SCOPE & EXCLUSIONS

What we assess,
and what we do not.

We assess the boundary behavior of the connected system as a whole: identity, authorization, data, RAG, APIs, tools, communications, and evidence. The scope is agreed before testing.

PRIMARY SCOPE

Primary assessment areas

01Authorization boundariesUsers, roles, departments, tenants, and service accounts.
02Data boundariesSearch and retrieval across databases, RAG, documents, files, and analytics stores.
03Action boundariesRead, create, update, delete, export, and send permissions.
04Tool / API boundariesMCP, external APIs, SaaS, web access, commands, and other tools.
05Instruction / decision boundariesPrompt injection, ambiguous requests, and privilege-expansion attempts.
06Auditability / repeatabilityWhether requests, decisions, tool calls, denials, and errors can be traced.
EXCLUSIONS

Generally out of scope

Other specialists can be involved when needed, but the service itself is not intended to provide the following.

01

General vulnerability assessment

Broad OS, middleware, or web-application vulnerability scanning.

02

Unauthorized intrusion or disruption

Intrusion into third-party systems, destructive actions, or denial of service.

03

Legal or certification judgment

Final legal opinions or the certification audit itself for ISMS, SOC 2, and similar frameworks.

04

General AI benchmarking

Overall knowledge, writing, translation, or benchmark quality.