Active scanning
Use scan routes only for assets you own or are explicitly authorized to test.- Maintain an allowlist outside FullHunt.
- Validate domains, hosts, public IPs, and CIDR ranges against approved scope.
- Require explicit confirmation before an agent or automation triggers a scan.
- Record the requester, target, purpose, and authorization reference.
- Apply time, request, credit, and polling limits.
- Stop immediately when authorization changes.
Passive intelligence
Passive records can still be sensitive or incomplete. Do not publish named third-party exposures without validation and a responsible disclosure process. Treat ownership and attribution fields as evidence requiring corroboration.Credentials and dark-web data
- Restrict access to staff with an incident-response need.
- Redact passwords and unrelated personal fields from logs, tickets, and reports.
- Do not use exposed credentials to access an account or system.
- Define retention, deletion, and breach-response requirements before collection.
- Store only the fields needed for investigation and notification.
