Our security

A security company should minimize what it asks you to trust.

RulesHold keeps public intake deliberately limited and separates an assessment request from authorization to test.

Public intake is non-sensitive

We do not ask for credentials, API keys, production tokens, customer records, source archives, or confidential architecture files through the public request form.

No testing by form submission

Submitting a target or company website is not authorization. Scope, Rules of Engagement, and written authorization are separate prerequisites.

Scope comes first

Assessment boundaries, authorized targets, identities, exclusions, timing, and stop conditions are agreed before intrusive testing begins.

Evidence is handled deliberately

Sensitive access details and assessment evidence are not requested through the public intake form. Appropriate handling is defined after scope and authorization are established.

Findings are validated

RulesHold aims to report findings that are reproducible, evidence-backed, connected to impact, and useful for remediation rather than producing alert volume for its own sake.

Retesting matters

Where included in scope, remediation is followed by retesting to determine whether the original security path has actually been closed.