External assessment model

SecuTest can observe public DNS records, standard network responses and other signals exposed to ordinary internet clients. These point-in-time observations support infrastructure classification and prospect intelligence. They are not a penetration test. Their purpose is not to certify the overall security of a target.

Assessment boundaries

Collection is designed around public signals and normal protocol interactions. SecuTest does not use credential attacks, destructive techniques, persistence or vulnerability exploitation as part of the normal product workflow.

Evidence and interpretation

Observed evidence and inferred conclusions are separate concepts. A provider fingerprint can support a classification, while an unavailable or unrecognized signal remains unknown or not detected. It does not automatically prove compromise and it does not prove that a system is vulnerability-free.

What an external assessment does not prove

  • It does not prove the complete internal architecture of a company.
  • It does not prove that a missing public fingerprint means a security control is absent.
  • It does not prove compromise or the absence of compromise.
  • It reflects point-in-time observations that can change.

Vulnerability disclosure

If you believe you found a vulnerability in SecuTest itself, contact hello@secutest.io and include enough technical detail for reproduction. Our machine-readable policy is available at /.well-known/security.txt.

Safe harbour

We will treat good-faith research that follows this policy as authorized to the extent we can do so. We aim to acknowledge a complete report within five business days and provide an initial triage update within ten business days.

Allowed research

  • Good-faith testing of SecuTest systems you can access without harming other users.
  • Minimal proof needed to demonstrate a vulnerability.
  • Coordinated disclosure that gives us a reasonable opportunity to investigate and remediate.

Prohibited research

  • Denial of service, destructive testing or intentional data corruption.
  • Social engineering, credential theft or attempts to access another customer's data.
  • Automated activity likely to materially degrade the service.
  • Public disclosure before reasonable coordination when doing so could expose users.

SecuTest does not currently promise monetary bounties for vulnerability reports.

Related policies

See the Privacy Policy, Terms & Conditions and About SecuTest for current product and data-processing context.