Skip to content
zentex ~/
All writing

2026-06-10

Authorized means written down

Every security engagement I take starts the same way. A written scope that names the systems, the techniques, and the window. Not a verbal ok on a call. A document both sides can point at later.

The Publive work ran like that. Scope first, then recon, then findings written up as they landed, each with reproduction steps and impact stated plainly. Critical bugs got reported the day they were confirmed, not saved for a dramatic final report.

I do not test systems I was not asked to test. Curiosity is not authorization, and a bug found outside scope is not a favor, it is a liability for everyone involved. If you want your systems poked, the invitation has to exist in writing. Then I am happy to break things carefully.

Reply by email: zentex@warm.run