
California security scanning laws require separate review of access, permission, data use and computer-service use. Penal Code § 502(e)(1) also provides a civil remedy for qualifying damage or loss, so nothing broke is not a complete analysis of a prospect review.
Evidence before outreach · Part 7: California. Research date: October 6, 2026. Preliminary statutory analysis, not legal advice or clearance. Decisions, defenses and application to the actual collection methods require counsel review.
- California security scanning laws are not limited to changing or damaging data.
- Penal Code § 502 separately addresses data use, computer services and access without permission.
- Qualifying investigation expenses can be compensatory damages after a statutory violation and related loss are established.
- Public evidence does not automatically authorize direct verification requests.
- SCOUTz prospect intelligence keeps indexed observations separate from confirmed conditions.
Why is no damage an incomplete permission test?
An MSP often evaluates a tool by whether it changes anything. California's statutory language asks additional questions. What resources did the tool use? What data did it take or copy? What permission applied?
The same questions matter when a prospect challenges the work. Accurate logs and report labels are more useful than a general assurance that the review was benign.
What should MSPs review under California security scanning laws?
The official text of Penal Code § 502, consulted October 6, 2026, defines access broadly in subsection (b)(1). It includes communicating with computer resources and causing input, output or processing.
Relevant conduct provisions include § 502(c)(2), (3), (7): respectively, access with data taking, copying or use without permission; computer-service use without permission; and access without permission. These are distinct provisions and should not be summarized as a single requirement to hack and damage.
| Provision | Statutory issue | Review question |
|---|---|---|
| § 502(b)(1) | Broad definition of access | What resources did the request communicate with or use? |
| § 502(c)(2) | Taking, copying or using data without permission | Which data was obtained and what permission applied? |
| § 502(c)(3) | Computer-service use without permission | Which service was used and under what conditions? |
| § 502(c)(7) | Access without permission | What authorized the particular interaction? |
| § 502(e)(1)–(2) | Civil damage or loss by reason of a violation | Was a violation and qualifying related loss established? |
The statutory text alone does not resolve what permission accompanies every public service. Relevant decisions and the actual facts remain necessary.
How do public records differ from direct computer-service use?
Reading an index that already contains a reference is not the same act as contacting the referenced service to verify it. A published DNS query differs from a web request, and both differ from exploit or authentication testing.
Describe every collector separately. A product can be largely public-source while one collector introduces live target requests. That exception belongs in the inventory, not under a passive label that conceals it.
For each finding, preserve:
- The identified source and source date, where available.
- The report's collection date.
- The destination of any request.
- The type of information retrieved.
- The permission or approved public-access basis relied upon.
- The facts that remain unverified.
Do not infer private content, current availability or a confirmed vulnerability from an indexed reference alone. Unknown evidence remains unknown.
Do investigation costs automatically establish liability?
Section 502(e)(1)–(2) permits an owner or lessee suffering damage or loss by reason of a violation to bring a civil action. Its compensatory-damages language includes reasonably necessary expenditures to verify whether systems or data were altered, damaged or deleted by the access. Subsection (e)(2) allows an award of reasonable attorney's fees.
This matters for risk assessment, but the sequence matters too. An investigation invoice does not prove the underlying violation. The required connection between a violation and qualifying damage or loss still has to be established.
Nothing broke does not end the analysis. Someone investigated does not establish liability either.
Do not borrow exceptions from a different state
Section 502(h)(1)–(2), (i) contains employment-related limits, with additional conditions in its text. A third-party MSP should not assume that being employed by its own company creates permission to use a prospect's systems.
The scope and application of those provisions need counsel's review. This article does not claim a general commercial-security-research exemption under California law.
Location remains relevant
Section 502(j) addresses access caused between jurisdictions and treats the person as having accessed the system in each jurisdiction for purposes of an action under the section. That language is a reason to examine request origin and target location.
A prospect's headquarters alone is not a sufficient jurisdictional model. Nor is the assessment provider's cloud region a dependable shield from review.
Proof: apply the described SCOUTz method boundaries
SCOUTz's free domain review, according to the team, relies on public records and passive enumeration. Reports define indexed as publicly discoverable and state that no request was sent to verify an indexed observation. The report therefore should not imply a direct examination of the indexed resource.
The deeper Microsoft 365 assessment is separate. The described workflow requires prospect authorization and full sign-up through a permission-based connection and remains read-only without content reads.
The team describes no exploit checks, brute-forcing or authentication testing. Reports contain diagnosis, not threatened disclosure or a built-in remediation upsell. Those product facts help define the legal-review scope; they do not eliminate the need to evaluate collectors, permissions and uses individually.
Practical questions for California counsel
Bring the actual request inventory rather than a product overview. Ask counsel to evaluate the permission associated with each public service, any limitations or objections, the collection of data and computer-service use.
A separate review should cover:
- Relevant decisions interpreting the specific § 502 subsections.
- Applicable defenses and exceptions for the actual role and conduct.
- Qualifying civil loss and the available remedies.
- Cross-jurisdiction facts and other possible claims.
- Accuracy and compliance of the outreach message and attachment.
This installment does not supply a current case-law survey or predict outcomes. Suggested interim controls include approved public-source collection, separate permission for protected access and a stop process after an objection.
FAQ
Does California law apply only to destructive hacking?
No. Section 502 includes separate provisions for data use, computer-service use and access without permission.
Does an investigation expense prove a § 502 violation?
No. The civil remedy still requires a statutory violation and qualifying damage or loss by reason of it.
Can read-only activity still require permission analysis?
Yes. The absence of intentional changes does not determine whether access or service use was permitted.
Does public availability authorize every automated request?
Not automatically. The service, method, permissions and relevant decisions need review.
Does being a security company establish an exemption?
No general exemption is established by that label. Counsel should examine the actual statutory exceptions and conduct.
Is this California legal clearance for SCOUTz?
No. The article reviews statutory starting points and leaves method-specific application, decisions and other claims for counsel.
One last thing
A source label can prevent an unsupported admission and an unsupported reassurance at the same time. Say what was collected, where it came from and what was not checked.
Use the collection-method definitions to distinguish index reads from direct requests. The state index preserves pending reviews; the authorization guide sets out practical scope controls. SCOUTz's trust boundary describes no content reads and customer-approved deeper access. Compare California's civil-loss provision with Florida's conviction-linked remedy, not a borrowed generic rule.
What is the separate federal civil-access question?
18 U.S.C. § 1030(g) permits a civil action only under its stated violation, damage-or-loss and specified-factor conditions. Section 1030(e)(11)'s loss definition is not itself a finding of liability, and § 1030(a)(2)(C) and (a)(5) identify separate conduct elements. California investigation expense cannot simply be substituted for every federal element.
The federal source is GovInfo's official 2024 edition, effective January 6, 2025, not verified current 2026 code. DOJ Justice Manual § 9-48.000 C is charging guidance, not immunity from this civil review or California law.
Sources
Statutes: official California Penal Code § 502(b)(1), (c)(2), (3), (7), (e)(1)–(2), (h), (i), (j), linked near claims; federal § 1030(g), (e)(11), (a)(2)(C), (a)(5), linked above.
Court decisions: no holding is asserted; permission and qualifying-loss decisions remain pending.
Agency guidance: DOJ Justice Manual § 9-48.000, not an enforceable research exemption.
Product sources: SCOUTz trust and the team's workflow description. Sources consulted October 6, 2026. Exhaustive amendment comparison, other claims and method-specific application remain incomplete.
