Purpose
Vijilan operates a 24/7 security operations center with privileged visibility into partner and client environments. That access only works if everyone using it does so lawfully and in good faith. This policy sets out what is and is not acceptable use of Vijilan services, portals and APIs.
Prohibited use
You may not use Vijilan services to:
- Break the law, or help anyone else do so.
- Access, scan, test or attack any system you are not clearly authorized to act on. Authorization must be documented and current; a past engagement is not standing permission.
- Exfiltrate, resell or otherwise misuse security telemetry, detections, threat intelligence or client data obtained through the service, including data belonging to another partner or client.
- Deploy malware, ransomware, command-and-control infrastructure, credential-stuffing tooling or denial-of-service capability, other than in a controlled engagement you are contractually authorized to run.
- Attempt to bypass authentication, escalate privilege, disable logging or evade detection within Vijilan systems, or probe our infrastructure without written permission.
- Share credentials, portal access or API keys outside the people named on your account, or leave them in source control, tickets or chat.
- Interfere with the integrity or performance of the service for other partners.
- Misrepresent Vijilan’s role, certifications or findings — including presenting our reports as your own independent audit, or Vijilan as a direct supplier to an end client.
Your responsibilities
- Keep account and portal access limited to people who need it, and remove access promptly when they leave.
- Enable and keep multi-factor authentication on every account that has it available.
- Hold the authorizations you assert. When you onboard a client environment you are confirming that the client has agreed to the monitoring and to any response actions we may take on their behalf.
- Report suspected compromise of your own credentials or of a monitored environment without delay.
- Keep the contact details we hold for you current — an incident is the wrong moment to discover they are stale.
Security research
We welcome good-faith reports of vulnerabilities in our own systems. Report them to security@vijilan.com before disclosing anywhere else, and give us a reasonable window to remediate. Do not access, modify or retain data belonging to anyone else while testing, and do not run denial-of-service or social-engineering tests against us or our partners. Research conducted on those terms will not be treated as a breach of this policy.
Enforcement
Where we believe this policy has been breached we may suspend affected access. Our strong preference is to contact you first and resolve it together, and we will do that wherever the circumstances allow. Where a breach is causing active harm — to another partner, to a client environment, or to the integrity of the service — we may suspend access immediately and notify you straight after. Serious or repeated breaches can lead to termination under your service agreement.
Changes and contact
We may update this policy as our services change; material changes will be communicated to partners through the usual account channels. Questions about this policy go to legal@vijilan.com. To report misuse, contact soc@vijilan.com.