Sometimes we test a publicly available agent before anyone has hired us, and send the company what we found. These are the rules we follow when we do, and they are not negotiable.
An auditor's credibility survives exactly one breach of this kind. So we publish the constraints rather than describe them, and we build them into the tooling: the pre-audit profile in our harness enforces the request budget in code and aborts the run if it is exceeded. A rule that lives only in a document is a rule that gets broken on a busy day.
We test the demo, sandbox or trial that you have deliberately made available to anyone. We do not create accounts to get further in, we do not use credentials, and we do not go behind an authentication boundary of any kind.
We read the terms before the first request. Where automated access is prohibited, we either test by hand within the terms or we do not test at all. Where the terms are ambiguous, we treat them as prohibiting.
One conversation thread, a hard cap of thirty requests, no parallelism, and rate limiting well below anything your infrastructure would notice. We never test availability, latency under load, or anything else that costs you capacity.
Every input is synthetic. We never enter a real person's details, and we never attempt to reach another user's data, session or record — not to prove it is possible, not as a demonstration, not at all. If we come across someone else's data by accident, we stop, tell you, and delete it.
Findings go to the company they concern before they go anywhere else. Directly, in full, with the transcripts and the reproduction log attached, and with no conditions on what you do next.
We never name you, quote you, or describe your system publicly without your written agreement. This holds whether you buy anything, disagree with the findings, or never reply to us at all. Silence is not consent, and there is no deadline after which it becomes consent.
Whatever we found is handed over in full with its artifacts, at no cost and with nothing withheld to create a reason to hire us. If you never speak to us again, you still keep everything.
security.txt, and follow whatever disclosure policy you publishIf you would rather we did not test your public agent, tell us and we will stop, delete what we have collected, and add you to a list we check before every engagement. You do not need to give a reason and we will not ask for one.
Email yusifli.pervin@gmail.com with your domain. We will confirm within two working days, and the confirmation will tell you exactly what we had collected and that it is gone.
If something here is unclear, or you think a rule should be stricter, say so. These rules have been rewritten before and will be again.