Public security maturity index.
Private operational systems.
Array controls authorized campaigns and assessment waves. Seed supplies the native C++23 assessment engine. Sofer coordinates private-line agents, models, probes, tools, and domain packages. Isomorph tests model refusal and jailbreak-class inference boundaries. Bounds verifies agent, runtime, and release trust. Kun records path-only access-recovery memory without retaining raw credentials. ORCA operates engagement state, modules, findings, reports, and bundles. Gate decides whether the connected line is ready to release or hand off.
Read the capability-level practice map. It describes what each project does while keeping targets, credentials, live payloads, client data, and engagement findings private.
Authorization boundary.
Public tools may be read and run within their licenses and documented limits. Written authorization first: private security practice begins only after written authorization, written scope, and lawful authority are established. This page does not publish source for private systems, counterparties, sensitive deployment detail, target specifics, or operational methods.
A request without a lawful basis receives only public material.
Data-backed claims.
The claim registry is public: security-tools.json. It records purpose, maturity, source, install or entry route, verification command, evidence date, limitations, and authorization boundary for each promoted item.