# Responsible Use & Scope Limitations TraceForge is designed strictly for **authorized defensive security audits, forensic investigations, verified bug bounties, and academic research**. --- ## 1. Authorized Operator Mandate Operators must hold explicit, written authorization from asset owners before performing active reconnaissance or network scans. ### Legitimate Use Cases: - **Defensive Incident Response**: Investigating compromised workstations, servers, or internal network traffic. - **Authorized Penetration Testing**: Auditing targets defined strictly within a written statement of work. - **Bug Bounty Programs**: Testing domains and scopes explicitly declared by the program policy. - **Law Enforcement & Forensics**: Ingesting and analyzing evidence under valid legal warrant. - **Academic Research**: Conducting security and metadata analysis in controlled laboratory environments. --- ## 2. Prohibited Activities The following actions are strictly prohibited with TraceForge: - Unauthorized computer access, network intrusion, or port scanning without asset owner consent. - Denial-of-service (DoS/DDoS) attacks or deliberately exhausting target bandwidth/resources. - Bulk scraping of private individuals for harassment, stalking, doxxing, or unauthorized surveillance. - Intercepting private communications or Wi-Fi traffic without legal authorization. --- ## 3. Statutory Notice Unauthorized computer access is a criminal offense under international cybercrime legislation: - **India**: Information Technology Act, 2000 (§§ 43, 66, 66B, 66C, 66D, 79). - **United States**: Computer Fraud and Abuse Act (CFAA, 18 U.S.C. § 1030). - **European Union**: Directive 2013/40/EU on attacks against information systems. - **United Kingdom**: Computer Misuse Act 1990 (Sections 1, 2, 3, 3A). See [DISCLAIMER.md](https://github.com/paman7647/TraceForge/blob/master/DISCLAIMER.md) and [RESPONSIBLE_USE.md](https://github.com/paman7647/TraceForge/blob/master/RESPONSIBLE_USE.md) for full policy terms.