Security Testing · Hong Kong

Penetration Test Authorization Letter — Hong Kong Guide & Template

A penetration test authorization letter is the written permission that allows a security testing provider to probe your systems. It sets the scope, the testing window and the legal basis for the engagement — essential wherever unauthorized access to computer systems is a criminal offence, as it is in Hong Kong.

The complete authorization document used for LuDuan engagements is below, followed by guidance on what any authorization letter should include.

Penetration Test & Vulnerability Assessment Authorization
Effective date: 15 August 2026 · Governed by the laws of the Hong Kong Special Administrative Region

1. Authorization Granted

You (the "Client") hereby authorize LuDuan AI Group ("LuDuan") and its nominated consultants to perform authorized security testing, including penetration testing, vulnerability scanning, configuration reviews and security assessments against the target systems specified in the engagement ("Authorized Targets").

2. Scope of Testing

  • Specific targets (domains, IP addresses, systems, applications) will be defined in the engagement confirmation or statement of work for each order.
  • Testing will be conducted only within the defined scope and the agreed time window described below.
  • Testing types include, where applicable: external/internal penetration testing, web application testing, vulnerability scanning and configuration review.

3. Testing Window

Testing shall be conducted during the time window mutually agreed between LuDuan and the Client in the engagement confirmation. Any request to reschedule the testing window must be submitted at least 3 business days in advance.

4. Restrictions

  • No denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks against production systems unless expressly agreed in writing.
  • No social engineering unless separately agreed in writing.
  • No exfiltration of data beyond what is strictly necessary to demonstrate a vulnerability.
  • No testing of third-party systems outside the Authorized Targets.
  • Compliance with Personal Data Laws: If any personal data (as defined under the Personal Data (Privacy) Ordinance, Cap. 486) is incidentally encountered during testing, it shall not be accessed, copied or retained beyond what is strictly necessary to demonstrate the vulnerability. Such data must be securely deleted immediately upon demonstration.
  • Where destructive testing is required, prior written confirmation will be obtained.

5. Critical Findings Notification

Any critical or high-severity findings identified during testing shall be communicated to the Client's designated contact within 24 hours of identification, prior to the issuance of the final report.

6. Data Handling & Clean-up

Upon completion of the testing, LuDuan shall securely delete or destroy all data, logs and temporary files generated during the testing, except as required for the final report or as otherwise agreed in writing.

7. Client Representations

You represent and warrant that you own, operate or are otherwise duly authorized to authorize testing of all Authorized Targets and that such testing does not violate any applicable law, regulation or third-party agreement.

8. Legal Acknowledgement

You acknowledge that unauthorized access to computer systems is a criminal offence under the laws of Hong Kong (including the Crimes Ordinance, Cap. 200 and section 27A of the Telecommunications Ordinance, Cap. 106) and other applicable jurisdictions. This Authorization serves as the lawful basis for the testing activities described herein.

9. Confidentiality

All findings, data and information obtained during testing are confidential and protected under the NDA entered into between the parties (or, where applicable, the Data Sharing Consent and NDA acknowledged at order placement).

10. Duration & Renewal

This Authorization is valid for the specific engagement period stated in the order. Any re-testing or new testing requires a fresh order and renewed authorization.

Relationship with Other Documents

This document forms part of the LuDuan legal framework together with the Non-Disclosure Agreement, Data Sharing Consent, Disclaimer, Penetration Test Authorization, Service Terms and Refund Policy. Where there is any conflict, the order of precedence is: Penetration Test Authorization, NDA, Data Sharing Consent, Disclaimer, Service Terms, Refund Policy, unless expressly agreed otherwise in writing. All documents acknowledged at order placement together constitute the agreement governing your engagement with LuDuan.

What should a penetration test authorization letter include?
  • The parties: the client entity and the testing provider, with full legal names.
  • Authorized Targets: domains, IP ranges, applications and environments in scope — and what is explicitly out of scope.
  • Testing types: external/internal penetration testing, web application testing, vulnerability scanning or configuration review, as applicable.
  • Testing window: the agreed dates and hours, and rules for rescheduling.
  • Restrictions: no denial-of-service, no social engineering and data-handling limits — unless separately agreed in writing.
  • Critical findings process: how and when high-severity issues are escalated to the client's designated contact.
  • Acceptance: the person with authority to authorize testing accepts the terms — in the LuDuan flow this is recorded through the acknowledgement checkbox at order placement, so no separate signature is needed.
Frequently asked questions

What is a penetration test authorization letter?

A penetration test authorization letter is written permission from the client that allows a security testing provider to probe specified systems. It defines the targets in scope, the testing window and restrictions — and establishes the legal basis for the engagement.

Is a signed authorization required before penetration testing?

Yes. Reputable providers will not test without one. In Hong Kong, unauthorized access to computer systems is a criminal offence (Crimes Ordinance, Cap. 200 and section 27A of the Telecommunications Ordinance, Cap. 106) — the authorization letter is the lawful basis for testing.

How do I authorize testing with LuDuan?

This authorization is included with every LuDuan security testing order — you acknowledge it at order placement, and the specific authorized targets are defined in the engagement confirmation.

See all security testing services →