Acceptable Use Policy
OrgRecon is built for defensive assessment of Salesforce assets controlled by, or explicitly entrusted to, the person running the scan. This policy defines that boundary.
1. Who may use OrgRecon
Access is invite-only during the MVP. You must provide accurate account and organization information, protect your sign-in session, and use the service only for legitimate security, compliance, or remediation work.
2. Assets you may assess
You may assess a host only when you own it or have clear authorization from the owner to perform the requested security assessment. Authorization of one host does not authorize:
- another hostname, tenant, organization, or Salesforce customer;
- Salesforce shared infrastructure or provider-parent domains;
- a related asset that OrgRecon discovers but that has not been approved; or
- authenticated users, accounts, or private workflows outside the selected assessment.
You are responsible for ensuring that your authorization remains valid throughout the scan.
3. Permitted use
You may use OrgRecon to:
- inventory externally observable Salesforce and Experience Cloud surfaces on an approved host;
- run OrgRecon’s supported deterministic, non-mutating checks;
- review evidence-backed findings and coverage outcomes;
- use the report-bound assistant to understand existing findings; and
- rescan an approved host to verify remediation.
4. Prohibited use
You must not use OrgRecon, its APIs, packages, or reports to:
- scan or monitor an asset without the owner’s permission;
- evade host authorization, account boundaries, safety controls, request controls, or access restrictions;
- execute exploits, destructive tests, mutating Apex actions, form submissions, or payloads outside functionality explicitly provided by OrgRecon;
- obtain, retain, disclose, or misuse credentials, access tokens, session cookies, Salesforce record contents, personal data, or secrets;
- disrupt, degrade, overload, deny service to, or interfere with Salesforce, OrgRecon, a customer, or a third party;
- distribute malware, conduct phishing or social engineering, impersonate another party, or facilitate fraud;
- reverse engineer the service to defeat security controls or gain unauthorized access; or
- violate applicable law, regulation, contractual obligations, privacy rights, or intellectual-property rights.
5. Reports and findings
OrgRecon reports are defensive assessment artifacts. A discovered route, component, object name, or action reference is not proof of exposure unless the report separately confirms anonymous access. A clean or completed check is not a guarantee that an entire Salesforce organization is secure.
Do not publish a report containing another party’s asset information without that party’s authorization. Do not use a finding as permission to access or modify data.
6. Safety and incident reporting
Stop a scan if you believe it is causing unexpected impact or evaluating an unauthorized asset. Report suspected product security issues privately through the Responsible Disclosure Policy or email [email protected]. Do not send credentials or customer record contents.
7. Enforcement
OrgRecon may pause or revoke access, cancel scans, preserve relevant audit records, or take other reasonable action when use appears unsafe, unauthorized, unlawful, or inconsistent with this policy. Serious or repeated misuse may be reported to the affected owner, service provider, or appropriate authority where required.
8. Changes and contact
We may update this policy as the service and its safety controls evolve. Material changes will be reflected by a new effective date. Questions about permitted use can be sent to [email protected].