This Acceptable Use Policy is general website text and should be reviewed before production use.
Authorised Targets Only
You must not request scans, reviews or checks of domains, websites, products, brands or infrastructure that you do not own or have permission to test. You must not submit third-party targets without written permission.
Prohibited Use
You must not use BrighouseSec services, reports, forms or shared links for:
- Harassment, intimidation or reconnaissance against unauthorised targets.
- Phishing, spam, credential theft, malware, social engineering or illegal activity.
- Exploitation, unauthorised access, destructive testing or attempts to bypass security controls.
- Submitting false ownership, false authorisation or misleading scope information.
Do Not Submit Secrets
Do not submit passwords, credentials, tokens, private keys, regulated sensitive data or unnecessary personal data through the website forms or enquiry channels.
Reports And Share Links
Reports must not be misrepresented as formal compliance certification or full penetration test results. Reports and share links must not be used to mislead customers, partners, investors or third parties.
Misuse Response
BrighouseSec may refuse service, suspend access, stop work, preserve relevant records or report abuse if misuse, unsafe conduct, unlawful activity or lack of authorisation is suspected.