JC·HARNESS

Responsible Use

Authorization and operator accountability requirements.

Required Before Real Runs

A real run cannot start until the operator confirms authorization, accepted scope, allowed hosts, protected context, and typed confirmation.

Policy

  • Authorized testing only.
  • Only test systems you own or have explicit written permission to assess.
  • The operator is responsible for target authorization and scope.
  • No anonymous active testing against arbitrary targets.
  • No denial-of-service testing unless explicitly scoped and separately enabled.
  • No destructive testing.
  • No persistence, malware, credential theft, exfiltration, or public exploitation.
  • No social engineering.
  • No attacks against third-party infrastructure outside the approved scope.
  • No remediation, PR creation, or branch push actions.
  • Findings are assessment outputs, not automatic fixes.
  • Human review is required before real execution and before publishing reports.
  • Private findings and artifacts remain protected.