Acceptable Use Policy

Authorization and safety requirements for using LaunchSafe to test applications and infrastructure.

Last updated: July 2026

Authorization required

You may use LaunchSafe only against systems you own or are explicitly authorized in writing to test. Authorization must cover the target, testing window, techniques, credentials, data handling, and expected operational impact. You are responsible for maintaining evidence of authorization.

Scope and rules of engagement

  • Submit accurate target, environment, repository, branch, and credential information.
  • Exclude third-party services and shared infrastructure unless authorization expressly includes them.
  • Use test environments and synthetic data when feasible.
  • Identify production constraints, prohibited actions, rate limits, and emergency contacts before testing.
  • Reconfirm authorization when scope, ownership, or infrastructure changes.

Prohibited use

  • Testing systems without ownership or written authorization.
  • Destructive testing, data deletion, ransomware, persistence, backdoors, cryptomining, or malware deployment.
  • Denial-of-service, traffic flooding, resource exhaustion, or intentional service degradation.
  • Social engineering, phishing, credential theft, physical intrusion, or surveillance.
  • Accessing, retaining, or disclosing third-party data beyond the minimum needed to validate an authorized finding.
  • Evading safeguards, concealing identity or scope, reselling unauthorized access, or using the service to facilitate harm.

Credentials and sensitive data

Use dedicated, least-privilege testing credentials. Do not submit production secrets unless necessary and expressly authorized. Revoke or rotate testing credentials when an engagement ends or exposure is suspected.

Unexpected impact

If testing affects availability, exposes out-of-scope data, crosses a trust boundary, or creates unexpected risk, stop the activity, preserve relevant evidence, and notify the target owner and LaunchSafe. Do not continue testing merely to increase impact.

Enforcement

LaunchSafe may pause testing, restrict functionality, suspend accounts, preserve relevant records, or terminate access when activity appears unauthorized, unsafe, abusive, or unlawful. We may cooperate with affected parties and authorities when legally required.

Reporting abuse

Report suspected misuse or unsafe activity to security@launchsafe.com.