This document records your authorisation for Layer8 Co., Ltd. (“Layer8”) to test the target you submit when ordering the SOC 2 Application Pentest (the “Service”).
Version: v0.1 (21 August 2026)
1. Who may accept this document
The person accepting this document must own the target asset, or otherwise be authorised to request security testing of it. Acceptance by a person without that authority is not valid.
2. What you authorise
You authorise Layer8 to carry out penetration testing of the target you specify when ordering, within the scope of the Service. The authorisation is limited to the FQDN, environment and target types specified in the order, to the test accounts you provide, and to the testing period agreed between you and Layer8.
3. What we record
To evidence your acceptance, Layer8 records:
- the signer’s name and job title
- the company name
- the target FQDN and environment
- the method used to verify authorisation
- the timestamp of acceptance
- the version of the document accepted
4. Verifying authorisation
Where the relationship between the buying company and the target domain is clear, Layer8 verifies authorisation using a business email address together with acceptance of this document. Where they do not match, Layer8 contacts an approver at the company that owns the target. Orders from free email addresses, third-party production environments, unclear ownership, or any case Layer8 considers high risk require a DNS TXT record, a file served over HTTP, or a signed document.
5. Condition for starting
Layer8 does not begin testing until authorisation has been verified. If authorisation cannot be verified, the order is cancelled and refunded in full.
6. Third-party assets
If the target is operated by a third party, you must obtain that third party’s permission before accepting this document. Layer8 may contact the third party where it considers this necessary.
7. Your representation
By accepting this document you represent that, at that time, you are authorised to request testing of the target. If that representation proves to be untrue and Layer8 or a third party suffers loss as a result, you are responsible for it.
8. Testing conditions
Testing conditions are set out in the Rules of Engagement. By accepting this document you also accept the Rules of Engagement.
9. Withdrawing authorisation
You may withdraw this authorisation at any time before testing starts, in which case the order is cancelled and refunded in full. Once testing has started, a stop request by email halts the assessment.
10. Responsibility
Given the nature of penetration testing, an effect on the target system cannot be ruled out entirely. Layer8 follows the prohibited actions and constraints set out in the Rules of Engagement. You are responsible for confirming that backups and recovery options are in place before testing starts.
11. Changes to this document
Layer8 may revise this document. The version that applies to your order is the version you accepted. Revised versions are published on this page.
12. Contact
For questions about this document, contact info@layer8.jp.