SECURITY RESEARCH SCOPING GUIDE Tervaq Security Intelligence Version: 2026-10-06 Blank planning template. Use only with appropriate authorization. Do not enter live credentials or unnecessary personal data. THE RESEARCH QUESTION Name the decision the engagement should support. Avoid an unrestricted promise to find every weakness. Business or security question: [Complete within your approved internal environment] Affected workflow and relevant operating context: [Complete within your approved internal environment] Required deliverables and audience: [Complete within your approved internal environment] Acceptance criteria and explicit exclusions: [Complete within your approved internal environment] AUTHORITY AND ACCESS Confirm who can authorize the work and which assets that authority covers. Authorizing organization and accountable contact: [Complete within your approved internal environment] Approved systems, environments, and third-party dependencies: [Complete within your approved internal environment] Permitted test identities, actions, and access levels: [Complete within your approved internal environment] Stop conditions, escalation contact, and access revocation: [Complete within your approved internal environment] INFORMATION HANDLING Agree on confidentiality and tooling before transferring material. Classification of information to be shared: [Complete within your approved internal environment] Approved storage, transfer, and analysis tools: [Complete within your approved internal environment] Whether any external AI service may process client material: [Complete within your approved internal environment] Access controls, retention, deletion, and handover expectations: [Complete within your approved internal environment] DELIVERY AND COMMERCIAL TERMS Commissioned work needs an agreed scope and price, not assumptions made during an initial inquiry. Project fee or retainer scope and payment schedule: [Complete within your approved internal environment] Milestones, review points, and change-control process: [Complete within your approved internal environment] Report format, evidence package, and retest allowance: [Complete within your approved internal environment] Intellectual property and publication terms to settle in the agreement: [Complete within your approved internal environment] CLOSURE Decide in advance how the work will end and what remains the organization’s responsibility. Deliverable review and acceptance owner: [Complete within your approved internal environment] Residual findings and proposed follow-up work: [Complete within your approved internal environment] Removal of temporary access and test data: [Complete within your approved internal environment] Final retention, deletion, and handover record: [Complete within your approved internal environment] Source: https://tervaq.com/resources/security-engagement-scope