Compliance & refusals

Toward good. We help asset owners harden systems they are allowed to test. We do not sell unauthorized intrusion.

We will not

  1. Test any target without recorded electronic/written authorization.
  2. Run destructive techniques (DoS, data destruction) by default.
  3. Operate an unlicensed vulnerability marketplace.
  4. Publicly disclose unpatched vulnerability details.
  5. Spam bug-bounty platforms with unverified AI noise.
  6. Accept opaque funds or off-books bounty skimming.

Legal anchors

  • China: Cybersecurity Law; Network Product Security Vulnerability Management Provisions; Criminal Law Art. 285.
  • US: CFAA — authorization is the threshold question.
  • EU: GDPR minimization; NIS2-aligned auditability for buyers.

This page is product policy, not legal advice. Engage licensed counsel before scaling in a jurisdiction.