Acceptable Use Policy
What may and may not be done with the SecureEdge Advisory website and customer portal, and how to report a security vulnerability responsibly.
Application
This policy applies to every person who uses the website or the customer portal of SecureEdge Advisory. It forms part of our Terms of Service. Where an engagement letter authorises conduct that this policy would otherwise prohibit, such as an agreed penetration test of a customer's own environment, the engagement letter prevails to the extent of the authorisation.
You must not
- Use the service in breach of applicable law, or to facilitate a breach of law by another person.
- Attempt to access an account, record, or area of the service that you are not authorised to access, or to circumvent an authentication, authorisation or rate-limiting control.
- Probe, scan or test the vulnerability of the service, except as our responsible disclosure policy permits, or as an engagement letter expressly authorises.
- Interfere with the service or with another user's use of it, including by overwhelming it with requests, or by introducing malicious code.
- Upload material that you have no right to upload, that infringes the rights of another person, or that contains personal data for which you have no lawful basis to disclose to us.
- Reverse engineer, decompile or attempt to derive the source code of the service, except to the extent that applicable law permits notwithstanding this restriction.
- Resell, sublicense or otherwise make the service available to a third party, except as an engagement letter expressly permits.
- Use the service, or any output of it, to represent that a certification has been granted where none has been.
Responsible disclosure
If you believe you have found a security vulnerability affecting our systems, report it to security@secureedgeadvisory.com. A person reads that mailbox and will acknowledge your report.
We ask that you give us a reasonable opportunity to investigate and remediate before you disclose the issue publicly, that you do not access, modify or delete data belonging to another person, that you do not degrade the service, and that you act in good faith.
Where you act in accordance with this policy, we shall not pursue or support a claim against you in respect of your research, and we shall treat your report as an authorised act. We do not presently operate a paid disclosure programme, and we shall say so plainly rather than imply otherwise.
Enforcement
Where we reasonably believe that this policy has been breached, we may suspend access to the service, and we may terminate an engagement in accordance with its terms. Where circumstances permit, we shall give notice and an opportunity to remedy the breach before we act. Where the breach threatens the security of the service or the data of another customer, we may act immediately and give notice afterwards.
Reporting misuse
To report a breach of this policy that does not concern a security vulnerability, write to support@secureedgeadvisory.com.