Security boundaries
How OrgRecon authorizes assessments, protects targets, and limits retained data.
Authorization
OrgRecon is owner-authorized and invite-only. Scans are limited to exact approved hosts; any path on an approved host can be selected as the scan entry point. Discovery of a related hostname does not authorize it.
Scanner safety
Checks are deterministic, bounded, and non-mutating. OrgRecon does not execute exploits, submit forms, click through workflows, or invoke actions whose read-only behavior cannot be established.
Data handling
Reports retain normalized observations, field names, counts, hashes, and evidence provenance. Raw Salesforce record values, record IDs, Salesforce access tokens, Salesforce refresh tokens, cookies, and response bodies are not retained or sent to the report assistant. WorkOS application-session refresh credentials are held only in a secure HTTP-only browser cookie to rotate the signed-in session.
Acceptable use
Use OrgRecon only for assets you own or are explicitly authorized to assess. Internet-wide or arbitrary third-party scanning is not supported.
Responsible disclosure
Report a security concern privately to [email protected]. Do not include customer data or credentials.