Rules of engagement

Authorized, scoped, and documented.

These rules protect customers, users, and testing integrity. They apply to Free Surface Recon, scoped Security Audits, and Continuous Monitoring.

  1. Testing and monitoring require authorization from the asset owner or authorized representative.
  2. Paid audit scope is confirmed manually before checkout.
  3. Continuous Monitoring setup confirms chatbot URL, widget access, canary placement, business truth facts, and alert destinations.
  4. Rate limits, excluded systems, production constraints, and sensitive data rules are documented before active or recurring tests.
  5. Findings and alerts are reported privately with evidence, impact, and remediation guidance.