Ownership
Confirm the partner controls or is authorized to test the target.
Authorize the scope, isolate sensitive access and stop production runs before irreversible actions.

The manifest records who owns the target, which domains and accounts are in scope and what the runner may do.
Confirm the partner controls or is authorized to test the target.
List domains, routes, accounts, tools and data that the run may access.
Separate read, reversible write and irreversible actions before execution.
Define the exact state where a public or production run must stop.
A result always carries its audit mode, fixtures and authorization context.
Read public content and perform reversible local interactions. Stop before account creation, submission or transaction.
Use approved test accounts and scoped permissions. Avoid production customer data and destructive changes.
Complete controlled scenarios with fixtures and test payment methods. Never cross into production.
The runner may reach a review state, but it does not complete an irreversible action without a separately approved sandbox protocol.
Security state is reported honestly, including limitations and controls that are still being operationalized.
Limit reachable targets and external destinations to the approved scope.
Keep credentials server-side, scoped and out of screenshots, logs and prompts.
Collect only evidence needed to reproduce and verify the finding.
Remove PII, tokens, payment, financial and medical data from report-safe artifacts.
Assign an explicit retention window and deletion path to sensitive artifacts.
Record agent, environment, tools, actions and interventions for later review.
The collection level is selected before the run and reduced when a lower level can prove the same assertion.
Record only approved screens, traces and structured events.
Remove unrelated content and avoid broad account or page exports.
Transform sensitive fields before an artifact enters a report or shared workspace.
Keep the artifact only for the agreed operational and review period.
Use the published security contact, describe the affected asset and wait for a secure exchange path before sending secrets or personal data.
Aiscovery does not display SOC 2, ISO, encryption or subprocessor claims until formal evidence, scope and current documentation are available.
Only when the applicant can demonstrate appropriate authorization from the owner.
No. They stop before irreversible confirmation or payment.
Report-safe artifacts must be minimized and redacted according to the agreed evidence policy.
Apply with an owned workflow, approved environment and the constraints your security team needs reviewed.