unsafe.ltd

Responsible use.

We build tools that attack software. These are the rules they follow, and how we handle your data.

Authorised testing only

Asera attacks software. That is only acceptable when the owner has agreed to it.

  • Asera only tests systems you own or are authorised to test.
  • Every run starts from a written scope: targets, test accounts, excluded paths and limits. Someone on your side signs it off.
  • Nothing outside the scope is touched. Rate limits and blocked methods apply for the whole run.

People approve the risky steps

Agents propose. People decide anything intrusive or irreversible.

  • Intrusive actions, such as writes, cross-account reads or fuzzing, pause until a person approves them.
  • Every agent step is logged with who approved it, and can be replayed.
  • A finding without evidence is reported as a question, not a result.

Your code and findings

Security data is sensitive. You decide where it goes.

  • Your code and findings are never used to train models.
  • You choose where each task runs: local models on your own hardware, or enterprise models through your own agreement and keys.
  • Source code can be kept on local models only. Secrets are redacted before any external call.
  • Asera and Evor can be deployed in your cloud or on your hardware.

This website

We do not collect anything about you here.

  • This site has no forms and sets no cookies.
  • The only third-party script is Cloudflare Web Analytics, which counts visits without cookies.
  • Emails you send to [email protected] are used only to reply to you.

Report a vulnerability

Found a security issue in unsafe.ltd or in one of our products? Tell us.

  • Email [email protected] with the affected URL or component and steps to reproduce.
  • Do not access or change data that is not yours, and do not run denial-of-service tests.
  • Our contact details are also published in /.well-known/security.txt.