What the Rules of Engagement are
The Rules of Engagement (RoE) are the written agreement that turns a security test from "someone is probing our systems" into an authorized activity. They name the targets, the boundaries, the allowed intensity, the time windows, the people who can stop everything, and what happens with the data that is found.
At SWR7 the RoE is not paperwork that follows the sale. It is the gate: the orchestrator will not schedule a single test on a target that is not covered by a signed RoE. The rule is enforced in code, not in a policy document.
What the document covers
- Targets and scope. The exact domains, subdomains, IP ranges and applications in scope — and, just as important, what is explicitly out of scope (third-party providers, payment processors, anything you do not own).
- Ownership or authorization. Your declaration that you own the targets or hold written authorization from the owner. SWR7 tests only under this condition.
- Safety levels allowed. From S0 (passive) to S3 (intrusive). Production is limited to S0–S1; S2 runs on staging, on production only in a window you authorize here; S3 never touches production.
- Time windows and rate limits. When intrusive tests may run, at what intensity, and blackout periods (a big match, a payout window, a release).
- Emergency contacts and stop conditions. Who can halt a test with one message, and what SWR7 does when a target behaves unexpectedly.
- Data handling. How findings, credentials and screenshots are stored, who can see them, and when they are deleted.
- Reporting and remediation. The format of the report, the severity scale, and the fact that on your systems the swarm is propose-only.
Why it protects you
A signed RoE is the difference between a security test and unauthorized access — in most jurisdictions, a criminal matter. It protects you in three concrete ways:
- It gives your ops and security teams a document to point at when an alert fires: this is expected, this is who is doing it, this is how to stop it.
- It caps the blast radius. Nobody will "just try" an intrusive test on production because it seemed useful.
- It makes the deliverable auditable: regulators and partners increasingly ask for evidence that testing was authorized and scoped.
How signing works with SWR7
Two paths, both traceable: an in-person authorization on screen during the kick-off, or the RoE signed and returned by email. In both cases the scope enters the orchestrator's allow-list and the swarm can start. Changing the scope later means amending the RoE — never a verbal "add this host too".
Frequently asked questions
Can we start with a quick look before signing anything?
SWR7 can show you how the service works on its own assets, and can discuss your surface at a high level. Nothing touches your systems — not even passive reconnaissance — before the RoE is signed.
How long does it take to sign the RoE?
The document is a few pages: signing is a matter of a day, not weeks. The slowest part is usually deciding what is out of scope.
Can we exclude specific systems?
Yes, and you should: third-party providers, payment processors and anything you do not own must be out of scope. The RoE lists exclusions explicitly.