Trust is the Foundation of Offensive Security
Red team operations require your organization to grant us the kind of access that no legitimate actor should have. We take that trust seriously. These are the non-negotiable principles that govern every SystemDown engagement.
Harm Avoidance
SystemDown does not conduct attacks that could cause irreversible damage to systems, data integrity, or business continuity without explicit authorization and a rollback plan in place.
Destructive techniques — including ransomware simulation, data destruction, or denial of service — are only executed against isolated test environments or with explicit written approval and verified rollback procedures.
Data Stewardship
Any client or third-party data accessed during an engagement is treated under strict chain-of-custody. Data is not retained beyond the engagement window without explicit written agreement.
Sensitive data accessed as proof-of-concept (credentials, PII, financial records) is documented, reported, and securely deleted. We do not store, copy, or use client data for any purpose other than demonstrating impact within the engagement.
Responsible Disclosure
All zero-day vulnerabilities and novel attack techniques discovered during research or client engagements are subject to a 90-day coordinated disclosure policy.
We notify affected vendors before public disclosure. If a vendor fails to respond within 90 days, we proceed with limited public disclosure to protect the broader community. Client-specific vulnerabilities are never disclosed without explicit client consent.
Conflict of Interest
SystemDown does not provide both offensive assessment and defensive tooling or managed detection services to the same client. This eliminates financial incentives to inflate findings or create dependency.
We disclose all known conflicts of interest before contract execution. Operators may not hold equity in or consulting relationships with any vendor whose products are assessed during an engagement.
Legal Compliance
All engagements are conducted in full compliance with applicable laws in the jurisdiction of the target organization. SystemDown does not operate in jurisdictions where authorized offensive security engagements are prohibited.
Engagements that cross international boundaries require separate legal review. We maintain legal counsel in all primary operating regions and conduct annual compliance reviews.