Skip to content

Authorized testing policy

Last updated: 27 August 2026

everbreach develops offensive security capability for defensive use. This policy describes the controls applied before any customer environment is tested.

No public scanning

The public website does not provide an open scanner. Early-access requests only express interest and do not trigger security testing.

Authorization before execution

A private test starts only after the target owner, scope and permitted techniques are documented.

Targets, concurrency, timing, prohibited actions and stop conditions are agreed before execution.

Current passive baseline

The current baseline collector uses GET and HEAD requests, a bounded list of public paths, DNS queries and a TLS handshake.

It sends fewer than 40 requests with at most four concurrent connections and identifies itself as everbreach/1.0.

The baseline collector does not brute-force credentials, issue state-changing requests or bypass a target block.

Experimental capabilities

Active or adaptive techniques are used only in isolated or explicitly approved scopes with additional controls.

Capabilities under evaluation are not enabled against a customer environment merely because an early-access form was submitted.

Report a concern

To report suspected scanner abuse or request a block, contact hello@everbreach.ch.