Authority first.
Law, the contract, and the signed authorisation outrank the programme.
01About
Kestrel.ICU is an advanced, AI-powered offensive security tool. It was built to find the path an attacker would take, and to prove it.
02The mark
A kestrel does not patrol for the sake of being seen. It holds, then commits to a point. The tool is built the same way. A superior offense is a controlled action against a target you have named, inside limits you have signed.
ScaryByte develops Kestrel and operates it. Scope, the run, and the readout stay with that team.

03Principles
A person entitled to grant access signs the rules.
A reached objective, with the steps that got there, is the result.
Every finding says what was done, what it proved, and what to change.
Scope is the signed document.
Offensive security, developed by ScaryByte.
04Compliance
The operator is bound before the tool is pointed at anything. These are the rules the programme actually keeps.
Law, the contract, and the signed authorisation outrank the programme.
Stay inside the window. Do not sell a finding. Do not inflate a severity. Prefer proof that does not expose more than it must.
A rehearsal is not the customer run. One customer's material stays with that customer.
Live card numbers, health records, and customer secrets are not used as practice material.
A customer's findings are not published without that customer's written approval.
Anyone else on the work stays inside the same rules. Access ends when the engagement closes.
Black, grey, or white box is named in the scope and the rules of engagement. The level does not replace written authorisation. A black-box test still needs named targets. The report states the level that was used, so a quiet interior is not mistaken for a clean one.
