Testing
Authorized Testing
Some Enji Guard features send active requests to live websites and APIs. This page sets out the conditions for that testing: who can authorize it, what is in scope, what may happen, and what is prohibited.
What this covers
This page covers active checks that Enji Guard can run against websites, APIs, and web resources you link — for example runtime checks and Auto-pentest. These checks send real requests to a live target, so they require your explicit consent.
Authorization requirement
You may run active checks only against systems that you own or have written permission to test. By enabling active checks, you confirm that:
- You own the target or have written authorization to test it.
- Your organization permits the test.
- Your hosting or infrastructure provider permits the test.
- The target is in scope.
- You understand that active checks may affect the target.
Consent validity
Consent applies to a specific project, website or domain, and selected scope. A renewed confirmation is required if:
- The website, domain, or target scope changes.
- The project is transferred to another owner or organization.
- Ownership or authorization may have changed.
- Materially more aggressive active-test types are added to the scope.
- A repository, website, or project is disconnected and reconnected.
- Twelve months have passed since the previous confirmation.
What Enji Guard may do during active testing
Within the approved scope, Enji Guard may discover endpoints, forms, parameters, and headers; send common vulnerability payloads; test for issues such as SQL injection, cross-site scripting, SSRF, IDOR/BOLA, broken access control, authentication bypass, and sensitive data exposure; generate the normal request volume needed to exercise endpoints; record reproduction steps; and generate a report.
Possible impact
Active checks can cause temporary errors or slowdown, higher request volume, security alerts and WAF or log noise, temporary account lockouts, and the exposure of bugs that need urgent remediation.
You accept these risks for the targets you authorize, and you are responsible for backups and for monitoring the target during testing.
Prohibited testing
- Denial-of-service or load testing.
- Credential stuffing, password spraying, or brute force.
- Malware, persistence, lateral movement, or destructive payloads.
- Data exfiltration.
- Privilege escalation outside the agreed scope.
- Scanning unrelated domains, IP ranges, tenants, customers, or shared infrastructure.
- Testing targets prohibited by a hosting, cloud, or customer contract.
Handling reports
Auto-pentest reports may contain sensitive vulnerability details. Treat them as confidential, and do not publish or share a report unless you have authority to disclose the target, findings, reproduction steps, and remediation information.
Stopping a test
You can stop future checks by disabling the job. For an urgent stop, contact [email protected].
Consent records
Enji Guard may store consent records showing that a user confirmed the active-testing conditions for a target. Consent records may survive disabling and re-enabling a job, and are kept for auditability even after a consent is no longer valid for future checks.
Enji Guard