Acceptable use policy
What may and may not be done with our website, our systems, and any findings or tooling we share. Status: draft template — requires review by qualified counsel before publication.
1. Purpose
This policy protects our systems, our clients and the people who depend on them. It applies to anyone using our website, contacting us, or receiving output from an engagement.
2. Permitted use of this website
- Reading, quoting with attribution, and linking to our published content.
- Submitting genuine enquiries through our contact forms.
- Security research on our own systems strictly within the scope of our responsible disclosure policy.
3. Prohibited use
- Testing, scanning or attacking any system you are not authorised to test, including ours outside the disclosure scope.
- Denial-of-service, load testing, or any activity that degrades availability.
- Attempting to access, alter or exfiltrate data belonging to others.
- Automated scraping that places unreasonable load on our infrastructure.
- Using findings, tooling, payloads or documentation we share outside the engagement for which they were provided.
- Misrepresenting an association with RASTTSec, or using our name in a way that suggests endorsement.
4. Engagement conduct
During an engagement, testing is limited to the assets named in the rules-of-engagement document. Destructive techniques, social engineering, physical intrusion and testing of third-party services require separate written authorisation. Any accidental access to data outside scope is reported immediately and the data is not copied or retained.
5. Good-faith research
If you report a vulnerability in our systems in good faith, within the boundaries described in our disclosure policy, we will not pursue legal action against you and will work with you on remediation and credit.
6. Enforcement
We may block access, terminate engagements, and report unlawful activity to the relevant authorities. Enforcement wording and appeal process must be confirmed with counsel. [Placeholder.]
7. Reporting abuse
Report suspected abuse of our services or impersonation of RASTTSec to [placeholder email].