Responsible Use
Authorization and operator accountability requirements.
Required Before Real Runs
A real run cannot start until the operator confirms authorization, accepted scope, allowed hosts, protected context, and typed confirmation.
Policy
- Authorized testing only.
- Only test systems you own or have explicit written permission to assess.
- The operator is responsible for target authorization and scope.
- No anonymous active testing against arbitrary targets.
- No denial-of-service testing unless explicitly scoped and separately enabled.
- No destructive testing.
- No persistence, malware, credential theft, exfiltration, or public exploitation.
- No social engineering.
- No attacks against third-party infrastructure outside the approved scope.
- No remediation, PR creation, or branch push actions.
- Findings are assessment outputs, not automatic fixes.
- Human review is required before real execution and before publishing reports.
- Private findings and artifacts remain protected.