Authorized testing policy
Last updated: 27 August 2026
everbreach develops offensive security capability for defensive use. This policy describes the controls applied before any customer environment is tested.
No public scanning
The public website does not provide an open scanner. Early-access requests only express interest and do not trigger security testing.
Authorization before execution
A private test starts only after the target owner, scope and permitted techniques are documented.
Targets, concurrency, timing, prohibited actions and stop conditions are agreed before execution.
Current passive baseline
The current baseline collector uses GET and HEAD requests, a bounded list of public paths, DNS queries and a TLS handshake.
It sends fewer than 40 requests with at most four concurrent connections and identifies itself as everbreach/1.0.
The baseline collector does not brute-force credentials, issue state-changing requests or bypass a target block.
Experimental capabilities
Active or adaptive techniques are used only in isolated or explicitly approved scopes with additional controls.
Capabilities under evaluation are not enabled against a customer environment merely because an early-access form was submitted.
Report a concern
To report suspected scanner abuse or request a block, contact hello@everbreach.ch.