
Washington uses RCW § 9A.90.030(12)'s definition of without authorization, centered on knowing circumvention of specified technological access barriers. That creates a different textual framework from broad access language alone, but it is not blanket permission for commercial prospecting or an exemption from other laws.
Evidence before outreach · Part 13: Washington. Research date: October 6, 2026. Preliminary statutory analysis, not legal advice or clearance. The official PDFs consulted carry a July 12, 2024 certification date; later amendments, relevant decisions and method-specific application require confirmation.
- Washington security scanning laws require reading the access prohibition with § 9A.90.030's definitions.
- Without authorization centers on knowing circumvention of technological access barriers under specified conditions.
- The white-hat research definition has purpose and use conditions; sales-first work is not automatically covered.
- Terms-of-service violations alone do not satisfy the specified definition, but separate claims remain possible.
- SCOUTz prospect intelligence keeps indexed observations separate from authorized Microsoft 365 evidence.
Why does Washington's barrier definition change the analysis?
A national summary can miss the specific wording that changes a state's analysis. Washington's barrier-based definition deserves attention because it is not the same as simply asking whether a company obtained a signed permission form.
But a different framework is not a green light for every request. The actual offense, definitions, research conditions and possible separate claims still need review.
What should MSPs review under Washington security scanning laws?
The official RCW § 9A.90.030(1), (12) HTML text, retrieved October 6, 2026, defines access broadly but supplies a separate definition of without authorization. Its separate definition of without authorization addresses knowing circumvention of technological barriers designed to exclude unauthorized individuals from obtaining information, without the owner's express or implied permission.
Section 9A.90.030(12) excludes white-hat security research and circumvention of a measure that does not effectively control access. It also says the specified permission language does not include access in violation of a duty, agreement or contractual obligation such as a terms-of-service agreement.
The official § 9A.90.050 PDF identifies intentional access without authorization to another's computer system or electronic database under circumstances not constituting first-degree trespass. Read the offense and definition together.
| Provision | Textual distinction | What it does not establish |
|---|---|---|
| § 9A.90.030(1) | Broad access definition | Every access is unauthorized |
| § 9A.90.030(12) | Knowing barrier circumvention and permission conditions | Every publicly reachable interaction is lawful under every law |
| § 9A.90.030(11) | White-hat purpose and information-use requirements | Every security-related sales workflow qualifies |
| § 9A.90.050(1) | Second-degree computer-trespass elements | A complete answer without the definitions |
These statutory distinctions are a research starting point. The PDFs' certification dates are not a representation that all later changes have been ruled out.
Did any request circumvent a technological access barrier?
For each collector, identify the source contacted, the request type and any access-control measure encountered. Reading an existing third-party record is different from directly verifying the indexed target. Published DNS queries and live service interactions also need separate descriptions.
If a method crosses or works around a restriction, record that fact accurately. A sales summary should not describe barrier circumvention as merely reading public information.
Relevant facts include:
- The service or source that received the request.
- The information sought and retrieved.
- The presence and function of any access barrier.
- Whether the method attempted to circumvent it.
- Any express or implied permission relied upon.
- The purpose of the activity and intended information use.
This is a suggested technical-review inventory, not a statement that every field is legally required.
Does sales-related work qualify as white-hat research?
Section 9A.90.030(11) defines white-hat research as access solely for good-faith testing, investigation, identification or correction of a security flaw or vulnerability, where the activity and derived information are used primarily to promote security or safety.
A commercial workflow should not assume that a security topic establishes those conditions. Counsel needs to examine the actual purpose and information use. The article does not decide that sales-related work always qualifies or never qualifies.
A research label cannot replace evidence of the activity's purpose and use.
Terms-of-service language has a limited role
Section 9A.90.030(12)'s treatment of agreements matters for this chapter's analysis. It does not erase a contract, defeat every civil claim or establish permission under another jurisdiction's law.
Do not turn a statutory distinction into advice to ignore restrictions. An MSP should understand the applicable service conditions and review separate obligations before using or redistributing source information.
A Washington connection is not the whole jurisdiction analysis
An interaction can have connections outside Washington. The sender, service operator and accessed systems may be in different places. This installment does not decide which laws apply to a multistate workflow.
Review the location facts and other relevant statutes separately. A permission or research argument under one chapter is not nationwide legal clearance.
Proof: apply the described SCOUTz boundaries
SCOUTz's free domain review relies on public records and passive enumeration, as described by the team. Reports define indexed as publicly discoverable and state that no request was sent to verify the indexed observation.
The deeper Microsoft 365 review follows prospect authorization and full sign-up through a permission-based connection. The team describes read-only access without content reads, exploit checks, brute-forcing or authentication testing.
Those boundaries can distinguish the workflow from bypassing protected access to investigate an indexed resource. They do not establish the Washington research exclusion or eliminate separate permission questions. The inventory should show what each collector actually does rather than relying on the product's category name.
What remains unresolved
This installment reviews the indicated official statutory documents. Confirm later amendments, relevant decisions, civil claims, other chapter provisions and the precise behavior of each collector before operational reliance.
Ask counsel to evaluate whether any technological barrier was circumvented, what permission applied and whether any asserted research exclusion meets its purpose and use conditions. Do not assign a statewide low-risk label without completing those questions.
Suggested interim controls include approved public-source methods, no unapproved barrier circumvention, a separate authorized tenant scope and a stop process after objections. These are operating recommendations, not universal statutory requirements for every public lookup.
Commercial report emails require their own review for purpose, truthful claims, sender identification and opt-out handling. The collection framework does not remove that separate obligation.
FAQ
Does Washington define unauthorized access around technological barriers?
The consulted § 9A.90.030(12) text centers on knowing circumvention of specified technological access barriers without express or implied permission, with stated exclusions.
Does that make every public-service request legal?
No. The conduct and chapter elements still need analysis, and other laws or claims can remain relevant.
Does commercial security research automatically qualify as white-hat research?
No automatic conclusion is justified. The definition has specific purpose and information-use conditions.
Does a terms-of-service violation alone satisfy the specified definition?
The consulted definition excludes the stated agreement violation from its permission language. That does not erase separate contract or other claims.
Are later Washington amendments fully ruled out here?
No. The official PDFs consulted carry a July 12, 2024 certification date, and later changes require confirmation before reliance.
Is this Washington legal clearance for SCOUTz?
No. It is preliminary statutory analysis with decisions, currentness checks and application to actual methods still requiring review.
One last thing
The useful contrast is not strict state versus permissive state. It is which elements this state requires, and what facts your actual workflow supplies or leaves unknown.
Use the methods guide to record target interactions, and the state index to see pending questions. The permission overview covers the separate federal and outreach layers. SCOUTz's trust boundary describes scoped technical permission, not legal clearance. Contrast the barrier-based definition with Arizona's authority and access language.
Is Washington's research exclusion federal immunity?
No. 18 U.S.C. § 1030(a)(2)(C), (a)(5), (g) provides distinct federal access, damage and conditional civil-remedy provisions. The cited official 2024 edition is effective January 6, 2025; current-2026 comparison remains pending.
DOJ Justice Manual § 9-48.000 B.3(8), C separately describes good-faith research for federal charging and expressly creates no enforceable right or benefit. Do not merge it with Washington's statutory definition or claim immunity from civil litigation or other laws.
Sources
Statutes: official RCW § 9A.90.030(1), (11), (12), HTML text retrieved October 6, 2026; § 9A.90.050(1), official PDF carrying a July 12, 2024 certification date. Federal § 1030(a)(2)(C), (a)(5), (g) uses the dated official edition above. Later amendment reconciliation remains incomplete.
Court decisions: none is asserted. Decisions on barriers, effective access measures and commercial research remain pending.
Agency guidance: DOJ Justice Manual § 9-48.000 is charging policy, not a court holding or immunity.
Product sources: SCOUTz trust and the team's description. Sources consulted October 6, 2026; civil claims, other chapter provisions and exact-method legal clearance remain incomplete.
