BOTXPOSE / SCOPE ENFORCEMENT

The signed scope is law.

Continuous testing must be continuously bounded. BotXpose evaluates every target and action against the approved scope, refuses out-of-scope requests and records the authorization context behind what it did.

  1. 01Authorize
  2. 02Understand
  3. 03Prove
  4. 04Deliver
  5. 05Repeat
01 / OPERATING INPUTS

Every action must carry its authority and evidence.

The status attached to each input determines whether it guides, permits, proves or records an action.

01ENFORCED

Target allowlist

The hosts, applications, APIs and environments that may be tested.

02ENFORCED

Action policy

Permitted techniques, prohibited actions, rate limits and operating windows.

03ENFORCED

Identity boundary

The test accounts, roles and credentials approved for use.

04AUDITABLE

Authorization record

The written authority associated with the testing plan and every resulting action.

05REDACTED

AI privacy boundary

The custom AI engine redacts and minimizes sensitive customer information before sending approved context to third-party AI models.

02

PROOF QUESTIONS

The agent must answer before a finding ships.

  1. 01

    Is the target explicitly in scope?

  2. 02

    Is this technique permitted for this environment?

  3. 03

    Does the action stay within approved identity and rate limits?

  4. 04

    Can the platform explain why the request was allowed?

03 / EVIDENCE PACKAGE

The result should
show its work.

BOTXPOSE / AUTHORIZATION
  1. 01Request-level scope enforcement
  2. 02Refusal of out-of-scope targets and actions
  3. 03Sensitive customer information redacted before third-party model requests
  4. 04Complete action history linked to authorization
  5. 05Clear stop conditions and operating constraints
04 / AUTHORIZATION BOUNDARIES

Continuous does not mean unrestricted.

  • Submitting a URL or document never expands scope.
  • Customer documentation may guide testing but cannot grant authority.
  • Third-party AI models receive redacted task context rather than underlying sensitive customer data.
  • Emergency contacts and stop conditions are agreed before execution.
  • Customer-specific controls are finalized during onboarding.
BOTXPOSE / BUILT BY BOTNET SECURITY

Give the agent a bounded target.

We will confirm the target, authorization, permitted actions, evidence controls and current deployment support before testing begins.