Only assess what you may access
Use Produra only to review source that you own or have explicit permission to assess and share with the hosted processors. Access to code does not create permission to test unrelated services, customer environments or third-party infrastructure. This beta accepts ZIPs and does not connect to GitHub.
Keep tests controlled
The hosted beta performs source inspection and does not execute application behavior tests. Any testing or edits in your own editor are separate actions that require appropriate scope and permission. Do not use report guidance to exfiltrate information, attack another person’s account, disrupt services or access targets outside your authorization.
Uploads are input, not instructions
Projects may contain vulnerable or suspicious source that needs review. Do not weaponize uploads to attack Produra, overwhelm storage or processing, bypass file or usage limits, or harm other users. Do not include stolen data, live credentials or customer records unnecessary for source review.
Respect access and rights
Keep account credentials private. Do not impersonate others, evade suspended access or use another person’s secrets. Ensure you have the necessary rights to share submitted code and dependencies; respect applicable laws and third-party licenses.
Report problems responsibly
Stop any testing that affects people or systems outside the approved scope. Preserve only the minimum evidence needed and notify the operator who provided beta access privately. Do not send real credentials or customer data in a report. A public security contact and disclosure process remain pending.
Responding to misuse
The operator may pause access or reject a request when needed to protect the beta or enforce authorized scope. This draft does not authorize testing Produra’s own infrastructure or anyone else’s systems.