Compliance & refusals
Toward good. We help asset owners harden systems they are allowed to test. We do not sell unauthorized intrusion.
We will not
- Test any target without recorded electronic/written authorization.
- Run destructive techniques (DoS, data destruction) by default.
- Operate an unlicensed vulnerability marketplace.
- Publicly disclose unpatched vulnerability details.
- Spam bug-bounty platforms with unverified AI noise.
- Accept opaque funds or off-books bounty skimming.
Legal anchors
- China: Cybersecurity Law; Network Product Security Vulnerability Management Provisions; Criminal Law Art. 285.
- US: CFAA — authorization is the threshold question.
- EU: GDPR minimization; NIS2-aligned auditability for buyers.
This page is product policy, not legal advice. Engage licensed counsel before scaling in a jurisdiction.