Legal

Acceptable Use Policy

Rules for using BrighouseSec services, forms, reports and shared materials responsibly.

Authorised domains only / Passive external checks / No misuse

This Acceptable Use Policy is general website text and should be reviewed before production use.

Authorised Targets Only

You must not request scans, reviews or checks of domains, websites, products, brands or infrastructure that you do not own or have permission to test. You must not submit third-party targets without written permission.

Prohibited Use

You must not use BrighouseSec services, reports, forms or shared links for:

  • Harassment, intimidation or reconnaissance against unauthorised targets.
  • Phishing, spam, credential theft, malware, social engineering or illegal activity.
  • Exploitation, unauthorised access, destructive testing or attempts to bypass security controls.
  • Submitting false ownership, false authorisation or misleading scope information.

Do Not Submit Secrets

Do not submit passwords, credentials, tokens, private keys, regulated sensitive data or unnecessary personal data through the website forms or enquiry channels.

Reports And Share Links

Reports must not be misrepresented as formal compliance certification or full penetration test results. Reports and share links must not be used to mislead customers, partners, investors or third parties.

Misuse Response

BrighouseSec may refuse service, suspend access, stop work, preserve relevant records or report abuse if misuse, unsafe conduct, unlawful activity or lack of authorisation is suspected.