Aethros

Updated February 2026

Acceptable use policy

Aethros is a security tool. The same capability that helps protect one system can be used to attack another — which is why this policy is short, specific, and enforced.

Authorization is a requirement

You may only use Aethros against systems you own or for which you hold written authorization from the responsible party. Authorization must predate the test, be specific about the target, and be valid at the time of execution.

Public bug bounty programs count as authorization within the scope published by the program — and only within it.

Scope verification

Domains must be confirmed by DNS record before entering a scope. The agent refuses targets that are not declared. Circumventing that verification, by any means, violates this policy.

Prohibited uses

You may not use Aethros to:

  • test, probe or access systems without authorization;
  • carry out denial of service, or any action that degrades someone else's production service;
  • develop or distribute malware, ransomware or extortion tooling;
  • compromise third-party supply chains;
  • evade detection for malicious purposes;
  • collect personal data in bulk, or run surveillance on individuals;
  • violate applicable law, including computer intrusion statutes in your jurisdiction.

What we log

Declared scopes, who authorized them and when, and the actions the agent executed are recorded append-only. That record serves your audit and ours — and may be required by a competent authority under a valid order.

Consequences

Violations lead to immediate account suspension, without refund of credits. Where there is evidence of a crime, we cooperate with authorities to the extent required by law.

Reporting abuse

If you suspect Aethros is being used against your infrastructure, write to abuse@aethros.io with whatever logs you have. We respond within 24 business hours.