Security

The safety model behind every run

Eonycs exists to test your systems with your permission — and to be able to prove that it stayed within those bounds.

Authorization before execution

Every assessment begins with a recorded scope: target hosts, included paths, excluded paths, and the authorization the customer has attested. The engine refuses to start without it, and the record is kept in the run's audit trail.

Mechanical controls

Authorized targets only

A run cannot start until scope and authorization are recorded in the audit trail.

Host lock

Verification traffic is pinned to the authorized host set.

Cross-host redirect protection

Redirects that leave the authorized scope are followed by nothing.

Mechanical payload guardrails

Canary tokens and non-destructive probes prove impact without touching real data.

Demonstrate, do not exploit

Findings are confirmed with the minimum interaction needed — never data extraction.

Audit trail

Scope, authorization, budgets, and every verification step are recorded.

Your keys, your models

Planned for private beta

Eonycs will support bring-your-own-key configurations so assessments can run against your own supported LLM provider account. This capability is planned for the private beta and is not yet available.

Authorized-use statement

Eonycs may only be used against systems you own or are explicitly authorized to test, and always within the scope recorded before the run. Using Eonycs against third-party systems without authorization is prohibited and is a breach of the terms of service.

Request a private pilot