S SecuTest
Guides Pricing For Partners About
Log In

Security & transparency

Security, Assessment Boundaries and Vulnerability Disclosure

How SecuTest approaches external security assessment, communicates the limits of automated findings, and handles responsible vulnerability reports.

Updated: August 22, 2026 Public security information B2B only

1. External assessment model

SecuTest evaluates security signals that are observable from the public internet for the submitted domain or hostname. The assessment is designed to be bounded and non-intrusive: it does not require an agent, internal credentials or authenticated access to the target environment.

Coverage can include public email-security configuration, DNS signals, TLS and certificate behavior, browser-facing HTTP controls, selected externally reachable services and public reputation signals. The exact coverage depends on what is observable for the target at assessment time.

For the commercial scope and control families, see the Domain Security Assessment and Email Security Assessment pages.

2. Evidence and interpretation

A SecuTest finding should be read together with its technical evidence and stated interpretation boundary. An external observation can show that a control is absent, weak, reachable or configured in a particular way; it does not automatically prove compromise, ownership, exploitability, business intent or internal impact.

SecuTest separates findings from inventory observations, unavailable providers and explicit coverage limitations where those distinctions are relevant. The score is a prioritization aid, not a substitute for technical review.

Finding-specific remediation and verification guidance is available in the Security Guides.

3. What an external assessment does not prove

  • It is not a penetration test and does not attempt to exploit the target.
  • It does not provide authenticated visibility into internal systems, source code, identities, endpoint state or private network controls.
  • A clean or high-scoring result does not prove that a system is vulnerability-free or fully secure.
  • A detected public condition does not by itself prove that it is exploitable in the target's complete technical and business context.
  • Results are point-in-time observations and can change as DNS, infrastructure, certificates, applications or third-party providers change.

SecuTest is intended to reduce uncertainty about the public attack surface, not to certify the overall security of an organization.

4. Privacy and data handling

SecuTest documents its handling of personal data, service data and relevant providers in the Privacy Policy. Legal and acceptable-use boundaries are documented in the Terms & Conditions.

Security reports and assessment output should be handled according to their sensitivity and the receiving organization's own access-control requirements.

5. From finding to remediation

SecuTest provides technical remediation guides for individual findings and offers bounded Guided Remediation for organizations that want implementation assistance tied to a SecuTest report.

Guided Remediation is not a managed security service, penetration test or unlimited implementation engagement. Its scope and prerequisites are agreed before work begins.

6. Report a SecuTest vulnerability

Email hello@secutest.io or use the contact form and select “Security vulnerability”. Include the affected URL or component, reproduction steps, impact, supporting evidence and a safe contact method.

You can also review the machine-readable disclosure contact published at /.well-known/security.txt.

Do not include live credentials, private keys, unnecessary personal data, malware or data obtained from unrelated third parties.

7. Safe harbour

We will not pursue legal action against good-faith research that follows this policy, avoids privacy harm and service disruption, and gives us reasonable time to investigate and remediate. This statement does not authorise testing of third-party systems or excuse violations of law.

8. Allowed research

  • Testing accounts, targets and data you own or are authorised to use.
  • Low-volume requests necessary to demonstrate a SecuTest vulnerability.
  • Reporting authentication, authorisation, injection, data-exposure or payment-flow flaws without exploitation beyond proof.

9. Prohibited research

  • Denial of service, resource exhaustion or high-volume automation.
  • Accessing, changing, deleting or retaining data that is not yours beyond the minimum proof.
  • Social engineering, phishing or physical attacks.
  • Credential stuffing, password spraying or brute force.
  • Malware deployment, persistence, lateral movement or destructive testing.
  • Public disclosure before coordinated remediation.

10. Our response targets

  • Acknowledge a complete report within five business days.
  • Provide an initial triage result within ten business days where practicable.
  • Share material status changes and coordinate disclosure in good faith.

These are targets, not service-level guarantees.

11. Recognition

With your permission, we may credit valid reports. SecuTest does not currently promise monetary bounties.

12. Related transparency pages

  • About SecuTest — assessment model, product philosophy and externally observable coverage.
  • Security Guides — finding-level evidence, threat context, remediation and verification.
  • Privacy Policy — data handling and privacy information.
  • Terms & Conditions — service and acceptable-use boundaries.
  • For Partners — white-label assessment workflow for MSPs, agencies and consultants.
Contents Assessment model Evidence Limitations Privacy Remediation Report a vulnerability Safe harbour Allowed research Prohibited research Response targets Transparency pages
About Security Privacy Policy Terms & Conditions Cookie Policy Contact