This clause controls whether you're allowed to hire security experts to deliberately try to break into the software and find weaknesses (called a "penetration test" or "pen test"). It matters because finding security holes before hackers do is good practice, but the software company might worry you'll damage their systems or steal data. Under UK and US law, unauthorized attempts to access a computer system are illegal under hacking laws (the Computer Fraud and Abuse Act in the US, the Computer Misuse Act 1990 in the UK), even if you own the account. This clause protects you legally by giving you permission. Without it, your security testing could be a crime.
If security is important to your business, insist on a clause that explicitly allows you to conduct penetration testing with reasonable notice (typically 5-10 business days). Specify that testing must be limited to systems you own or rent, not the provider's infrastructure. Ask the provider if they conduct their own regular security testing and request proof (like a third-party security audit report)—if they won't test their own systems, that's a red flag.
Frequently Asked Questions
What does this clause mean in simple terms?
This clause controls whether you're allowed to hire security experts to deliberately try to break into the software and find weaknesses (called a "penetration test" or "pen test").
Why should I care about this clause?
It matters because finding security holes before hackers do is good practice, but the software company might worry you'll damage their systems or steal data.
What are my options?
Under UK and US law, unauthorized attempts to access a computer system are illegal under hacking laws (the Computer Fraud and Abuse Act in the US, the Computer Misuse Act 1990 in the UK), even if you own the account.
How does this affect small businesses?
This clause protects you legally by giving you permission.
