Acceptable Use Policy

ChaosEngine orchestrates reconnaissance, scanning, and exploitation-adjacent tooling. That capability comes with a hard boundary: authorization.

Last updated: August 19, 2026

The rule

You may only run ChaosEngine workflows against targets — domains, IPs, repositories, applications, or models — that you own or have explicit, documented authorization to test. This applies to every node in a workflow: recon, scanning, exploitation, and AI-agent analysis alike.

No exceptions for "just recon" or "read-only" nodes. Unauthorized reconnaissance against third-party infrastructure is prohibited under this policy regardless of intent.

Prohibited uses

  • Running workflows against systems you don't own or lack written authorization to test
  • Using ChaosEngine to launch denial-of-service, mass-scanning, or indiscriminate internet-wide sweeps
  • Using the platform to develop or distribute malware unrelated to authorized security testing
  • Circumventing approval controls that an organization has configured for governance purposes
  • Reselling or sublicensing access without our written consent

Approval controls exist for a reason

ChaosEngine's approval-gated execution model exists so a second person signs off before a workflow runs against a target. Configuring gates to be meaningless (e.g. auto-approving everything by default) undermines the governance the platform is built to provide — we strongly recommend against it for any workflow touching production or third-party systems.

Enforcement

We may suspend or terminate access for violations of this policy. If you become aware of a violation, report it to core@secuenz.com.

Related policies