★ Mayhem Monkies
Acceptable Use Policy
Last updated: August 4, 2026
The one rule that matters most
You may only point Mayhem Monkies at a target you own or are explicitly authorized, in writing, to test. This applies to every target type: web URLs, code repositories, and cloud accounts. You are solely responsible for holding that authorization. Running security tests against systems you do not own or control, without permission, may be illegal.
You must not use the Service to
- Test, probe, scan, or attack any system you do not own or are not clearly authorized to test.
- Attempt to gain unauthorized access to, disrupt, degrade, overload, or deny service to any system or network.
- Falsify, circumvent, or click through the authorization attestations without actually holding authorization.
- Test systems where a failure could threaten human safety or critical infrastructure (e.g. medical, industrial control, transportation, emergency services).
- Use findings, credentials, or access obtained through the Service to harm others or commit any unlawful act.
- Violate any law, regulation, or third-party right, including privacy and intellectual-property rights.
- Attempt to attack, reverse-engineer for abuse, overload, or interfere with Mayhem Monkies' own infrastructure, or resell or abuse free-tier access.
Active and destructive testing
Exploit-grade / destructive testing is off by default and requires a separate, explicit authorization for each hunt. Only enable it on targets you own or are authorized to test destructively, where you hold current backups and accept the risk of disruption.
Enforcement
We may suspend or terminate accounts, cancel hunts, and withhold or revoke access for any violation, and we may report unlawful activity to the appropriate authorities. Violations may also make you liable to us under the indemnification section of the
Terms.
Reporting abuse