Security
The safety model behind every run
Eonycs exists to test your systems with your permission — and to be able to prove that it stayed within those bounds.
Authorization before execution
Every assessment begins with a recorded scope: target hosts, included paths, excluded paths, and the authorization the customer has attested. The engine refuses to start without it, and the record is kept in the run's audit trail.
Mechanical controls
Authorized targets only
A run cannot start until scope and authorization are recorded in the audit trail.
Host lock
Verification traffic is pinned to the authorized host set.
Cross-host redirect protection
Redirects that leave the authorized scope are followed by nothing.
Mechanical payload guardrails
Canary tokens and non-destructive probes prove impact without touching real data.
Demonstrate, do not exploit
Findings are confirmed with the minimum interaction needed — never data extraction.
Audit trail
Scope, authorization, budgets, and every verification step are recorded.
Your keys, your models
Planned for private betaEonycs will support bring-your-own-key configurations so assessments can run against your own supported LLM provider account. This capability is planned for the private beta and is not yet available.
Authorized-use statement
Eonycs may only be used against systems you own or are explicitly authorized to test, and always within the scope recorded before the run. Using Eonycs against third-party systems without authorization is prohibited and is a breach of the terms of service.
Request a private pilot