Acceptable Use
Acceptable Use Policy
AttackCompass is for authorized security testing. You remain responsible for scope, legality, and every action you run.
Effective date: October 10, 2026
Report vulnerabilities via Responsible Disclosure.
Purpose
Authorized security testing only
AttackCompass is built for authorized pentesting and related defensive security work. You may use it only on systems and data you are legally allowed to test.
You are solely responsible for obtaining and maintaining authorization, respecting rules of engagement, and complying with applicable law.
Allowed
Permitted use
Use AttackCompass to organize engagement state, review recommended next steps, capture evidence, and produce reports for authorized assessments.
Keep using your own tools. AttackCompass does not replace your responsibility to choose and run every action safely and within scope.
Prohibited
Misuse is not allowed
Do not use AttackCompass to plan, assist, or conceal unauthorized access, fraud, harassment, or other illegal activity.
Do not attempt to bypass entitlements, probe other customers' workspaces, disrupt the service, or abuse APIs and tokens.
Do not upload malware samples or illegal content except as necessary and lawful for an authorized engagement, and only under controls appropriate to that engagement.
Operator control
You stay accountable
Recommendations are guidance. They are not permission to test a target. Blocked or deferred steps do not define legal scope — your authorization does.
If guidance conflicts with your contract, laws, or rules of engagement, follow the authorization — not the recommendation.
Enforcement
Suspension and reporting
We may suspend or terminate access for Acceptable Use violations, legal risk, or abuse of the platform.
Report product security issues through the Responsible Disclosure policy. Report account abuse or billing problems to support@attackcompass.com.