Deeptech Legal

pwn.legal()

// law for hackers.
"a hacker is someone who understands how the world works." @gf_256

Legal services for _

Subscriptions, fixed-fee sprints, and crisis response counsel, from a law firm that understands your tradecraft.

|=───

sectors

// enumerate your legal attack surface.
vuln-research
Publication review · responsible disclosure · CMA authorisation · defamation risk · vendor threats
pentest-ops
MSA/SOW architecture · authorisation to test · physical & RF testing · AI tooling · third-party vuln carve-outs
offensive-security
Export controls · dual-use classification · end-user risk · cross-border sales · downstream use governance
incident-response
Legal workstream · privilege strategy · regulator comms · customer notification · vendor engagement terms
bug-bounty
Programme terms · safe harbour · scope design · payment structuring · coordinated disclosure
certification-bodies
Cyber Essentials · IASME schemes · CB contracts · DCC export controls
|=───

how we work

// subscriptions, sprints, and bespoke advisory.
01
retained counsel
from £2,500/mo +VAT
We join your Slack, learn your pipeline, provide continuous specialist access. Escalation lane, proactive risk management, institutional memory.
02
fixed-fee sprints
from £3,500 +VAT
Publication gates, export control maps, incident playbooks, contract architecture. Scoped, priced upfront, delivered fast.
03
special situations
bespoke
Disputes, investigations, regulatory action. Fast mobilisation, senior attention, bespoke pricing.
|=───

community

// open source. free clinic. shared knowledge.
help.pwn.legal
Free legal advice for security researchers. CMA, disclosure, vendor threats, bug bounty, police contact.
pro bono
templates.pwn.legal
Open-source contracts for UK pentesters and IASME certification bodies.
CC BY 4.0
pwnlegal.slack.com
Pentesters and CB operators. Contracts, scoping, and the commercial side of security work.
join free
|=───

faq

// common questions.
Do I need a lawyer before disclosing a vulnerability in the UK?
It depends on the circumstances. If you've identified a vulnerability through testing that wasn't explicitly authorised, or if the vendor is hostile, legal advice before disclosure can protect you from claims under the Computer Misuse Act 1990 or civil liability. Even with authorised testing, the scope of your authorisation matters. We offer free initial advice through our clinic.
Is penetration testing legal under the Computer Misuse Act?
Penetration testing is lawful when properly authorised. The key is the scope and quality of that authorisation // a vague email from a client may not be sufficient. Proper authorisation-to-test documentation, clear scope definitions, and appropriate MSA/SOW architecture are essential. Our open-source contract templates are designed for exactly this.
What should I do if a vendor threatens me after a security disclosure?
Don't panic, and don't delete anything. Vendor threats after responsible disclosure are more common than they should be. Get legal advice before responding // your response can significantly affect your position. We handle these situations regularly through both our free clinic and our paid services.
Do security tool vendors need to worry about export controls?
Yes. Dual-use technology // including intrusion software, cryptographic tools, and surveillance capabilities // is subject to UK and EU export control regimes. Selling cross-border without proper classification and licensing can result in criminal liability. Our Export Control Rapid Map sprint is designed to triage this quickly.
How much does it cost to instruct pwn.legal?
Monthly retainers start from £2,500+VAT/mo. Fixed-fee sprints start from £3,500+VAT. Special situations are priced bespoke. The free legal clinic is available for security researchers who can't access specialist counsel. See our services page for full pricing.
What's the difference between pwn.legal and Deeptech Legal?
pwn.legal is the infosec practice of Deeptech Legal Limited, an SRA-regulated law firm. When you engage pwn.legal, you contract with Deeptech Legal. The pwn.legal brand exists to serve the security community // the legal entity, regulatory protections, and professional indemnity insurance are all Deeptech Legal.
|=───

testimonials

$ tail -1 /var/log/feedback
"I recently engaged Rich at pwn.legal on an important legal matter — not directly cyber-related, but he was more than happy to assist. His responsiveness was exceptional: replies were rapid, and he had a real talent for translating complex legal language into plain terms. His guidance led to a significantly improved outcome, and what could have been an incredibly stressful process was made far more manageable. I wouldn't hesitate to recommend Rich and the pwn.legal team to anyone needing sharp, practical legal advice or representation."
Ben Folland, Ctrl-Alt-Int3l · attributed with permission
|=───

start

// get in touch.

Get in touch to discuss your requirements. We'll confirm next steps and, where appropriate, issue an engagement letter for e-signature.

[ book a call ] [ contact us ]