Responsible use
Authorized defense. Hard boundaries.
Evil AI is being built to improve systems with their owners—not to create an exploitation service, scan arbitrary targets, or manufacture certainty.
Authorization is mandatory
Automated and expert-assisted testing may cover only systems the customer owns or is explicitly authorized to test. Scope, environments, exclusions, test windows, contacts, data handling, and stop conditions must be recorded.
Automation remains bounded
- No unsolicited or surprise scanning
- No testing initiated from a public inquiry alone
- No destructive exploitation, persistence, evasion, or denial of service
- No credential harvesting or unnecessary sensitive-data collection
- No treating inconclusive automated results as confirmed vulnerabilities
- No claim that a score or assessment proves complete security or compliance
Expert assistance
Expert-assisted work is separate from automated plans. It begins only after a suitable independent specialist, credentials, scope, terms, confidentiality, and price are disclosed and accepted.
Evidence and disclosure
Reports are private by default. Evidence is limited to what is required to understand and remediate a finding. Public disclosure requires explicit, dated, scope-aware customer approval.
Stop-work authority
Testing stops when scope or authority is uncertain, unexpected harm is plausible, sensitive data appears unnecessarily, authorization is withdrawn, or an emergency condition is met.
Private beta · authorized applications only