You must
- Verify ownership of every target before scanning (domain DNS, file upload, or SSH credentials).
- Stay within the scope, rate limits, and timing windows you defined.
- Protect any credentials, tokens, or evidence produced during a run.
- Stop testing immediately if authorization is withdrawn or unexpected impact appears.
You must not
- Target systems, accounts, or data you do not own or have permission to test.
- Deploy malware, ransomware, destructive payloads, or credential-harvesting tools.
- Attempt denial of service, brute-force authentication, or resource exhaustion.
- Use findings to extort, harass, stalk, or discriminate against anyone.
- Resell or redistribute scan evidence outside your organization.
- Upload unlawful content or unnecessary personal data.
Enforcement
Elenxo may pause agents mid-run, preserve relevant records, restrict features, or suspend accounts when activity presents a credible safety, security, or legal risk. We cooperate with lawful investigations as required.

