This document sets out the conditions under which Layer8 Co., Ltd. (“Layer8”) carries out the SOC 2 Application Pentest (the “Service”). You accept these rules together with the Authorization to Test.
Version: v0.1 (21 August 2026)
1. Scope
Testing is limited to the FQDN, environment and target types specified in the order. Assets outside that scope, out-of-scope subdomains and third-party services are not tested. Any change of scope is reviewed by Layer8 before testing starts.
2. Prohibited actions
Layer8 does not perform any of the following:
- denial of service, load testing, or high-volume traffic aimed at availability
- deleting data, or making changes that cannot be reverted
- notifications, email or any other contact with your real customers
- real payments, transfers or the conclusion of contracts
- any feature you have listed as prohibited
3. Data and accounts
Testing uses only the test accounts and test data you provide. Write operations are limited to the features you explicitly allow. Where an environment also holds real data, Layer8 confirms the possible impact before deciding how to test.
4. Handling credentials
Test account credentials are never collected over email. They are submitted through an encrypted form and are accessible only to the engineers who need them. Credentials and raw traffic logs are deleted 30 days after the assessment is completed, and you may request immediate deletion at any time.
5. Real data and personal information
If we reach real user data or personal information inside the target, we examine only as much as we need to confirm whether access was authorised. Identifying details are masked in anything we record as evidence. We do not use that data for any purpose other than the assessment, and we do not move it outside our working environment.
6. Out-of-scope observations
If we notice signs of a vulnerability in an out-of-scope asset or a third-party service, we stop there rather than testing further, and report only what we observed.
7. Rate and testing windows
The rate limits, concurrency and testing windows you specify are applied to the test configuration and enforced while it runs. Where you do not specify them, Layer8 sets them according to the target environment.
8. Production environments
Where the target is a production environment, Layer8 confirms the following before starting:
- backups and recovery options
- emergency contacts and the hours they are reachable
- prohibited features, and the features where writes are allowed
- rate limits and testing windows
- how to reach you if a WAF or rate limiter blocks the assessment
9. Stop procedure
You can request a stop by email at any time. Layer8 halts the assessment on receipt of the request and records what had been carried out up to that point. Layer8 also stops testing, and contacts you, if it becomes aware of a serious effect on the target system.
10. Logging
Traffic and actions during the assessment are logged. Logs are used to reproduce findings, confirm their impact and evidence the work carried out.
11. What cannot be tested safely
Anything Layer8 judges cannot be validated safely is left untested and recorded in the report as Not Tested or Staging Only. Layer8 never reports an unvalidated item as confirmed.
12. Information obtained during testing
Information obtained during the assessment is used only to deliver and report on the Service. Your data is not used to train models.
13. Changes to this document
Layer8 may revise this document. The version that applies to your order is the version you accepted.
14. Contact
For questions about this document, contact info@layer8.jp.