Penetration Testing Authorisation

Last updated: August 2026 (v1.3)Effective: June 2026

This page explains the legal basis under which CyberOrbit AI Pty Ltd (ACN 700 012 157, ABN 75 700 012 157), performs active, intrusive security assessments on your behalf. Every scan we run is covered by an authorisation you gave, for a scope you named and a period you agreed.

1. Why this authorisation matters

CyberOrbit makes real, active network connections to the systems you specify and actively attempts to identify and, where you enable it, exploit security weaknesses in them. Without your written authorisation, that activity is a criminal offence in Australia (Criminal Code Act 1995 (Cth) s.477), the United Kingdom (Computer Misuse Act 1990), the United States (Computer Fraud and Abuse Act, 18 U.S.C. § 1030), and comparable laws elsewhere. Your attestation is CyberOrbit's (and your) legal record that testing was authorised.

2. What you confirm when you attest

When you authorise a set of targets, you confirm, personally and on behalf of your organisation, that:

  • You are duly authorised by your organisation to grant permission for active security testing.
  • You have full legal authority over, or have obtained binding written authorisation from the legal owner of, every domain, IP address, application, and system you list as a target.
  • You have obtained any consent required from third parties whose systems form part of, or host, the target (for example, hosting providers, cloud platforms, ISPs, and managed service providers).
  • You understand that initiating a scan without proper authorisation may constitute a criminal offence and expose you and your organisation to civil and criminal liability.

3. Scope of authorised testing

CyberOrbit will only test the targets you explicitly authorise. No testing will be performed against systems outside that scope. If a scan discovers that a target shares infrastructure with third-party systems not listed in scope, CyberOrbit will stop and report rather than proceed. You are responsible for ensuring your listed targets are within scope for testing and that you hold the appropriate authority for each one.

An authorisation may cover repeated testing of the same targets without a separate approval each time. Where it does, it runs only until the end date shown on the authorisation you accepted, and it never renews by itself. You can withdraw it for any target at any time from Authorised Targets in your settings, and testing of that target stops.

4. Conduct of testing

CyberOrbit assessments are designed to:

  • Use the least-destructive approach sufficient to confirm a vulnerability: proof-of-concept, not exploitation for impact.
  • Avoid accessing, exfiltrating, modifying, or destroying real data beyond what is necessary to confirm a finding.
  • Stop immediately if evidence of an active compromise or an out-of-scope system is detected.
  • Never install backdoors, persistence mechanisms, reverse shells, or any tool that survives after the assessment completes.

5. Record keeping

Your attestation, including your full name, job title, timestamp, IP address, and the exact authorisation text shown, is stored in our database and linked to every scan it covers. The targets it authorises, and the date each one expires, are visible to you at any time under Authorised Targets in your settings. This record is your legal protection as much as ours. CyberOrbit retains authorisation records for a minimum of 7 years in accordance with Australian legal record-keeping obligations.

6. Relationship to Terms of Service

This authorisation supplements, and is governed by, the CyberOrbit Terms of Service. Where this authorisation and the Terms of Service conflict on the subject of testing scope, conduct, or authorisation, this authorisation prevails.

7. Questions

If you have questions about the scope or legal basis of a planned assessment, contact our legal team before initiating the scan.

CyberOrbit AI · Australia