What we will never do.
We are an offensive tool pointed at your own systems. That only works if the boundaries are explicit — so here they are, with the limits we will not paper over.
Agentless by default.
Connecting a cloud installs nothing on your servers, and credentials are verified with a real call before they are stored. Public targets require verified domain ownership before we test them. Removing a member revokes their live tokens immediately; deactivating a user in your IdP through SCIM does the same.
Findings map to the frameworks your auditor already uses.
SOC 2 · ISO 27001 · ISO 42001 · PCI DSS · HIPAA · NIST AI RMF · NIST CSF 2.0 · EU AI Act · GDPR Articles 25 and 32. Those mappings are stated as evidence toward a control — never as a pass. We are not your auditor, and a vendor that tells you it has certified you has told you something untrue.