Home / Tools / Pentest scope generator
Fill in the client, the authorizing signer, the in-scope and out-of-scope assets, the testing window and the prohibited actions, and download a ready-to-send scope and authorization document as .docx or .pdf. No account, and nothing you type leaves your browser.
Everything is optional. Anything you leave blank stays as a fill-in line in the document, so you can print it and complete it by hand. Nothing is uploaded or stored — the document is built in your browser.
This is exactly what the downloaded document contains.
Penetration Testing Scope & Authorization This document records the scope and authorization for a penetration test. It states what may be tested, what may not, when testing may run, and who has authorized it. It is not a substitute for a signed contract; it is the record of permission the tester relies on. Client / asset owner: ____ Authorizing signer: ____ Tester / testing organisation: ____ Authorization effective from: ____ Authorization expires: ____ 1. AUTHORIZATION The signer named above confirms that they are authorized to permit security testing of the systems listed as in scope, and that they grant permission for the tester to perform that testing within the terms of this document. 2. SCOPE (IN SCOPE) The following assets are in scope. Nothing else is. ____ 3. OUT OF SCOPE The following are explicitly out of scope, in addition to any asset not listed as in scope. ____ 4. TESTING WINDOW ____ 5. PROHIBITED ACTIONS ____ 6. CONTACTS AND REPORTING Emergency contact: ____ Report recipients: ____ 7. SIGN-OFF Authorizing signer: ____ Name / title / date Tester acknowledgement: ____ Name / title / date
It ties a named signer to a named set of assets and a window of time. Those four facts — who authorised it, what may be tested, when testing may run, and what is forbidden — are the minimum a tester needs to be able to point at if the testing is ever questioned. The generator collects them as fields and renders them as a structured document with an authorization statement, scope, out-of-scope list, testing window, prohibited actions, contacts and a sign-off block.
A scope is a list of what is permitted, so an ambiguous entry is not a permission — it is an argument waiting to happen. Write hostnames and IP ranges exactly, and state third-party systems and anything not explicitly listed as out of scope. The generator adds that catch-all line for you, because "the tester found a connected service and assumed it was fair game" is one of the most common ways an engagement goes wrong.
An asset inventory is a map of what you would attack. Sending it to a third-party form to produce a document is an unnecessary disclosure, so this tool does not: the .docx and .pdf are assembled from your input in the browser using dependency-free writers, with no fetch, no storage and no analytics. Turn off your network after the page loads and it still works.
The authorization document is the permission; a rules of engagement document is the plan for how the permitted testing runs. Issue both, cross-reference them by date, and store them with the final report so the whole engagement is one traceable record. The generated document is not a contract and does not replace legal review — it is the operational record of permission that the tester relies on.
The document above is a promise a tester is trusted to keep. PentSeal makes the same scope and window a hard gate on execution: it verifies target ownership, records the signed scope and testing window, and will not run a scan outside them — with a scope and authorization workflow built into the product rather than a PDF on a shared drive.