This Authorization Agreement ("Agreement") is entered into between Zanshic Security ("Zanshic", "we", "us"), operated by Hamza Bourchid, and the client identified below ("Client", "you"), governing the security testing engagement described herein.
Client legal/company name:
Client authorized representative (name, title):
Client corporate email:
Client authorizes Zanshic to perform black-box, external, non-destructive penetration testing limited strictly to the domain(s), subdomain(s), and API endpoints explicitly listed in the intake form or a signed scope addendum ("In-Scope Assets"). No testing is authorized against any asset not explicitly listed. Any expansion of scope requires a new written addendum signed by both parties.
Zanshic will not test: production payment infrastructure without prior written consent, third-party services not owned by Client, physical security, social engineering, or denial-of-service techniques, unless separately and explicitly authorized in writing.
Client represents and warrants that:
This Agreement constitutes Client's explicit, written authorization for Zanshic to access and test the In-Scope Assets for the sole purpose of identifying security vulnerabilities. Without this authorization, such activity would be unlawful under applicable computer-misuse law.
Zanshic's testing methodology is strictly non-destructive. Zanshic will not, at any point:
Where testing requires a test/victim account, Zanshic will use accounts it creates and controls, not real Client end-user accounts, except where Client explicitly provides test credentials for this purpose.
Zanshic will treat all information obtained during testing — including findings, credentials, and any data incidentally encountered — as confidential. Data obtained during testing (including screenshots, session evidence, and proof-of-concept material) is retained only for the duration of the engagement and the reporting period that follows, and is deleted no later than 30 days after final report delivery unless Client requests a longer retention period in writing. Zanshic will not store, sell, or use Client data for any purpose beyond delivering the agreed testing service.
Zanshic will deliver a written report documenting all confirmed findings (or confirming no findings, where applicable), including severity ratings, evidence, and remediation guidance appropriate to the service tier purchased. Reports are reviewed and approved by a human before delivery.
Zanshic's testing activity is performed in good faith using industry-standard non-destructive methodology. To the maximum extent permitted by applicable law, Zanshic's total liability arising out of this engagement is limited to the fees paid by Client for the specific engagement giving rise to the claim. Zanshic is not liable for: pre-existing vulnerabilities or system instability unrelated to Zanshic's testing activity; Client's failure to remediate reported findings; or any indirect, incidental, or consequential damages. Client is solely responsible for maintaining backups and for any consequences of authorizing testing against production systems.
Zanshic carries no liability for security incidents occurring after report delivery ("post-report breaches") — see Terms of Service for the full disclaimer.
Client agrees to indemnify Zanshic against any claim arising from Client's breach of Section 3 (Authorization & Representations) — specifically, any claim that Client did not have the legal right to authorize testing of the In-Scope Assets.
This Agreement is effective for the duration of the engagement (one-time audit, or the active period of a monthly subscription). Either party may terminate a monthly engagement effective at the next billing cycle upon written notice. Zanshic reserves the right to immediately halt testing if evidence suggests Client lacks authority over the In-Scope Assets.
This Agreement is governed by the laws of the Kingdom of Morocco. Any dispute arising from this Agreement shall be resolved through arbitration seated in Casablanca, Morocco. Where Client requires this Agreement to be governed by United States law instead, this is available at a premium of 50% on the contract price, subject to a separate addendum.
This Agreement, together with any signed scope addendum and the Zanshic Terms of Service, constitutes the entire agreement between the parties regarding this engagement.
Client authorized signatory · Date
Hamza Bourchid, Zanshic Security · Date