Public intake is non-sensitive
We do not ask for credentials, API keys, production tokens, customer records, source archives, or confidential architecture files through the public request form.
Our security
RulesHold keeps public intake deliberately limited and separates an assessment request from authorization to test.
We do not ask for credentials, API keys, production tokens, customer records, source archives, or confidential architecture files through the public request form.
Submitting a target or company website is not authorization. Scope, Rules of Engagement, and written authorization are separate prerequisites.
Assessment boundaries, authorized targets, identities, exclusions, timing, and stop conditions are agreed before intrusive testing begins.
Sensitive access details and assessment evidence are not requested through the public intake form. Appropriate handling is defined after scope and authorization are established.
RulesHold aims to report findings that are reproducible, evidence-backed, connected to impact, and useful for remediation rather than producing alert volume for its own sake.
Where included in scope, remediation is followed by retesting to determine whether the original security path has actually been closed.