JC·HARNESS

Responsible Use

Authorization and operator accountability requirements.

Documentation Update Mode

This page is source-backed documentation and updates when the app is deployed. Live run, finding, report, artifact, credential, and integration state is shown on the linked operator surfaces rather than embedded here.

Required Before Real Runs

A real run cannot start until the operator confirms authorization, accepted scope, allowed hosts, protected context, and typed confirmation.

Policy

  • Authorized testing only.
  • Only test systems you own or have explicit written permission to assess.
  • The operator is responsible for target authorization and scope.
  • No anonymous active testing against arbitrary targets.
  • No denial-of-service testing unless explicitly scoped and separately enabled.
  • No destructive testing.
  • No persistence, malware, credential theft, exfiltration, or public exploitation.
  • No social engineering.
  • No attacks against third-party infrastructure outside the approved scope.
  • No remediation, PR creation, or branch push actions.
  • Findings are assessment outputs, not automatic fixes.
  • Human review is required before real execution and before publishing reports.
  • Private findings and artifacts remain protected.