What you may run through Xaish.
The security catalog includes offensive and dual-use tools. Use them only on systems you own or are authorized to test. Updated .
This policy is part of the Terms of service. Violation can mean immediate suspension, termination, and referral to law enforcement.
Authorized targets only
Pentest automators, exploit-research planners, attack batteries, malware/YARA analysis, recon, and similar tools may be used solely against:
- systems you own, or
- systems for which you have written authorization (a charter, RoE, or contract).
You may not use Xaish to probe, exploit, or map third-party systems without that authorization. "I found a bug" is not authorization.
Prohibited
- Attacks, fraud, extortion, or unauthorized access against anyone else.
- Generating or deploying malware, ransomware, or exploit code except inside an isolated lab you are authorized to operate.
- Child sexual abuse material, or any sexual content involving minors.
- Content that incites violent crime or terrorism.
- Evading sanctions, or using Paynnt / the tools for money laundering or sanctions evasion.
- Sharing account credentials, reselling seats, or wrapping the API as your own product without a written partner agreement.
- Circumventing tier gates, rate limits, or daily caps, or attacking the Xaish infrastructure.
- Uploading others' production secrets, personal data, or regulated data you have no right to process.
Payment tools
Payment and Paynnt tools are for your own operations. Do not use them to process payments for others as an unlicensed money transmitter. Devnet value is for testing only.
Agents and API keys
If you connect an agent, you are responsible for what it submits and what it spends. Set spend caps. Revoke keys you are not using.
We may act without notice
We may rate-limit, refuse a request, suspend a workspace, or preserve logs when we believe this policy or the law is being broken. Report abuse to security@xaish.com.