Rules of engagement
Authorized, scoped, and documented.
These rules protect customers, users, and testing integrity. They apply to Free Surface Recon, scoped Security Audits, and Continuous Monitoring.
- Testing and monitoring require authorization from the asset owner or authorized representative.
- Paid audit scope is confirmed manually before checkout.
- Continuous Monitoring setup confirms chatbot URL, widget access, canary placement, business truth facts, and alert destinations.
- Rate limits, excluded systems, production constraints, and sensitive data rules are documented before active or recurring tests.
- Findings and alerts are reported privately with evidence, impact, and remediation guidance.