Scope guardrails
Escudiva is upfront about the edges of what we offer:
- No red-team engagements. We test what’s in scope, on a defined schedule, with your written authorization — never covert or unannounced.
- No exploit development. We identify and verify vulnerabilities; we don’t build weaponized exploits.
- No compliance certification. We don’t issue SOC 2 or PCI attestations.
- No “unhackable” guarantees. Nobody can honestly promise that. We reduce real, measured risk.
- Deep manual penetration testing is delivered through a named, formalized security partner under Escudiva’s signed scope and authorization — disclosed in every Services Agreement.
Every engagement that touches scanning requires a signed Authorization to Test before any work begins.