This policy forms an integral part of the contractual set. It exhaustively defines the purposes for which the service may be used and the uses that are prohibited. It applies to the customer, its users, its staff and its subcontractors, for whom it is responsible.
Use of the service is limited to the following purposes, listed exhaustively:
Any use foreign to these purposes is prohibited. Where there is doubt as to whether a contemplated use falls within one of them, the customer refers the matter to Stealed beforehand.
The customer shall not:
The last prohibition applies neither to threat-led penetration testing conducted under Articles 26 and 27 of Regulation (EU) 2022/2554 (DORA), nor to penetration testing conducted by a customer that is an essential entity within the meaning of Directive (EU) 2022/2555 (NIS 2), under the corresponding addenda.
Keywords submitted for monitoring are directly linked to the security purpose pursued and contain no personal data. Prohibited are keywords corresponding to the name of a natural person, the name of a competitor, the name of a third party for which the customer is not responsible, and terms liable to reveal data falling under Article 9 of Regulation (EU) 2016/679.
Every keyword is subject to Stealed's prior approval, which may be refused without reasons and withdrawn at any time if its continued use appears incompatible with this policy.
The customer shall not publish, without Stealed's prior written agreement, any benchmark, performance measurement or element of the Platform's methodology. This restriction covers the technical and methodological elements belonging to Stealed.
It does not prevent the customer from expressing an opinion on the service, from using data relating to its own exposure, or from disclosing information to a supervisory authority, an auditor, an insurer or in legal proceedings.
The customer takes appropriate measures to prevent any misuse of the service by its users, staff and subcontractors. It informs Stealed without delay of any non-compliant use of which it becomes aware and puts an immediate stop to it.
It keeps its user list up to date, revokes without delay the access of persons who have left or changed roles, and applies to data extracted from the Platform the minimum measures set out in the security policy.
Stealed logs sensitive actions performed on the Platform and may carry out sample checks on compliance with this policy, without accessing the content of the customer's internal communications.
Any breach constitutes a material breach of the contractual set and permits immediate suspension of access, then termination by operation of law if the breach is not remedied within the period set by the formal notice.