Politique d’utilisation de l’outil

Limites de la revue passive publique, contrôles approfondis autorisés et gouvernés et règles de fonctionnement de la famille de produits.

Cette politique explique ce que l’outil est conçu pour faire, ce qu’il refuse de faire, comment la vérification privée et les résultats noindex sont gérés, et comment les preuves de connecteurs en lecture seule, les exports fiables, la cartographie de l’écosystème fournisseurs, l’inventaire passif des actifs, la supervision, l’historique et la remédiation accompagnée par KMayer restent gouvernés.

Identité and ownership

Identité du fournisseur and output ownership stay explicit so the tool is not mistaken for a separate company or an unrestricted content source.

Identité du fournisseur et de l’outil

Utilisation gouvernée
  • KMayer est le fournisseur. KMayer Exposure Lens AI est l’outil et la famille de services proposés par KMayer pour la revue passive de posture externe, les résultats privés vérifiés et la revue approfondie gouvernée lorsque les conditions sont réunies.
  • The tool name should not be read as a separate company, a stand-alone managed-service provider, or an identity outside KMayer.

Copyright, IP et output-use boundary

Internal review
  • © 2026 KMayer. Tous droits réservés. KMayer owns the tool interface, report layout, scoring logic, summaries et visual presentation.
  • Private outputs are provided for the requesting recipient's internal review and may not be copied, republished, resold, reverse engineered, or used to create a competing service without written permission from KMayer.

Mode public et sécurité

The public lane is useful because it stays bounded, passive et verification-aware.

Public lane exclusions

Passive only
  • The public lane allows no brute force, no exploit workflow, no credential attacks, no intrusive testing in the public lane, no private data access et no bypass attempts.
  • Deeper review requires verified ownership, active engagement, approved scope et explicit consent.

Limites de la revue passive publique

Passive only
  • Every anonymous request starts in passif public and stays limited to public DNS, mail posture, HTTPS, TLS, visible headers, trust files, indexing signals et a tightly capped set of same-host public pages.
  • The public lane is designed to show what matters first in a revue passive de posture externe. It is not presented as a full security assessment or unrestricted discovery workflow.

No exploit behavior, no brute force, no login attempts et no intrusive testing

No exploit behaviorNo brute force
  • No exploit attempts, no exploit workflow, no credential attacks, no credential spraying, no brute-force discovery, no authenticated interaction, no private data access, no bypass attempts, no hidden-path probing et no offensive testing in the public lane.
  • No active internet-wide scanning, no private endpoint guessing, no intrusive testing in the public lane et no following of unrelated third-party estates discovered in page content.

Vérification privée et gestion des accès

Verified access
  • L’e-mail de vérification est envoyé en premier et no private result delivery occurs until the intended recipient completes the verification click.
  • Private routes use opaque tokens, verification-aware access controls, safe reuse or expiry behavior et results-ready email delivery only after verification and completion.

Gouvernered deeper evidence

revue approfondie autorisée, connector-backed evidence et intelligence issue d’exports fiables remain approval-based and non-offensive.

prérequis revue approfondie autorisée

Gouvernered deep review
  • revue approfondie autorisée requires verified ownership, active engagement, approved scope et explicit consent for the reviewed domain, account, or evidence source.
  • The deeper lane is not anonymously available and it does not replace the passive boundary that applies to public submissions.

Preuves de connecteur en lecture seule

Preuves en lecture seule
  • Only preuves de connecteurs en lecture seule is permitted et only when the reviewed tenant or domain is approved for that governed workflow.
  • Connector-backed evidence must stay attributable, bounded et tied back to the reviewed account or domain instead of being used as a broad authenticated scanning path.

Trusted exports, quarantine, review et approved-for-parse controls

Approved export
  • Trusted exports and customer-provided artifacts are not parsed on arrival. They enter quarantine first and remain blocked until scanner or manual review plus approved-for-parse controls allow structured extraction.
  • Refusered, unapproved, or out-of-scope artifacts do not become active evidence simply because they were uploaded.

Advanced capability boundaries

Advanced output stays evidence-backed and governed instead of turning into unlimited discovery or public leakage.

Limites de l’écosystème fournisseurs et de l’inventaire passif des actifs

Passive only
  • La cartographie de l’écosystème fournisseur et l’inventaire passif des actifs restent appuyés par des preuves. Ils utilisent d’abord les preuves publiques et peuvent ensuite inclure des confirmations de connecteur ou d’export approuvées si le workflow y est éligible.
  • These capabilities do not authorize intrusive subdomain brute forcing, internet-wide active probing, or silent conflict collapse when evidence disagrees.

Supervision, historique et comportement noindex des résultats privés

Verified accessnoindex privé
  • Monitoring and history apply only where that continuity is enabled. The system may retain diffs, alerts, audit trails, suppression context et change explanations so recurring behavior stays explainable instead of noisy.
  • Les pages publiques d’information peuvent être indexées, mais les résultats privés restent noindex, noarchive, nofollow et hors découverte par sitemap pour le parcours du destinataire vérifié.

Assisted remediation and deeper review boundaries

Gouvernered deep review
  • The product is designed to show what matters, why it matters et what to fix first. It is not packaged as a full self-serve remediation playbook for every environment.
  • KMayer can help validate findings, review revue approfondie autorisée eligibility, interpret approved evidence sources et move the work into assisted remediation planning when the engagement supports it.

What revue approfondie autorisée changes for decision quality

Gouvernered deep review
  • It can improve provenance, ownership confidence, provider alignment et the quality of remediation sequencing when the engagement is eligible.
  • It does not mean anonymous public scans automatically gain private connector, export, or monitoring context.

What remains intentionally governed

Utilisation gouvernée
  • Les résultats privés sont volontairement prêts pour la décision, mais les internes bruts des connecteurs, les artefacts non restreints et les classeurs propres à l’environnement ne sont pas exposés comme un blueprint ouvert.
  • KMayer-assisted remediation is the path for deeper control validation, sequencing et change planning when the engagement supports it.

Confidentiality and reliance

Livraison privée, completeness limits et reliance boundaries stay clear before the tool is promoted more broadly.

Confidentiality and private result URLs

Verified accessnoindex privé
  • Les résultats privés sont contrôlés, non indexés et destinés au destinataire vérifié. Ne transférez pas les URL de résultats privés à des parties non autorisées.
  • KMayer may use submitted details and governed evidence sources to deliver the review, provide follow-up support et maintain quality, audit et security controls around the workflow.

No guarantee of completeness

Utilisation gouvernée
  • The tool provides an evidence-backed external posture review, not a guarantee that every issue, dependency, exposure path, or control failure has been discovered.
  • Availability, scope, freshness et confidence can vary based on public evidence quality, approved access, third-party permissions et the governed workflow that applies to the review.

Not legal, compliance, penetration-test, or incident-response advice

Utilisation gouvernée
  • The output is informational and prioritization-oriented. It is not a legal opinion, a formal compliance attestation, a penetration-testing service, or incident-response advice.
  • If you need environment-specific legal review, full compliance interpretation, offensive testing, or incident response, KMayer can help route the work appropriately instead of implying this tool replaces those services.

User responsibility and acceptable use

Internal review

Use the tool only for domains and evidence sources you own, administer, or are authorized to assess, or for legitimate passive informational analysis where that use is appropriate. Do not use it for harassment, competitor surveillance, phishing, impersonation, unlawful monitoring, unauthorized investigation, or any attempt to bypass the governed revue approfondie autorisée controls.

Third-party and visual governance

Connector, dependency et future visual-asset use stay governed so the product is not misrepresented.

Third-party services and dependencies

Utilisation gouvernée
  • Connector outputs are read-only and remain subject to the permissions, terms, availability, rate limits et current configuration of the third-party services involved.
  • KMayer does not promise uninterrupted access to every external API, platform, or provider surface et evidence depth can change when those dependencies change.

Generated or assisted visual assets

Utilisation gouvernée
  • Any future generated visual asset requires KMayer approval before deployment and must not imply false certifications, fake customers, fake screenshots, or unsupported metrics.
  • Illustrative visuals must stay consistent with the KMayer brand and should be documented with source, prompt, date et approval state where practical.

Nous contacter and escalation path

Utilisation gouvernée
  • Use the Nous contacter page or [email protected] when you need clarification on scope, confidentiality, acceptable use, or a KMayer-led follow-up.
  • Si l’usage prévu, les preuves soumises ou la limite d’engagement ne sont pas clairs, faites une pause et confirmez avec KMayer avant de vous appuyer sur l’outil en dehors de ses règles de fonctionnement déclarées.

Lecture d’usage sûr

Lisez ces ressources avec la politique de l’outil pour clarifier les limites de la revue passive.

La politique reste la source de vérité opérationnelle. Ces guides ajoutent un contexte lisible métier pour l’exposition passive et les signaux de confiance.

FR
KMayer - IT Service Provider
Politique de confidentialité

Our website is committed to protecting your privacy. We collect and process data to enhance your experience, such as recognizing you when you return and understanding how you interact with our content. Your information is used responsibly to ensure that our services remain valuable, secure et tailored to your needs. For a detailed explanation of how we handle and protect your data, please refer to our Politique de confidentialité