Acceptable use & security assessment policy
Security Inspector is designed for authorized, passive assessment of public Internet targets.
Authorization required
You may add or assess a target only when your organization owns it, administers it, or has sufficient permission from the owner. For new targets, Kairoseth records the authenticated actor and timestamp of the authorization confirmation.
Permitted activity
The current service performs bounded passive HTTP/HTTPS, TLS, DNS, email-security and related public-configuration observations needed for the published Security Inspector methodology.
Prohibited activity
Do not use the service for unauthorized targets, harassment, disruption, credential attacks, exploitation, authenticated crawling without authorization, private-network probing, port scanning, evasion of controls, unlawful surveillance or collection of data you are not entitled to process.
No permission from Kairoseth
Kairoseth's ability to technically reach a public target does not grant you permission to assess it. Your authorization statement is a customer representation, not a transfer of responsibility to Kairoseth.
Abuse response
We may reject targets, rate-limit activity, preserve relevant audit evidence and suspend access when necessary to investigate or contain suspected misuse.
Operational policy v1. Corporate identification details must be completed before commercial launch and the final texts should receive legal review.