Acceptable Use

Effective: 11 August 2026

RedCore is for authorized defensive security work. This policy is a baseline; signed Rules of Engagement may impose stricter controls.

Required authorization

The customer must prove authority over every target and obtain required third-party, cloud-provider, hosting, employee, and data-owner permissions. Scope must identify allowed assets, exclusions, methods, windows, rate limits, accounts, data modes, and emergency contacts.

Prohibited use

Operational controls

RedCore may refuse, pause, or terminate work where authority is uncertain, scope signals conflict, safety thresholds are reached, the emergency contact cannot be reached, or continued testing creates unacceptable risk. Customer stop requests take precedence over automation.

Reporting concerns

Report suspected misuse through the contact form. Do not include secrets or exploit payloads in the form.