Trust
What crosses, what authorises it, and what gets written down
We are asking to run real attacks against your systems. These are the controls that make that a decision you can take, and the places where we will not claim more than we have.
What crosses the boundary
From us to you
A rendered command and nothing else. The protocol has no field for a technique identifier, a scenario, or a query, so our knowledge graph cannot reach your host even by accident. That is enforced by a test on the agent bundle, not by an intention in a design document.
From you to us
The output of those commands, and the derived list of tools your engagement needs. Credentials harvested during a run are scrubbed at teardown and redacted from every record on both sides.
What authorises a command
One manifest, which you approve. It names the scope, each permission granted, a time window, and a switch that stops everything.
- Scope is checked twice — once when a value is bound into a command, once on the finished command before it runs.
- Permissions are exact-match and do not carry over between engagements.
- Lateral and destructive actions need a second sign-off beyond being listed at all.
- The kill switch is checked before every command, and works mid-run without editing the manifest the run is audited against.
- The agent re-validates everything against its own frozen rules. It does not trust instructions merely because they came from us.
What we do not attest, and will not imply
Authority for an engagement is your own approval of a file, out of band. Nothing in this system attests who wrote that manifest or that anyone signed off on it, and we keep the word "signed" out of every description of an engagement for that reason.
What we do prove is integrity. The manifest's bytes are hashed onto every audit record, so a finished run can show exactly which text governed it — and an evidence pack can prove the manifest it shows you is the one the commands ran under, rather than one widened afterwards. Those are different claims and we would rather make the smaller true one.
The agent image is signed, with its bill of materials readable off the image. An image signature attests the runner. It says nothing about the authority the runner acts under.
What is written down
Every command is recorded — executed, refused, or gated — on both sides of the connection. Ours, and one left on your own hosts, so you never have to ask us what we did. The refusals matter as much as the executions: a record that only shows what ran cannot show you what the scope stopped.
Found something in ours?
If you have found a security problem in omvia.net, in GraphWalker, or in anything
else of ours, write to
omvia@omvia.net and we will read
it. Machine-readable details are at
/.well-known/security.txt.
Our safe-harbour statement is below.
Safe harbour
If you research our systems in good faith and follow this statement, we will not bring or support legal action against you for that research, and we will say so in writing if anyone asks us to.
- It covers omvia.net, GraphWalker, and other systems we operate. It cannot cover a customer's systems, or a third party's — we have no standing to waive somebody else's rights, and an engagement of ours is authorised by that customer's own scope rather than by this page.
- Stay within what testing requires. Do not access, alter or keep data that is not yours, do not degrade a service for anyone else, and leave social engineering, physical access and attacks on our staff out of it.
-
Tell us before you tell anyone else, at
omvia@omvia.net, and give us a reasonable chance to fix it — ninety days is the outside figure we would ask for, and most things should be much faster. We will keep you informed rather than go quiet. - If you find customer data, stop, and tell us immediately. Do not download it to prove the point.
We do not run a bug bounty and we are not offering payment. We will credit you if you would like us to. And if you are unsure whether something is in scope, ask first — a question costs us nothing and we would rather answer it than have you guess.