The paperwork, written to be read.
Two documents every security engagement should have and most small ones skip. They are here in full, free to take and adapt, because an engagement that goes wrong usually goes wrong on something nobody wrote down first.
Rules of Engagement
The document that says exactly what will be tested, when, by whom, and what happens when something goes wrong. Agreed before any testing starts — including on engagements that feel too small to need one.
Mutual Non-Disclosure Agreement
A short, plain-English mutual NDA covering a security engagement. Mutual because the tester sees the client's systems and the client sees the tester's methods — one-way NDAs in this context are usually a sign nobody read it.
The rules of engagement document is operational and I stand behind it — it is the one I use. The NDA is a starting point rather than legal advice; I am not a lawyer, and a contract you have not had reviewed is a contract you are guessing about. Both are deliberately short, because paperwork nobody reads protects nobody.