whitehat-security/README.md
tegwick 348738ba73 Register whitehat-security and align operating boundaries
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0260c-4067-7052-9647-ad000d576e38
2026-08-21 22:52:37 +02:00

26 lines
1.2 KiB
Markdown

# whitehat-security
NetKingdom's offensive security facility. Automated white hat IT-security,
pen-testing and isolation-probing — pointed at infrastructure we choose,
including our own.
The estate's **adversarial evidence facility**: it attacks our own systems, on
a schedule, to find out whether the security properties they claim are actually
true.
It exists because a repo testing its own boundary grades its own homework. The
probes most worth having are the ones an author would not think to write.
- **Independent in operation.** It does not take a declared posture as true.
NetKingdom owns both the security canon and this facility, so findings leave
through `risk-nexus` under separate ownership rather than being resolved here.
- **It finds; it does not fix.** Findings route to `risk-nexus`, which owns
severity and disclosure. The repo that owns the defect owns the repair.
- **A pass means the attacks we tried did not work** — not that the boundary
holds. Reports say so.
- Intent: [`INTENT.md`](INTENT.md)
- Scope: [`SCOPE.md`](SCOPE.md)
- Workplans: [`workplans/`](workplans/)
- Rules of engagement (pending operator approval):
[`docs/rules-of-engagement.md`](docs/rules-of-engagement.md)