Responsible Use Policy
This is the most important document on this site. Crucible is an offensive security tool, and the line between legitimate assurance testing and unauthorised attack is authorisation — nothing else.
You may only use Crucible against AI systems you own, or that you have explicit written authorisation to test. Running a campaign against someone else’s system without that authorisation is likely to be a criminal offence in your jurisdiction, and it is a breach of these terms regardless.
1. What authorisation means
Before running a campaign against a target you do not own, you must hold authorisation that:
- comes from a person with authority to grant it for that system;
- is in writing, and identifies the specific systems and endpoints in scope;
- covers the testing window in which you intend to run;
- has not been withdrawn.
A public-facing endpoint is not an invitation. A bug-bounty programme authorises only what its own scope document authorises, and many explicitly exclude automated or high-volume testing — check before you run.
2. Prohibited uses
You may not use Crucible to:
- test systems you neither own nor have written authorisation to test;
- cause denial of service, or degrade availability for real users of a production system;
- access, retain or exfiltrate real personal data belonging to third parties;
- develop, refine or stage an attack intended for unauthorised use;
- evade detection or logging on a system you do not own;
- produce content that is unlawful in your jurisdiction or the target’s.
3. Use canaries, not real data
Crucible is designed so you never need to put real personal data at risk. Plant synthetic canary values and synthetic records, and declare them in your spec. Disclosure of a canary is stronger evidence than disclosure of real data, and it carries none of the consequences.
If a campaign causes real personal data to be disclosed, stop, preserve the evidence, and follow your own incident and breach-notification process.
4. Rotate what you expose
A canary that appears in a finding now exists in that run’s evidence ledger and in every copy of the report. Rotate it. Crucible says so in the remediation guidance for every disclosure finding, and the report repeats it.
5. Run against staging where you can
Adversarial campaigns send a lot of hostile traffic. Prefer a staging environment that mirrors production configuration. Where you must test production, agree a window, set a conservative maxAttempts budget, and tell whoever is on call.
6. Handling what you find
If you discover a vulnerability in a third party’s system while testing under authorisation, disclose it to them first and give them reasonable time to remediate before publishing. Do not use a finding as leverage.
7. Our position
BMC Operations LLC does not operate campaigns on your behalf and does not monitor what you test. The authorisation obligation is yours. We may suspend access to any hosted service we offer where we have a reasonable belief it is being used against systems without authorisation.
8. Reporting misuse
If you believe Crucible is being used against your systems without your authorisation, contact security@crucible.langes.fun. Include timestamps, source addresses and any identifying strings from the traffic. Note that the open-source engine can be run by anyone on their own infrastructure, so we may not be able to identify or stop a given operator — but we will help you understand what you are seeing.
Last updated 2026-10-07. These documents are published by BMC Operations LLC and are provided for transparency. They are not legal advice.