1. Scope
Andromalius is a software product provided by Richard Kowalczyk, a New York sole proprietor. This policy applies to the website, API, audit products, reports, support channels, and associated integrations. The founding beta is limited to United States business users age 18 or older.
2. Required authority
You may submit only artifacts you own or are authorized to analyze. An Andromalius report does not grant permission to access, test, scan, exploit, or interfere with the system described by an artifact.
3. Prohibited use
You must not use Andromalius to:
- violate law, sanctions, export controls, intellectual-property rights, privacy rights, or contractual restrictions;
- submit private keys, recovery phrases, credentials, malware, unnecessary personal data, confidential customer data, or unlawfully obtained material;
- attack, probe, overload, scrape, reverse engineer, evade limits, or interfere with Andromalius or any provider;
- conceal unlawful payment flows, launder funds, manipulate activity, conduct wash transactions, or evade screening;
- falsely describe an automated report as a certification, guarantee, endorsement, complete security review, or authorization to access a system; or
- use a report or service output to facilitate exploitation or unauthorized access.
4. Enforcement
We may reject, rate-limit, preserve, suspend, or report activity when reasonably necessary to protect the service, users, providers, or comply with law. We may deny future access without refund when the purchased service was delivered or the request materially violated this policy, subject to non-waivable law and the Refund Policy.
5. Security reports
Report a suspected vulnerability privately to security@andromalius.io before disclosure. Do not test the public service beyond ordinary documented use without prior written authorization. These interim policies do not create a security-research safe harbor.