Back to Guides
Guide2 October 2026

Is pentesting illegal?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. Is pentesting illegal without permission?
  3. What does the law say in the United States?
  4. How does Canadian law treat unauthorized testing?
  5. What are the UK requirements?
  6. Why does a written contract matter?
  7. How does Decloak fit into the legal picture?
  8. What are the risks of unauthorized pentesting?
  9. How to stay on the right side of the law?
  10. Bottom line

Key takeaways

Is pentesting illegal without permission?

Pentesting without explicit, written permission is illegal in most countries because it constitutes unauthorized access. Courts and prosecutors treat the activity as a violation of computer - crime statutes such as the U.S. Computer Fraud and Abuse Act, Canada's Criminal Code, and the UK's Computer Misuse Act.

What does the law say in the United States?

The U.S. Computer Fraud and Abuse Act (18 U.S.C. § 1030) criminalizes unauthorized access to a protected computer. The Department of Justice's 2022 Revised Prosecutorial Guidelines make clear that prosecutors will not bring CFAA charges for "good - faith security research" only when the research is authorized by the system owner. Without that authorization, any testing that accesses or modifies data is a CFAA violation.

How does Canadian law treat unauthorized testing?

Canada's Criminal Code sections 184 and 342 make unauthorized use of a computer a criminal offence. Security researchers are advised to obtain written consent to avoid liability, because the law does not distinguish intent when the access is not authorized.

What are the UK requirements?

The UK Computer Misuse Act makes it illegal to access any program or data without authorization. A valid penetration - test agreement must be signed and must specify the target IPs, scope, tools, and testing window. Anything outside that agreement is a criminal breach.

Why does a written contract matter?

A penetration - test agreement acts as legal protection for both parties. It defines:

Decloak's free scan runs core checks on any publicly reachable URL, but the same legal principle applies: you must have the right to scan the target. Scanning a site you do not own or have permission to test could be considered unauthorized access under the statutes mentioned above. Decloak does not perform active exploitation unless you opt into the paid Active Security Testing or AI Pentesting features, which also require explicit consent.

What are the risks of unauthorized pentesting?

How to stay on the right side of the law?

  1. Obtain a signed penetration - test agreement before any testing begins.
  2. Clearly define scope, tools, and time windows in the contract.
  3. Keep documentation of the agreement and any communications.
  4. Use reputable scanning tools that respect the agreement, such as Decloak, and only enable active testing when consent is documented.
  5. After testing, provide a detailed report and follow up with remediation guidance.

Bottom line

Pentesting is legal only when you have proper, written consent from the system owner. Conducting any testing without that consent is illegal in most jurisdictions and can lead to criminal prosecution or civil liability.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary