A penetration test authorization letter is the written permission that allows a security testing provider to probe your systems. It sets the scope, the testing window and the legal basis for the engagement — essential wherever unauthorized access to computer systems is a criminal offence, as it is in Hong Kong.
The complete authorization document used for LuDuan engagements is below, followed by guidance on what any authorization letter should include.
You (the "Client") hereby authorize LuDuan AI Group ("LuDuan") and its nominated consultants to perform authorized security testing, including penetration testing, vulnerability scanning, configuration reviews and security assessments against the target systems specified in the engagement ("Authorized Targets").
Testing shall be conducted during the time window mutually agreed between LuDuan and the Client in the engagement confirmation. Any request to reschedule the testing window must be submitted at least 3 business days in advance.
Any critical or high-severity findings identified during testing shall be communicated to the Client's designated contact within 24 hours of identification, prior to the issuance of the final report.
Upon completion of the testing, LuDuan shall securely delete or destroy all data, logs and temporary files generated during the testing, except as required for the final report or as otherwise agreed in writing.
You represent and warrant that you own, operate or are otherwise duly authorized to authorize testing of all Authorized Targets and that such testing does not violate any applicable law, regulation or third-party agreement.
You acknowledge that unauthorized access to computer systems is a criminal offence under the laws of Hong Kong (including the Crimes Ordinance, Cap. 200 and section 27A of the Telecommunications Ordinance, Cap. 106) and other applicable jurisdictions. This Authorization serves as the lawful basis for the testing activities described herein.
All findings, data and information obtained during testing are confidential and protected under the NDA entered into between the parties (or, where applicable, the Data Sharing Consent and NDA acknowledged at order placement).
This Authorization is valid for the specific engagement period stated in the order. Any re-testing or new testing requires a fresh order and renewed authorization.
This document forms part of the LuDuan legal framework together with the Non-Disclosure Agreement, Data Sharing Consent, Disclaimer, Penetration Test Authorization, Service Terms and Refund Policy. Where there is any conflict, the order of precedence is: Penetration Test Authorization, NDA, Data Sharing Consent, Disclaimer, Service Terms, Refund Policy, unless expressly agreed otherwise in writing. All documents acknowledged at order placement together constitute the agreement governing your engagement with LuDuan.
A penetration test authorization letter is written permission from the client that allows a security testing provider to probe specified systems. It defines the targets in scope, the testing window and restrictions — and establishes the legal basis for the engagement.
Yes. Reputable providers will not test without one. In Hong Kong, unauthorized access to computer systems is a criminal offence (Crimes Ordinance, Cap. 200 and section 27A of the Telecommunications Ordinance, Cap. 106) — the authorization letter is the lawful basis for testing.
This authorization is included with every LuDuan security testing order — you acknowledge it at order placement, and the specific authorized targets are defined in the engagement confirmation.