# Distributed Systems, Inc. — Security Testing Rules of Engagement

Effective: October 6, 2026  
Policy owner: Arthur Colle, Founder & CEO and accountable infrastructure security lead  
Function: Infrastructure Security within Research & Engineering  
Authorized personnel at adoption: Arthur Colle (one person)  
Offensive-testing function: Research & Engineering - Offensive Security Testing, established October 6, 2026; led by Arthur Colle. The two functions share the same sole member.

## Purpose and authorization

Defensive testing protects the company's autonomous-agent software, distributed AI infrastructure, identity services, and tool execution boundaries. Arthur Colle authorizes each engagement before testing starts. Authorization must be documented with named targets and system owners, the company’s ownership or explicit permission to test, environments, permitted test classes, data handling, a start date and time, and an end date and time. Changes require renewed authorization.

No engagement may target third-party systems without their explicit written authorization. Research affiliation does not confer authorization. Frontier-model and sandbox-isolation evaluations must use owned or expressly authorized isolated environments with synthetic data and non-production secrets unless a separately approved scope specifies otherwise.

## Conduct and stopping conditions

Use individual accounts and attributable activity. Use the least privilege needed for the engagement. Keep credentials in approved secret storage and exclude secrets and personal data from shared reports. Respect the approved scope, rate limits, and test window. Stop on unexpected access to out-of-scope systems, exposure of real credentials or personal data, signs of service disruption, or an unanticipated ability to cross a third-party boundary. Notify the security lead and system owner before resuming.

## Findings and remediation

Record reproducible steps, affected component and revision, evidence, severity, impact, the accountable owner, and recommended remediation. Escalate suspected critical vulnerabilities or active compromise to the security lead immediately. Deliver the written findings to the system owner within ten days after testing ends. Track remediation and require patch validation or an appropriate regression check before closure. Preserve sanitized evidence; restrict raw logs containing sensitive information.

## Workspace and provider incidents

Only named, approved members of this security function may use a restricted security-testing workspace. Report suspected model misuse or compromise to the model provider within its required notification window and cooperate with investigation. Record account revocation and personnel or scope changes, and notify the provider when required by the applicable program terms.

## Status

This policy establishes the present operating rules. It is not a claim of historical compliance, an external certification, or prior execution of engagements under these rules. The October 6, 2026 local automated regression assessment has its own dated test summary.
