Responsible use
Assessment authorization policy
Public trust standard · 31 August 2026
Two-part authorization gate
No active assessment begins until the requester has both legally attested its authority and completed technical ownership verification for the target. A publicly resolvable hostname, reachable IP address, payment, or account creation alone is never authorization.
Scope is a hard boundary
The verified target list, methods, test window, limits, exclusions, and emergency contact form the enforceable assessment boundary. Redirects, linked infrastructure, shared hosting, subsidiaries, suppliers, and other third parties remain out of scope unless separately authorized and verified.
Permitted SaaS activity
The commercial platform is limited to approved discovery, configuration checks, exposure validation, authenticated assessment where expressly authorized, remediation retesting, and evidence generation.
Not exposed in SaaS
Destructive payloads, persistence deployment, credential theft, seed or private-key collection, denial-of-service activity, indiscriminate brute force, and laboratory implant capabilities are not available to commercial customers.
Safety controls
Rate limits, concurrency limits, maintenance windows, emergency stop controls, target allowlists, immutable authorization and audit events, expiry of approvals, and operator review protect customer systems and third parties.
Reporting concerns
Suspected abuse, incorrect authorization, or unintended impact should be reported immediately to office@globalconnect.sbs. Relevant jobs will be paused while reviewed.