Responsible Use Policy
Last updated 1 September 2026
PenStrike is a powerful offensive-security tool. This policy defines how it must be used. It applies to everyone who uses PenStrike and forms part of our Terms of Service.
01Purpose
PenStrike emulates a real adversary to prove exploitable vulnerabilities. With that capability comes responsibility: it must only ever be pointed at systems that are in scope and properly authorized. This policy is not optional.
02Authorization is mandatory
You must hold valid, current, written authorization from the owner of every target before any testing begins. Authorization must define the in-scope assets, the permitted activities and the testing window. You are solely responsible for obtaining and retaining that authorization.
03Stay in scope
Testing is strictly limited to the assets you were authorized to test.
- Do not test hosts, domains, accounts, or services outside the agreed scope.
- Do not pivot or move laterally into systems that were not authorized.
- Stop and seek clarification if scope is ambiguous.
04Non-destructive by design
PenStrike is built to validate impact without causing harm. You must not use it to destroy or alter data, deploy ransomware-like behaviour, or run denial-of-service attacks. Proof of a finding must be bounded to what is necessary to demonstrate it, and nothing more.
05Prohibited targets and activities
- Any system you do not own or are not explicitly authorized to test.
- Third-party infrastructure, shared services or providers outside your authorization.
- Critical infrastructure, medical, or safety systems without specific written authorization.
- Exfiltrating, retaining, or exposing real user data beyond the minimum needed as proof.
- Any use that is illegal in the jurisdictions that apply to you or the target.
06Evasion and access capabilities
Features such as rotating residential egress, TLS impersonation, CAPTCHA solving and autonomous account creation exist to reach the surface a real attacker would reach. They may be used only within an authorized scope and never to attack, defraud or deceive third parties outside that scope.
07Data handling
Collect the minimum data required to prove a finding. Store any evidence securely, share it only with the asset owner and authorized stakeholders, and delete it when it is no longer needed. Treat all discovered data as confidential.
08Disclosure
Report findings to the asset owner through the agreed channel and follow coordinated, responsible disclosure. Do not publicly disclose vulnerabilities without the owner’s consent and a reasonable opportunity to remediate.
09Legal compliance
You are responsible for complying with all laws that apply to your testing, including computer-misuse, privacy and data-protection laws. When in doubt, obtain legal advice before you proceed.
10Enforcement
Violations of this policy may result in immediate suspension or termination of access, and we may cooperate with lawful requests from authorities. We take misuse seriously.
11Report abuse
If you believe PenStrike is being misused, or you are the owner of a system you believe was tested without authorization, contact us immediately at [email protected].