Rules of Engagement

// Operational Policy Manual — Binding Legal Framework

Operational Policy Manual
// EZEKIEL//SEC — COMMITMENT TO RIGOR, CONFIDENTIALITY & LEGAL SAFETY
ACTIVE POLICY
EZEKIEL//SEC — UNCLASSIFIED POLICY DOCUMENT — REV. 2026.1
1. Purpose and Scope

This policy establishes binding rules for all penetration testing engagements and Bug Bounty Program (BBP) maintenance conducted by Ezekiel//sec. It applies to internal employees, subcontractors, and external security researchers. Adherence guarantees client safety and legal compliance.


2. The "Safety Assurance" Client Pledge
No Operational Impact Guarantee

Testing prioritizes safety; no fuzzing on production auth modules without explicit authorization.

Data Privacy & Integrity

Exfiltration prohibited; proof via metadata only.

Confidentiality (Zero Spill)

Findings treated as client IP. Strict Clean Desk policy enforced.

Legal Safe Harbor

Binding Safe Harbor Letter provided to all researchers upon engagement initiation.


Part A — Client Rules of Engagement (RoE)
Authorization & Scope

Signed authorization required before any engagement begins. Scope Boundary Table defines in-scope assets with precision. Third-party authorization remains the client's responsibility.

Critical Findings Protocol

Testing halts immediately upon discovery of critical/zero-day vulnerabilities. Client notified within 1 hour. Coordinated Vulnerability Disclosure (CVD) 90-day timeline enforced before any public release.

Testing Rules (Do's and Don'ts)
  • Social Engineering: Restricted — requires explicit written sign-off.
  • Physical Intrusion: Restricted — legal waiver required.
  • DoS / Fuzzing: Prohibited unless destructive testing waiver is signed.
  • Privilege Escalation: Allowed for PoC only — no persistent backdoors.
  • Data Exfiltration: Strictly prohibited — directory listing/metadata only.

Part B — Bug Bounty Program (BBP) Management
ISO 29147 Standard

Report submission via encrypted channel → triage within 24h → client notification. Researcher embargo enforced until patch is ready and deployed.

Safe Harbor Promise

No legal action against researchers who stop at data exposure, avoid service interruption, and respect embargo timelines.

Duplicate & Re-test Rules

First report timestamp determines bounty eligibility. Re-test conducted only after patch deployment is confirmed.


Part C — Internal Code of Conduct
Do No Harm

No trolling or harassment of client staff. If illegal content is encountered, all testing stops immediately — report to CISO within the hour.

Confidentiality & Data Handling

PGP encryption mandatory for all reports. Clean Desk: client data wiped after engagement per DoD 5220.22-M standard.

Compliance with Law (CERT-In, GDPR/CCPA)

Critical infrastructure findings reported as per regulatory mandate. No EU/CA user data processed without a valid DPA in place.


4. Breach of Policy & Remedies
For Clients

If Ezekiel//sec violates RoE, client may terminate engagement immediately with full refund.

For Researchers / Hackers

Minor violation: warning issued and/or report rejection. Severe violation (unauthorized data access): permanent ban, forfeited bounties, and law enforcement notification.

Internal Staff

Immediate termination and full legal liability without exception.


5. Sign-off & Acceptance

By initiating a penetration test or joining the Ezekiel//sec Bug Bounty Program, the undersigned acknowledges and accepts full agreement to these Rules of Engagement, including all clauses regarding safe harbor, responsible disclosure, and operational conduct.