Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- Is pentesting illegal without permission?
- What does the law say in the United States?
- How does Canadian law treat unauthorized testing?
- What are the UK requirements?
- Why does a written contract matter?
- How does Decloak fit into the legal picture?
- What are the risks of unauthorized pentesting?
- How to stay on the right side of the law?
- Bottom line
Key takeaways
- Pentesting is not illegal by definition, but it becomes illegal without written permission from the target owner.
- Most jurisdictions criminalize unauthorized computer access (e.g., U.S. CFAA, Canada Criminal Code, UK Computer Misuse Act).
- A signed penetration - test agreement that defines scope, tools, and time window protects both tester and client.
- Using a scanner like Decloak's free scan still requires you to have the right to scan the target; the scan itself follows the same legal principle.
Is pentesting illegal without permission?
Pentesting without explicit, written permission is illegal in most countries because it constitutes unauthorized access. Courts and prosecutors treat the activity as a violation of computer - crime statutes such as the U.S. Computer Fraud and Abuse Act, Canada's Criminal Code, and the UK's Computer Misuse Act.
What does the law say in the United States?
The U.S. Computer Fraud and Abuse Act (18 U.S.C. § 1030) criminalizes unauthorized access to a protected computer. The Department of Justice's 2022 Revised Prosecutorial Guidelines make clear that prosecutors will not bring CFAA charges for "good - faith security research" only when the research is authorized by the system owner. Without that authorization, any testing that accesses or modifies data is a CFAA violation.
How does Canadian law treat unauthorized testing?
Canada's Criminal Code sections 184 and 342 make unauthorized use of a computer a criminal offence. Security researchers are advised to obtain written consent to avoid liability, because the law does not distinguish intent when the access is not authorized.
What are the UK requirements?
The UK Computer Misuse Act makes it illegal to access any program or data without authorization. A valid penetration - test agreement must be signed and must specify the target IPs, scope, tools, and testing window. Anything outside that agreement is a criminal breach.
Why does a written contract matter?
A penetration - test agreement acts as legal protection for both parties. It defines:
- The exact systems to be tested.
- The testing methods and tools allowed.
- The time period during which testing may occur.
- Ownership of any discovered vulnerabilities or data. With this contract, the tester can safely use aggressive techniques, including exploitation, without risking criminal prosecution.
How does Decloak fit into the legal picture?
Decloak's free scan runs core checks on any publicly reachable URL, but the same legal principle applies: you must have the right to scan the target. Scanning a site you do not own or have permission to test could be considered unauthorized access under the statutes mentioned above. Decloak does not perform active exploitation unless you opt into the paid Active Security Testing or AI Pentesting features, which also require explicit consent.
What are the risks of unauthorized pentesting?
- Criminal charges under statutes like the CFAA, Criminal Code, or Computer Misuse Act.
- Civil lawsuits for damages, even if the tester acted in good faith.
- Potential loss of professional reputation and future work opportunities.
How to stay on the right side of the law?
- Obtain a signed penetration - test agreement before any testing begins.
- Clearly define scope, tools, and time windows in the contract.
- Keep documentation of the agreement and any communications.
- Use reputable scanning tools that respect the agreement, such as Decloak, and only enable active testing when consent is documented.
- After testing, provide a detailed report and follow up with remediation guidance.
Bottom line
Pentesting is legal only when you have proper, written consent from the system owner. Conducting any testing without that consent is illegal in most jurisdictions and can lead to criminal prosecution or civil liability.
Related guides
What is an AI pentest and how does it differ from traditional testing?
An AI pentest uses artificial - intelligence agents to automate reconnaissance, vulnerability discovery, exploitation and reporting, giving faster, repeatable assessments while still needing human review.
Is Penetration Testing Being Replaced by AI?
AI speeds up discovery but still needs human expertise; Decloak’s AI Pentesting bridges the gap by confirming exploits safely.
What are the 5 stages of penetration testing?
Penetration testing follows a five - stage lifecycle - reconnaissance, scanning, vulnerability assessment, exploitation, and reporting - to systematically uncover and document security weaknesses.