Responsible Use & Scope Limitations

TraceForge is designed strictly for authorized defensive security audits, forensic investigations, verified bug bounties, and academic research.


1. Authorized Operator Mandate

Operators must hold explicit, written authorization from asset owners before performing active reconnaissance or network scans.

Legitimate Use Cases:

  • Defensive Incident Response: Investigating compromised workstations, servers, or internal network traffic.

  • Authorized Penetration Testing: Auditing targets defined strictly within a written statement of work.

  • Bug Bounty Programs: Testing domains and scopes explicitly declared by the program policy.

  • Law Enforcement & Forensics: Ingesting and analyzing evidence under valid legal warrant.

  • Academic Research: Conducting security and metadata analysis in controlled laboratory environments.


2. Prohibited Activities

The following actions are strictly prohibited with TraceForge:

  • Unauthorized computer access, network intrusion, or port scanning without asset owner consent.

  • Denial-of-service (DoS/DDoS) attacks or deliberately exhausting target bandwidth/resources.

  • Bulk scraping of private individuals for harassment, stalking, doxxing, or unauthorized surveillance.

  • Intercepting private communications or Wi-Fi traffic without legal authorization.


3. Statutory Notice

Unauthorized computer access is a criminal offense under international cybercrime legislation:

  • India: Information Technology Act, 2000 (§§ 43, 66, 66B, 66C, 66D, 79).

  • United States: Computer Fraud and Abuse Act (CFAA, 18 U.S.C. § 1030).

  • European Union: Directive 2013/40/EU on attacks against information systems.

  • United Kingdom: Computer Misuse Act 1990 (Sections 1, 2, 3, 3A).

See DISCLAIMER.md and RESPONSIBLE_USE.md for full policy terms.