REDTEAM
RT-SOW-- ·
Statement of Work

Offensive Security Engagement

Client: Prepared: Effective: Confidential

1 · Parties

This Statement of Work ("SOW") is entered into between ("Client") and REDTEAM ("Service Provider"), together "Parties", for the offensive security engagement described below.

This SOW is effective only when accompanied by a signed Authorization Form and Rules of Engagement. The documents together form the complete engagement agreement.

2 · Background & Objectives

3 · Scope of Work

3.1 In-Scope Assets

Asset / TargetTypeEnvironmentNotes
    
    

3.2 Out of Scope

4 · Services & Methodology

Engagement tier:

Methodology: Testing follows OWASP Top 10, OWASP ASVS, PTES, and OSSTMM-informed workflows, adapted to the engagement tier. A governed AI-assisted pipeline supports reconnaissance and exploit validation; every action remains scoped, authorized, and audit-logged.

Approach: Proof-of-concept only. Exploitation demonstrates risk without destruction, and no data is exfiltrated beyond what the report evidence requires.

5 · Deliverables

6 · Timeline & Milestones

MilestoneDescriptionTarget Date
M1Authorization, ROE, and access confirmation 
M2Reconnaissance complete 
M3Testing complete 
M4Draft report delivered 
M5Retest and final report 

7 · Team & Contact

Lead: · ·
Escalation: · ·

8 · Assumptions & Dependencies

9 · Fees & Payment

ItemAmount (MYR)Terms
   
   

10 · Compliance & Legal

11 · Acceptance

By signing below, the Parties agree to the scope, deliverables, timeline, and terms in this Statement of Work, together with the accompanying Authorization Form, Rules of Engagement, and NDA.

For the Client
Name: ______________________
Title: ______________________
Date: ______________________
For REDTEAM
Name: ______________________
Title: ______________________
Date: ______________________

COMPANY STAMP

REDTEAM · redteam.alesa.my · redteam@alesa.myTemplate RT-SOW v1.0 ·