Authorized use
Assessments under clear authority
Last updated: August 4, 2026
Moyo is a product of SenTeGuard Inc.. Assessments are not free-form red team theater. We only perform work under clear authority, lawful sources, defined scope, and documented data handling.
Assessments are performed only:
- 01
With customer authorization
Preliminary scans require the submitter’s confirmation, by submitting the request form, that they are authorized to request an assessment of the named organization or that only lawful public sources will be used. Extended reports and white-box engagements require written authorization (and a statement of work where applicable) from the customer or another lawful authorizing party.
- 02
Against customer-owned systems or lawful public sources
Outside-in work uses lawful public information, not unauthorized private access. White-box and internal testing target systems, corpora, and endpoints the customer owns or is otherwise authorized to have tested. We do not accept unsolicited confidential uploads through open public forms.
- 03
Within an agreed scope
Domains, organizations, source categories, systems in scope, success criteria, and out-of-scope activity are agreed before deep work. Preliminary requests collect “what we should examine” to guide a limited public review, not an unbounded hunt.
- 04
With documented retention and deletion rules
Marketing contact fields, public-source working sets, customer confidential materials, and generated findings are retained and deleted under rules described in our privacy policy and, for paid work, in the engagement SOW. Customer confidential data is not kept indefinitely “just in case.”
What we will not do
- · Assess private systems without written authorization
- · Treat a web form alone as authority for white-box testing
- · Accept confidential documents from anonymous public form submissions
- · Expand beyond the agreed scope without updated authorization
- · Imply that a software license alone authorizes testing of third-party private systems
Licensed deployments of Moyo remain subject to the same authorization principles: the licensee must only analyze organizations and systems they are entitled to examine, using lawful public sources or in-scope customer-authorized assets. See software licensing.