SWR7
Home/Insights/Process
Process

Rules of Engagement: why nothing runs before you sign

Security testing without a signed scope is not a service. It is an incident waiting for a lawyer.

SWR7 teamPublished 2 min read

What the Rules of Engagement are

The Rules of Engagement (RoE) are the written agreement that turns a security test from "someone is probing our systems" into an authorized activity. They name the targets, the boundaries, the allowed intensity, the time windows, the people who can stop everything, and what happens with the data that is found.

At SWR7 the RoE is not paperwork that follows the sale. It is the gate: the orchestrator will not schedule a single test on a target that is not covered by a signed RoE. The rule is enforced in code, not in a policy document.

What the document covers

  1. Targets and scope. The exact domains, subdomains, IP ranges and applications in scope — and, just as important, what is explicitly out of scope (third-party providers, payment processors, anything you do not own).
  2. Ownership or authorization. Your declaration that you own the targets or hold written authorization from the owner. SWR7 tests only under this condition.
  3. Safety levels allowed. From S0 (passive) to S3 (intrusive). Production is limited to S0–S1; S2 runs on staging, on production only in a window you authorize here; S3 never touches production.
  4. Time windows and rate limits. When intrusive tests may run, at what intensity, and blackout periods (a big match, a payout window, a release).
  5. Emergency contacts and stop conditions. Who can halt a test with one message, and what SWR7 does when a target behaves unexpectedly.
  6. Data handling. How findings, credentials and screenshots are stored, who can see them, and when they are deleted.
  7. Reporting and remediation. The format of the report, the severity scale, and the fact that on your systems the swarm is propose-only.

Why it protects you

A signed RoE is the difference between a security test and unauthorized access — in most jurisdictions, a criminal matter. It protects you in three concrete ways:

  • It gives your ops and security teams a document to point at when an alert fires: this is expected, this is who is doing it, this is how to stop it.
  • It caps the blast radius. Nobody will "just try" an intrusive test on production because it seemed useful.
  • It makes the deliverable auditable: regulators and partners increasingly ask for evidence that testing was authorized and scoped.

How signing works with SWR7

Two paths, both traceable: an in-person authorization on screen during the kick-off, or the RoE signed and returned by email. In both cases the scope enters the orchestrator's allow-list and the swarm can start. Changing the scope later means amending the RoE — never a verbal "add this host too".

Non-negotiableSWR7 does not test targets without ownership or written authorization. If a prospect asks us to "have a look" at a competitor, the conversation ends there.

Frequently asked questions

Can we start with a quick look before signing anything?

SWR7 can show you how the service works on its own assets, and can discuss your surface at a high level. Nothing touches your systems — not even passive reconnaissance — before the RoE is signed.

How long does it take to sign the RoE?

The document is a few pages: signing is a matter of a day, not weeks. The slowest part is usually deciding what is out of scope.

Can we exclude specific systems?

Yes, and you should: third-party providers, payment processors and anything you do not own must be out of scope. The RoE lists exclusions explicitly.

Want to know what your surface looks like from outside?

An intro call, no commitment. If it makes sense, you receive the Rules of Engagement — nothing is tested before you sign.

Book an intro call