Acceptable Use Policy
Breach intelligence is powerful. These rules keep its use defensive, authorized and lawful.
This document is a structured placeholder and should be reviewed and finalized by legal counsel before being relied upon.
Core Principle
The StealerHunt platform exists to help organizations defend their own assets and users. Every use of the platform must be authorized, defensive in purpose, and compliant with applicable law.
Permitted Use
- Monitoring domains and assets your organization owns or operates.
- Monitoring third-party assets only with the explicit, documented authorization of their owner (e.g. an MSSP engagement letter).
- Investigating exposure findings for remediation, notification and audit.
- Producing sanitized reports for internal stakeholders, auditors and regulators.
Prohibited Use
- Accessing accounts or systems using credentials found through the platform.
- Monitoring organizations or individuals without authorization.
- Re-selling, publishing or trading raw exposure data or unmasked evidence.
- Using findings for harassment, extortion, social engineering or any offensive operation.
- Attempting to bypass tenant isolation, masking, rate limits or other platform controls.
Enforcement
Suspected violations may result in suspension of access pending investigation, and in termination for material breach. Where the law requires it, violations may be reported to competent authorities. Platform activity is logged for audit purposes.
Reporting Misuse
If you believe platform data is being misused, or your organization is being monitored without authorization, contact us through the contact form. Reports are handled confidentially.