Skip to main content
ThreatHunt and ThreatContain revealed.See the announcements
Legal

Acceptable Use Policy

The rules of the road for using Vijilan services.

Last updated · July 2026
Who this applies to: Vijilan sells exclusively through partners. This policy binds our partners and, through them, the end clients whose environments we monitor. Where an executed agreement between Vijilan and a partner says something different, that agreement governs.

Purpose

Vijilan operates a 24/7 security operations center with privileged visibility into partner and client environments. That access only works if everyone using it does so lawfully and in good faith. This policy sets out what is and is not acceptable use of Vijilan services, portals and APIs.

Prohibited use

You may not use Vijilan services to:

  • Break the law, or help anyone else do so.
  • Access, scan, test or attack any system you are not clearly authorized to act on. Authorization must be documented and current; a past engagement is not standing permission.
  • Exfiltrate, resell or otherwise misuse security telemetry, detections, threat intelligence or client data obtained through the service, including data belonging to another partner or client.
  • Deploy malware, ransomware, command-and-control infrastructure, credential-stuffing tooling or denial-of-service capability, other than in a controlled engagement you are contractually authorized to run.
  • Attempt to bypass authentication, escalate privilege, disable logging or evade detection within Vijilan systems, or probe our infrastructure without written permission.
  • Share credentials, portal access or API keys outside the people named on your account, or leave them in source control, tickets or chat.
  • Interfere with the integrity or performance of the service for other partners.
  • Misrepresent Vijilan’s role, certifications or findings — including presenting our reports as your own independent audit, or Vijilan as a direct supplier to an end client.

Your responsibilities

  • Keep account and portal access limited to people who need it, and remove access promptly when they leave.
  • Enable and keep multi-factor authentication on every account that has it available.
  • Hold the authorizations you assert. When you onboard a client environment you are confirming that the client has agreed to the monitoring and to any response actions we may take on their behalf.
  • Report suspected compromise of your own credentials or of a monitored environment without delay.
  • Keep the contact details we hold for you current — an incident is the wrong moment to discover they are stale.

Security research

We welcome good-faith reports of vulnerabilities in our own systems. Report them to security@vijilan.com before disclosing anywhere else, and give us a reasonable window to remediate. Do not access, modify or retain data belonging to anyone else while testing, and do not run denial-of-service or social-engineering tests against us or our partners. Research conducted on those terms will not be treated as a breach of this policy.

Enforcement

Where we believe this policy has been breached we may suspend affected access. Our strong preference is to contact you first and resolve it together, and we will do that wherever the circumstances allow. Where a breach is causing active harm — to another partner, to a client environment, or to the integrity of the service — we may suspend access immediately and notify you straight after. Serious or repeated breaches can lead to termination under your service agreement.

Changes and contact

We may update this policy as our services change; material changes will be communicated to partners through the usual account channels. Questions about this policy go to legal@vijilan.com. To report misuse, contact soc@vijilan.com.