Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a0260c-4067-7052-9647-ad000d576e38
26 lines
1.2 KiB
Markdown
26 lines
1.2 KiB
Markdown
# whitehat-security
|
|
|
|
NetKingdom's offensive security facility. Automated white hat IT-security,
|
|
pen-testing and isolation-probing — pointed at infrastructure we choose,
|
|
including our own.
|
|
|
|
The estate's **adversarial evidence facility**: it attacks our own systems, on
|
|
a schedule, to find out whether the security properties they claim are actually
|
|
true.
|
|
|
|
It exists because a repo testing its own boundary grades its own homework. The
|
|
probes most worth having are the ones an author would not think to write.
|
|
|
|
- **Independent in operation.** It does not take a declared posture as true.
|
|
NetKingdom owns both the security canon and this facility, so findings leave
|
|
through `risk-nexus` under separate ownership rather than being resolved here.
|
|
- **It finds; it does not fix.** Findings route to `risk-nexus`, which owns
|
|
severity and disclosure. The repo that owns the defect owns the repair.
|
|
- **A pass means the attacks we tried did not work** — not that the boundary
|
|
holds. Reports say so.
|
|
|
|
- Intent: [`INTENT.md`](INTENT.md)
|
|
- Scope: [`SCOPE.md`](SCOPE.md)
|
|
- Workplans: [`workplans/`](workplans/)
|
|
- Rules of engagement (pending operator approval):
|
|
[`docs/rules-of-engagement.md`](docs/rules-of-engagement.md)
|