Ethics and responsible use
GRIMZ is a real pentesting tool. Here's what we expect from anyone using it.
Guiding principle
Everything we build starts from one premise: the power to scan, prioritize exploits and operate against a system is only legitimate within an explicitly authorized scope. This isn't marketing language — it's built into the product itself: human confirmation before any active action, and scope definition as a mandatory step in the TRACEZ → GRIMZ flow.
Explicit scope
We never execute or enable an active action without the operator having defined exactly which assets are covered.
No support for unauthorized intrusion
If we detect or are told about GRIMZ being used against unauthorized targets, we act on it — including suspending access.
Responsible disclosure
If a TRACEZ investigation or a GRIMZ operation reveals a real vulnerability in third-party infrastructure, we follow a responsible disclosure process toward the system's owner before any publication.
What GRIMZ and TRACEZ are not
GRIMZ is not a tool for indiscriminate attack or unauthorized intrusion. TRACEZ is not a tool for harassing, doxxing or surveilling private individuals without a legitimate basis. Use of both platforms is subject to our terms of use.
Report an issue
If you see the platform being misused, or find a vulnerability in no-do.dev, TRACEZ or GRIMZ, contact us.