Ethics Framework

Trust is the Foundation of Offensive Security

Red team operations require your organization to grant us the kind of access that no legitimate actor should have. We take that trust seriously. These are the non-negotiable principles that govern every SystemDown engagement.

PRINCIPLE 01

Authorization Before Action

No SystemDown operator engages any system, network, or individual without explicit written authorization from a legally accountable representative of the target organization. This applies without exception — including in cases where prior access exists from earlier phases of an engagement.

Authorization documents specify scope, out-of-scope systems, allowed techniques, and the escalation chain. Any action outside the authorized scope is a hard stop.

PRINCIPLE 02

Harm Avoidance

SystemDown does not conduct attacks that could cause irreversible damage to systems, data integrity, or business continuity without explicit authorization and a rollback plan in place.

Destructive techniques — including ransomware simulation, data destruction, or denial of service — are only executed against isolated test environments or with explicit written approval and verified rollback procedures.

PRINCIPLE 03

Data Stewardship

Any client or third-party data accessed during an engagement is treated under strict chain-of-custody. Data is not retained beyond the engagement window without explicit written agreement.

Sensitive data accessed as proof-of-concept (credentials, PII, financial records) is documented, reported, and securely deleted. We do not store, copy, or use client data for any purpose other than demonstrating impact within the engagement.

PRINCIPLE 04

Responsible Disclosure

All zero-day vulnerabilities and novel attack techniques discovered during research or client engagements are subject to a 90-day coordinated disclosure policy.

We notify affected vendors before public disclosure. If a vendor fails to respond within 90 days, we proceed with limited public disclosure to protect the broader community. Client-specific vulnerabilities are never disclosed without explicit client consent.

PRINCIPLE 05

Conflict of Interest

SystemDown does not provide both offensive assessment and defensive tooling or managed detection services to the same client. This eliminates financial incentives to inflate findings or create dependency.

We disclose all known conflicts of interest before contract execution. Operators may not hold equity in or consulting relationships with any vendor whose products are assessed during an engagement.

PRINCIPLE 06

Legal Compliance

All engagements are conducted in full compliance with applicable laws in the jurisdiction of the target organization. SystemDown does not operate in jurisdictions where authorized offensive security engagements are prohibited.

Engagements that cross international boundaries require separate legal review. We maintain legal counsel in all primary operating regions and conduct annual compliance reviews.