Legal
Orvantis Security conducts offensive testing exclusively against systems that a client owns or is lawfully authorised to have tested. Every engagement begins only after a signed scope, Rules of Engagement, and written authorisation are in place. We do not test systems without explicit, documented permission — full stop.
If you believe you've found a vulnerability in Orvantis Security's own website or infrastructure, we want to hear from you. Please report it responsibly:
If you research the security of Orvantis Security's own public assets in good faith and within the limits of this policy — testing only our systems, avoiding privacy violations, service disruption and data destruction, and giving us reasonable time to remediate before any disclosure — we will treat that research as authorised and will not pursue or support legal action against you for it.
This safe harbour applies only to assets Orvantis Security owns or operates; it does not grant permission to test, and does not protect you in relation to, any third party. If you are unsure whether something is in scope, contact us first and we'll clarify.
If you suspect a vulnerability in something you own or run and want help validating and fixing it, that's exactly the kind of work we do. Reach out via the contact page — it stays confidential.
Security matters: security@orvantis.co.ke · General: martin@orvantis.co.ke