// ETHICS — back to home

Ethics and responsible use

GRIMZ is a real pentesting tool. Here's what we expect from anyone using it.

Guiding principle

Everything we build starts from one premise: the power to scan, prioritize exploits and operate against a system is only legitimate within an explicitly authorized scope. This isn't marketing language — it's built into the product itself: human confirmation before any active action, and scope definition as a mandatory step in the TRACEZ → GRIMZ flow.

§ 1

Explicit scope

We never execute or enable an active action without the operator having defined exactly which assets are covered.

§ 2

No support for unauthorized intrusion

If we detect or are told about GRIMZ being used against unauthorized targets, we act on it — including suspending access.

§ 3

Responsible disclosure

If a TRACEZ investigation or a GRIMZ operation reveals a real vulnerability in third-party infrastructure, we follow a responsible disclosure process toward the system's owner before any publication.

What GRIMZ and TRACEZ are not

GRIMZ is not a tool for indiscriminate attack or unauthorized intrusion. TRACEZ is not a tool for harassing, doxxing or surveilling private individuals without a legitimate basis. Use of both platforms is subject to our terms of use.

Report an issue

If you see the platform being misused, or find a vulnerability in no-do.dev, TRACEZ or GRIMZ, contact us.