Purpose and Scope
We may send a limited business security notice when fresh public evidence shows a material issue and the recipient can verify it independently.
Orbitwise OÜ (registry code 17396410) operates BoringSec. This policy governs narrowly targeted business-to-business email about security-posture evidence observed on a public website and the related BoringSec report or recheck.
It does not authorize exploitation, authenticated testing, access-control bypass, publication of sensitive evidence, indiscriminate bulk email, purchased contacts, or communication with private individuals. It is not a promise that every technically reachable address or jurisdiction is eligible for automated outreach.
The primary commercial market for this version is the United States. Standard initial messages and follow-ups are treated as commercial email and must satisfy the applicable CAN-SPAM controls described below. A generic top-level domain is not represented as proof that a business is physically located in the United States.
Evidence Boundary
An automated message needs a recent passive assessment, enough coverage, a material signal, and a safe explanation of its limits.
Automated approval is available only when all applicable controls pass, including:
- a bounded, read-only assessment of the public surface;
- fresh, final, non-provisional evidence from the approved source path;
- sufficient coverage and a material security-posture signal;
- a recipient-safe summary that does not expose secrets or an exploit path;
- a new pre-send verification when the evidence has become stale; and
- an honest statement that a public scan is not a penetration test or proof of compromise.
The assessment and scoring boundaries are described in the BoringSec Methodology.
Recipient and Jurisdiction Boundary
We use attributable public business or security contacts, never bought or guessed personal addresses, and fail closed when jurisdiction is unclear.
An autonomous recipient must satisfy every applicable recipient control:
- the address is an attributable public business or security contact for the assessed domain, with the required independent source confidence;
- the mailbox is deliverable, role-relevant, and not a no-reply or privacy proxy;
- a role mailbox published on the assessed company's own public website may qualify when it is on-domain, attributable to that hostname, relevant to security or ordinary business enquiries, and passes deliverability checks;
- the address and registrable domain are not suppressed or inside a cooldown;
- the domain and address are not duplicate targets in another active sequence; and
- the jurisdiction is covered by the current approved policy. Unknown, conflicting, or manual-only jurisdictions do not receive an automatically approved message.
Government, military, critical-infrastructure, healthcare, education or research, non-profit, personal, and public-figure targets are outside the autonomous commercial path. A technical finding alone does not make a target commercially eligible.
Message and Cadence
The first note is evidence-first, follow-ups are capped, and any reply or opt-out stops automation immediately.
- The initial message identifies BoringSec and the public domain assessed.
- The message is clearly presented as a commercial security-report offer; sender, From, Reply-To, routing information, and subject must be accurate and non-deceptive.
- It describes only the safe problem class, timestamp, evidence limits, and a self-service recheck.
- It may explain the value of a paid report without threats, fear tactics, or a claim that the site was breached.
- Only a bounded number of spaced follow-ups is permitted; there is no endless sequence.
- Payment, any human reply, unsubscribe, complaint, hard bounce, do-not-contact request, or suppression immediately stops the automated sequence.
- The unsubscribe mechanism remains available for at least 30 days after a message, and an opt-out is honoured no later than 10 business days after receipt.
Discounts, coupons, changed prices, contracts, legal conclusions, and non-standard commitments are not covered by automatic approval.
Delivery, Audit, and Emergency Stop
Every attempt is rate-limited, deduplicated, recorded, and governed by an immediate operator kill switch.
The delivery path applies:
- global, per-domain, per-recipient daily and weekly volume limits;
- provider idempotency so a retry cannot silently create a duplicate email;
- suppression and pre-send eligibility checks at the final provider boundary;
- a durable policy-decision receipt before provider I/O;
- bounce and complaint monitoring with an automatic circuit breaker; and
- a master outbound-email kill switch that an operator can disable immediately.
A software worker may approve only a message that passes the declared policy. BoringSec operators can pause the database sending gate or master outbound delivery without weakening the audit trail.
Privacy and Contact Choice
We keep only the minimum contact and delivery evidence needed for the bounded sequence, and every message provides an easy opt-out.
We process the minimum public business-contact, assessment, delivery, suppression, and conversion data needed to evaluate and operate this outreach. Where permitted, this processing is based on the legitimate interests of helping an organization understand a material public security-posture signal and offering a relevant report, balanced against recipient privacy, context, and contact preferences.
Every message includes sender identification, a physical postal address, and a visible unsubscribe path. Unsubscribing, objecting, or asking not to be contacted creates a suppression record for future outreach. Read the Privacy Policy or contact privacy@boringsec.com to exercise a data protection right.
Policy Identity and Review
This is boringsec-us-commercial-outreach/v2. Material changes require a new version and production configuration review.
Policy version: boringsec-us-commercial-outreach/v2. Material changes to recipient scope, jurisdiction allowlists, evidence thresholds, cadence, provider identity, or suppression controls require a new version and a reviewed production configuration.
Security questions about BoringSec itself should go to security@boringsec.com. Privacy objections and contact preferences should go to privacy@boringsec.com.
See the BoringSec Trust Center for the broader data, provider, and security-control boundaries.