2. Prohibited security activity
- Unauthorized access, scanning, exploitation, credential attacks, password spraying, or privilege escalation.
- Denial-of-service, stress testing, destructive testing, persistence, malware, ransomware, command-and-control, or evasion.
- Social engineering, phishing, impersonation, fraud, surveillance, or interception.
- Accessing, copying, modifying, or retaining data beyond the minimum authorized evidence.
- Testing a third-party dependency, tenant, cloud account, or network not expressly included in scope.
3. Prohibited content and conduct
- Illegal, infringing, deceptive, defamatory, abusive, or privacy-invasive activity.
- Processing highly sensitive or regulated information without a lawful basis and appropriate written agreement.
- Using audit output to misrepresent certification, legal compliance, security, accessibility, endorsement, or guaranteed search results.
- Sharing accounts, bypassing seat limits, reselling access outside authorized client work, or circumventing payment and entitlement controls.
- Attempting to reverse engineer, scrape, probe, or attack Asuruas itself outside the Responsible Disclosure policy.
4. Crawler safety
- Use reasonable crawl delay, concurrency, depth, response-size, and timeout settings.
- Honor robots directives and site-owner instructions unless a lawful, authorized reason is documented.
- Exclude logout, destructive, payment, order, admin, search-amplification, and high-cost endpoints unless specifically required and safe.
- Do not place passwords, session cookies, API keys, private keys, or permanent secrets in reusable headers or forms.
- Stop and report unexpected exposure of credentials, private records, or sensitive personal information.
6. Email, webhooks, and integrations
- Use only destinations you control or are authorized to contact.
- Do not send spam, purchased lists, deceptive messages, or unlawful marketing through Asuruas.
- Protect webhook and integration secrets and validate received signatures.
- Do not use integrations to exfiltrate Customer Data or bypass role controls.
7. Enforcement
We may throttle, quarantine, cancel jobs, disable a feature, suspend an account, preserve evidence, or terminate service when reasonably necessary to address suspected violation or immediate risk. We consider severity, intent, history, cooperation, and impact and will provide notice and an opportunity to respond where practical.
8. Reporting
Report abuse or unsafe behavior to clancaster@lancastersolutionsllc.com. Security vulnerabilities should follow the Responsible Disclosure page. Effective August 9, 2026.