Security audits and testing are not permitted
Ordinexis Sdn Bhd does not permit unsolicited or self-initiated security audits, vulnerability assessments, penetration tests or adversarial testing of its systems. This applies to manual activity, automated tools, third-party services and AI agents acting on your behalf.
No assets are in scope for public security testing. This website does not offer an open audit, security research or bug bounty programme. Do not start an assessment or commission someone else to perform one against our services.
This policy does not replace an express right or obligation in a separately signed agreement or mandatory law. A purchasing discussion, security questionnaire, support exchange, trial account or informal conversation is not such an agreement and does not grant testing rights.
Systems and environments covered
The restrictions apply to Ordinexis-controlled websites, product consoles, public demos, APIs, integrations, voice endpoints and supporting infrastructure, including services provided for iKB, SalamAI, Saloma AI and MataAI. They apply whether an endpoint is advertised, linked, authenticated or publicly reachable.
Access to your own account does not permit testing tenant separation, another account, administrator functions or the shared service. Customer environments and third-party infrastructure have their own owners and access rules; this policy grants no authority over them.
Activities that are prohibited
- Automated vulnerability scans, active reconnaissance, security crawlers, endpoint or account enumeration, fuzzing and bulk probing intended to find weaknesses.
- Attempts to exploit a vulnerability, bypass authentication or access controls, escalate privileges, or inspect another user's information.
- Credential guessing, password spraying, session manipulation, extraction of secrets or tokens, and attempts to gain persistence.
- Load, stress, denial-of-service or resource-exhaustion tests, including excessive model requests, voice sessions or calls.
- Adversarial prompt injection or model probing intended to bypass security boundaries, expose protected data or invoke unauthorised tools.
- Phishing, social engineering, physical intrusion, or testing our staff, customers or suppliers as a way to assess our security.
The same restrictions apply if a scanner labels its activity "passive", "non-destructive" or "read-only" but sends probes to our systems. An intention to help does not make prohibited testing permitted.
What ordinary product evaluation allows
You may browse published information, use a product or demo through its intended interface, and evaluate its advertised functions within the applicable terms and limits. For example, you may try a non-sensitive translation or a normal Web Talk conversation. You must not turn that access into security probing or attempts to extract protected information.
"AI You Can Audit" refers to reviewing AI outputs, sources, operating records and controls where those product capabilities are available. It is not an invitation to audit, attack or probe the underlying infrastructure. Reviewing an answer for correctness is different from attempting to cross a security boundary.
If you are unsure whether an activity is ordinary permitted use, do not proceed with the questionable activity. Asking a question or receiving no reply does not grant permission.
Business security questions and due diligence
Prospective and existing customers can send security questions or contractual requirements to hey@ordinexis.com. We can discuss the available product information and the appropriate route for a business review.
A request for due diligence does not grant access to systems, source code, private records or another customer's information, and does not guarantee an audit report or certification. Do not arrange a third-party scanner or assessor against our services on the basis of a procurement requirement alone.
If an issue appears during normal use
Stop at the observation. Do not repeat the action, expand the investigation, collect additional data or ask another person to reproduce it. Report what you already know using our Responsible Disclosure Policy.
The disclosure channel exists so concerns can be reported privately. It does not permit testing before or after a report, and it does not provide retrospective approval for unauthorised activity.
Protective action and policy boundaries
Ordinexis may block traffic, suspend access, preserve relevant security records or take other proportionate protective action when activity threatens services or breaches applicable terms. Suspected unlawful activity may be referred to the appropriate authorities. These actions remain subject to applicable law and any relevant agreement.
This policy is not a statement that our systems are free from vulnerabilities, have passed a particular audit, or hold a security certification. Read it with our Terms & Conditions, Privacy Policy and AI Use Policy. Nothing here removes rights or obligations that cannot lawfully be excluded.
Ordinexis Sdn Bhd / Kuala Lumpur, Malaysia
Back to top