Terms for working with SystemDown
These terms govern the use of the SystemDown website and the expectations associated with our services. They are intended to support clear communication, lawful execution, and responsible security testing.
These terms supplement any signed agreement, statement of work, or engagement letter. In the event of a conflict, the executed agreement controls for the specific engagement. For website usage, these terms apply to the public-facing information and inquiry process on this domain.
Scope and authorization
All SystemDown services are performed only under a signed statement of work, engagement letter, or written authorization that defines the approved scope, systems, timing, and operational boundaries. No service, testing activity, or access request proceeds without explicit authorization from the authorized organizational representative.
Client responsibilities
Clients are responsible for ensuring they have the lawful right to authorize the engagement, identifying approved contacts, providing necessary access and artifacts, and coordinating internal stakeholders such as legal, compliance, IT, and incident response teams where needed.
Ethical operating standards
SystemDown operates under a strict ethics framework. We do not conduct destructive, non-approved, or unlawful testing. Any activity outside agreed scope is excluded unless explicitly revised in writing by the client and the SystemDown engagement lead.
Delivery and reporting
We provide findings, evidence, and remediation guidance in a structured format suitable for security, technical, and executive stakeholders. Client-facing deliverables are tailored to the engagement objectives and may include reports, debriefs, detection validation, and purple-team sessions.
Intellectual property and confidentiality
All SystemDown methodologies, tools, research, documentation, and materials remain the property of SystemDown unless otherwise agreed in writing. Client information shared during an engagement is handled under confidentiality obligations and retained only as necessary to satisfy the engagement and applicable legal requirements.
Limitations and disclaimers
While we strive to deliver high-quality assessments, no security service can guarantee that all vulnerabilities or attack paths will be identified. SystemDown provides professional judgment and operational testing based on the agreed scope, but the outcome depends on the environment, conditions, and controls in place at the time of testing.
Legal compliance
All engagements must comply with applicable laws, contractual obligations, and approved authorization boundaries. SystemDown may decline or suspend work where legal, operational, or ethical risk cannot be sufficiently managed.
Clients are responsible for confirming that the authorized work is lawful in their jurisdiction and that any required notifications, approvals, or oversight processes have been completed before testing begins.
Questions
If you have questions about these terms, engagement boundaries, or how SystemDown handles client information, please contact engage@systemdown.net.