betaTest your AI system free
Legal

Responsible Use Policy

Last updated 14 August 2026

Prooflane sends adversarial input at AI systems on purpose. Prompt injection, jailbreaks, tool-abuse attempts, poisoned retrieval, load generation — these are the point of the product, and they are the same techniques an attacker would use. That is why this policy exists, and why it forms part of our Terms of Service.

The rule that matters most

Only test systems you own, or that you have explicit permission to test. Permission means someone with authority to grant it has said yes, ideally in writing, and knows what you intend to run. Being able to reach a system is not permission. A public endpoint is not permission. A bug bounty page is permission only within the scope it states.

Do not

  • Point Prooflane at anyone else's systems, models, or MCP servers without authorisation.
  • Use Prooflane, its attack library, or its findings to gain unauthorised access to anything, to exfiltrate data, or to cause damage or disruption.
  • Reuse the payloads and techniques it contains as offensive tooling, or repackage them into something intended for attack rather than testing.
  • Run load or stress profiles against systems you do not control, or against shared infrastructure where the impact reaches other people.
  • Use Prooflane to break the law, to breach a contract or a provider's terms, or to evade another party's security controls.
  • Attempt to interfere with Prooflane itself — our hosted services, other users' accounts, or the entitlement and plan limits.

Testing safely

  • Prefer non-production. Adversarial and load testing can degrade a live system, trip rate limits, or leave odd data behind. Use a staging environment where you can.
  • Expect side effects. Tool-abuse tests deliberately try to make an agent do something destructive. If the agent's tools can send email, move money, delete records, or run commands, point Prooflane at an environment where that is safe.
  • Tell the people who need to know. Your own security and operations teams should not discover your red-team run as an incident.
  • Mind third-party costs. Agent-driven tests make real calls to your LLM provider and you pay for them. Large runs can be expensive.

Handling what you find

Findings about someone else's system — a provider, a vendor, an open-source project — should go to whoever can fix them, privately and with reasonable time to respond. Do not publish, sell, or exploit them. Prooflane's output is informational and heuristic; treat a finding as something to verify, not as a proven exploit.

If this policy is broken

We may suspend or close accounts we believe are being used against this policy, and we may decline to provide hosted features to them. Where we are legally required to act on or report activity, we will.

Reporting misuse

If you believe Prooflane is being used against your systems, or you have found a security issue in Prooflane itself, email prooflaneteam@prooflane.ai. Please include enough detail to investigate. We will not pursue anyone who reports a genuine issue in good faith and does not exploit it.