stop conditions

Immediately stop and notify contacts when:

  • an out-of-scope tenant, customer, or system is reached
  • production availability or cost is materially affected
  • real secrets or regulated data are exposed beyond minimum proof
  • destructive or irreversible behavior occurs
  • unrelated active compromise is discovered
  • client incident commander invokes stop authority

7. Communications and emergency contacts

RoleNameMobileEmailAuthority
Client incident commander[NAME][PHONE][EMAIL]Stop / approve containment
Client technical lead[NAME][PHONE][EMAIL]Target and test decisions
Qompute AI principalJoey Victorino[PHONE][EMAIL]Operator stop authority

8. Evidence handling

  • Approved storage: [LOCATION]
  • Classification: [LEVEL]
  • Encryption: [METHOD]
  • Retention: [PERIOD]
  • Prompt or customer-content handling: [RULE]
  • Secret redaction: show identifier or last four characters only
  • Hash algorithm: SHA-256 unless client policy requires another standard

9. Tooling

All tools and versions are recorded. Open-source licenses and data-handling behavior are reviewed. No tool receives customer data or credentials without explicit approval.

10. Signatures

[CLIENT AUTHORIZED SIGNER] [QOMPUTE AI AUTHORIZED SIGNER]

Back to AI security engineering

Happening now?

Send a project inquiry and set timing to active incident. Joey Victorino reads those first and answers the same business day, US Pacific. Put no credentials, prompts, or customer data in the form.

Describe the situation