Customer-facing controls
Email verification
Confirm the address used for website setup, invitations, billing, recovery, and protected operations.
Website authority verification
Require DNS, meta-tag, public-file, or approved managed evidence before a full website audit.
Roles and tenant boundaries
Separate owner, administrator, billing, member, and viewer responsibilities within the active organization.
MFA and recovery codes
Add a time-based second factor and one-time offline recovery codes.
Session review and revocation
Inspect active sessions and revoke access that is no longer recognized or authorized.
Abuse controls
Apply registration, recovery, audit, target-host, and organization controls designed to limit misuse.
Assessment boundaries
- Automated security checks identify observable conditions and configuration signals; they do not prove the absence of exploitable vulnerabilities.
- The customer remains responsible for ownership, permission, scope, credentials, rate, exclusions, and third-party systems.
- Denial-of-service testing, credential attacks, persistence, malware, destructive changes, social engineering, and unauthorized data access are prohibited without separate written authorization and controls.
- Unexpected sensitive-data exposure should stop the affected test and trigger the minimum necessary evidence-preservation and reporting process.
Operational safeguards
- Production startup rejects missing required secrets and Mailgun configuration.
- Stripe and Mailgun events are accepted only after signature validation and replay-window checks.
- Security-sensitive account, billing, scope, export, and operational actions are retained in audit records.
- High-impact production changes require appropriate review, testing, approval, rollback context, and verification.
How to use the security center
Use this page to understand Asuruas assessment boundaries, authorization requirements, evidence handling, disclosure channels, and the difference between an observable signal and a confirmed vulnerability.
- Confirm ownership or written authorization before testing.
- Use the narrowest scope and safest rate that can answer the question.
- Protect evidence and stop if sensitive data is exposed.
- Escalate high-impact findings through the responsible-disclosure process.
Turn security controls for accounts, website authorization, and audit evidence into an accountable record.
A clear public record of the purpose, boundaries, ownership, and next action for security controls for accounts, website authorization, and audit evidence.