# whitehat-security Automated white hat IT-security, pen-testing and isolation-probing. The estate's **adversarial evidence facility**: it attacks our own systems, on a schedule, to find out whether the security properties they claim are actually true. It exists because a repo testing its own boundary grades its own homework. The probes most worth having are the ones an author would not think to write. - **Independent by construction.** It does not take a declared posture as true, and it is not owned by the repo whose canon it verifies. - **It finds; it does not fix.** Findings route to `risk-nexus`, which owns severity and disclosure. The repo that owns the defect owns the repair. - **A pass means the attacks we tried did not work** — not that the boundary holds. Reports say so. - Intent: `INTENT.md` - Workplans: `workplans/`