Authority and scope
You may only propose testing for systems you own or have explicit authority to test. Authorization must identify the target, permitted techniques, accounts, dates, exclusions, and an emergency contact. Apparent public availability is not authorization.
Prohibited activity
No testing of third-party targets; denial of service; destructive actions; malware deployment; credential theft; persistence; social engineering; physical testing; data exfiltration; evasion of agreed limits; unlawful surveillance; or attempts to access another customer’s information.
Credentials and data
Do not submit secrets through the marketing site. A future pilot may use purpose-built least-privilege credentials through a separately approved channel. Test data should be synthetic where practical, and sensitive findings must be handled on a need-to-know basis.
Agent actions and human control
Proposed agents would operate only inside approved controls. Human operators and customers remain responsible for scope decisions, approvals, remediation, and escalation. Agent output must not be treated as authority to expand testing.
Enforcement
We may reject or stop a request that lacks authority, creates material safety risk, or violates these rules. Suspected illegal or harmful activity may be preserved or disclosed when required by applicable law.