Scope
This policy governs all use of services operated by Sanctum SecOps LLC: our websites and subdomains, the customer portal, operator consoles, the certificate storefront and its order path, our API and gateway endpoints, the service desk and knowledge base, and our research and laboratory hosts. It applies to you whether you are a customer, a customer's employee or contractor, a partner, or an anonymous visitor.
Where you have a signed agreement with us, that agreement controls and this policy supplements it. Where a certificate authority we front imposes its own subscriber terms, those terms apply to you in addition to these, and the stricter requirement wins.
General prohibitions
You may not use the services to do any of the following, or to help anyone else do it.
- Break the law, or infringe anyone's intellectual property, privacy or contractual rights.
- Distribute malware, ransomware, cryptominers, or any code designed to damage, disable or gain unauthorised access to a system.
- Run phishing, fraud, impersonation or social-engineering campaigns, or host content that supports one.
- Send unsolicited bulk email, or use anything you obtain from us to build or enrich a spam list.
- Publish or transmit content that is unlawful, defamatory, harassing, or that sexually exploits a minor.
- Misrepresent your identity, your organisation, or your authority to act for an organisation.
- Export or re-export our software, cryptographic modules or technical data in violation of United States export control law or sanctions, including to an embargoed destination or a denied party.
Certificates, keys and PKI
These obligations exist because a mis-issued certificate harms every relying party on the internet, not just you. Breach of any of them is grounds for immediate revocation without notice.
- Request certificates only for domain names, IP addresses and organisations you own or are demonstrably authorised to represent. Requesting a name you do not control is prohibited outright.
- Do not submit false, stale or misleading validation information, and do not obstruct or attempt to circumvent a validation check.
- Generate and hold your own private keys, protect them appropriately, and never transmit a private key to us, to a partner or to a certificate authority. We do not want it and will not accept it.
- Report a suspected private key compromise, a mis-issuance, or a certificate you did not request to us immediately so it can be revoked within the timelines the CA/Browser Forum requires.
- Do not use a certificate we supply to sign code you did not author or do not have the right to distribute, and do not use a certificate to intercept, proxy or decrypt traffic without the informed authorisation of the parties to it.
- Do not use a publicly trusted certificate to operate a certificate authority, or attempt to use an end-entity certificate as an issuing certificate.
- Do not use certificates, OCSP responders, CRL endpoints or trust artifacts in a way that misrepresents their scope — a test or private-hierarchy artifact must not be presented as publicly trusted.
- Do not use our free or per-transaction tools to assess or attack infrastructure you do not own or have written permission to test.
Platform, network and API conduct
- Do not attempt to gain unauthorised access to any account, host, container, network segment or dataset, or to escalate the privileges you were granted.
- Do not probe, scan or test the vulnerability of our systems except under our written authorisation or a coordinated disclosure process. Reporting a vulnerability you found incidentally is welcome; running a scanning campaign against production is not.
- Do not defeat, bypass or degrade a rate limit, quota, gate, access control, licence check or metering mechanism, and do not share credentials or API keys outside the accounts entitled to them.
- Do not overload, flood or otherwise impair the availability of the services for others, or use them to launch a denial-of-service attack elsewhere.
- Do not resell, sublicense or white-label the services unless a written agreement says you may, and do not use automated means to bulk-extract our content, catalogue or documentation.
- Do not reverse engineer or decompile our software except to the extent that law expressly permits and our licence does not override.
- Do not falsify, suppress or attempt to alter an evidence, audit or provenance record. The ledger is append-only; trying to rewrite it is treated as a security incident.
Your content and your users
You are responsible for everything submitted from your accounts, including by your employees, contractors and end users, and for making sure their use complies with this policy. You must have the rights and, where applicable, the consents needed for any personal information you send us, and you must not send us special category data, payment card numbers or health information through the service desk or ordinary email.
Do not upload anything to a ticket, repository or API that you are not permitted to disclose to us. Redact production secrets before sending logs; if you send us a live credential, we will tell you and you should treat it as compromised and rotate it.
Enforcement
We investigate suspected violations and may take any of the following steps, choosing the least disruptive one that actually addresses the problem.
- Ask you to remediate, with a deadline.
- Rate-limit, throttle or block specific traffic, addresses or credentials.
- Suspend an account, an API key or a gated surface.
- Revoke a certificate, immediately and without notice where a CA/Browser Forum revocation timeline or a key compromise requires it.
- Terminate the engagement under the termination provisions of your agreement.
- Preserve evidence and report the matter to law enforcement or to an affected certificate authority.
Where the situation allows it we will tell you first and give you a chance to fix it. Where it does not — an active attack, a key compromise, a mis-issuance, a legal demand, or a risk to other subscribers — we will act first and explain afterwards. We do not refund for a suspension or termination caused by your violation.
Reporting abuse
Report abuse, a suspected mis-issued certificate, a key compromise or a vulnerability to [email protected], with "Abuse" or "Security" in the subject line, and include enough detail to reproduce or verify the problem — hostnames, certificate serial numbers, timestamps with time zone, and what you observed. Reports about certificate mis-issuance are triaged ahead of everything else. For an urgent matter, telephone +1 (607) 378-8287.
We will not pursue a good-faith security researcher who stays within scope, avoids privacy violations and service degradation, does not exfiltrate data beyond what is needed to prove the finding, and gives us a reasonable opportunity to remediate before publishing.
Changes
We update this policy as the services and the governing requirements change, and the version in force is the one published here on the effective date at the top. Continued use after a change is acceptance of it. For a change that materially restricts permitted use, we will notify affected customers before it takes effect.
This version's digest is recorded in the Sanctum evidence ledger as a policy event, so a reader can confirm which text was in force on a given date. It is computed over every reader-visible string in this document, trimmed and newline-joined in document order, encoded UTF-8 — recompute it yourself if you want to check.