Authorization is a requirement
You may only use Aethros against systems you own or for which you hold written authorization from the responsible party. Authorization must predate the test, be specific about the target, and be valid at the time of execution.
Public bug bounty programs count as authorization within the scope published by the program — and only within it.
Scope verification
Domains must be confirmed by DNS record before entering a scope. The agent refuses targets that are not declared. Circumventing that verification, by any means, violates this policy.
Prohibited uses
You may not use Aethros to:
- test, probe or access systems without authorization;
- carry out denial of service, or any action that degrades someone else's production service;
- develop or distribute malware, ransomware or extortion tooling;
- compromise third-party supply chains;
- evade detection for malicious purposes;
- collect personal data in bulk, or run surveillance on individuals;
- violate applicable law, including computer intrusion statutes in your jurisdiction.
What we log
Declared scopes, who authorized them and when, and the actions the agent executed are recorded append-only. That record serves your audit and ours — and may be required by a competent authority under a valid order.
Consequences
Violations lead to immediate account suspension, without refund of credits. Where there is evidence of a crime, we cooperate with authorities to the extent required by law.
Reporting abuse
If you suspect Aethros is being used against your infrastructure, write to abuse@aethros.io with whatever logs you have. We respond within 24 business hours.