Authorized assessment policy

Acceptable Use Policy

OrgRecon is built for defensive assessment of Salesforce assets controlled by, or explicitly entrusted to, the person running the scan. This policy defines that boundary.

Effective July 27, 2026

Use OrgRecon only on assets you are authorized to assess. Do not use the service for arbitrary third-party scanning, disruption, exploitation, credential collection, or access beyond the approved host.

1. Who may use OrgRecon

Access is invite-only during the MVP. You must provide accurate account and organization information, protect your sign-in session, and use the service only for legitimate security, compliance, or remediation work.

2. Assets you may assess

You may assess a host only when you own it or have clear authorization from the owner to perform the requested security assessment. Authorization of one host does not authorize:

You are responsible for ensuring that your authorization remains valid throughout the scan.

3. Permitted use

You may use OrgRecon to:

4. Prohibited use

You must not use OrgRecon, its APIs, packages, or reports to:

5. Reports and findings

OrgRecon reports are defensive assessment artifacts. A discovered route, component, object name, or action reference is not proof of exposure unless the report separately confirms anonymous access. A clean or completed check is not a guarantee that an entire Salesforce organization is secure.

Do not publish a report containing another party’s asset information without that party’s authorization. Do not use a finding as permission to access or modify data.

6. Safety and incident reporting

Stop a scan if you believe it is causing unexpected impact or evaluating an unauthorized asset. Report suspected product security issues privately through the Responsible Disclosure Policy or email [email protected]. Do not send credentials or customer record contents.

7. Enforcement

OrgRecon may pause or revoke access, cancel scans, preserve relevant audit records, or take other reasonable action when use appears unsafe, unauthorized, unlawful, or inconsistent with this policy. Serious or repeated misuse may be reported to the affected owner, service provider, or appropriate authority where required.

8. Changes and contact

We may update this policy as the service and its safety controls evolve. Material changes will be reflected by a new effective date. Questions about permitted use can be sent to [email protected].