Ethics & scope

Responsible Use

PromptSlayer exists to help teams find and fix weaknesses in their own AI systems. That intent is enforced in the product design, not just stated in a policy page.

Authorization first

The runner requires an explicit target declaration and an authorization acknowledgement before any live audit can start. There is no anonymous scan mode.

Safe-by-default demo

The public demo never issues outbound requests. Target responses and evaluator verdicts are simulated in the browser, so reviewers can explore the tool without capability risk.

Defensive framing

Findings are written for the team fixing the model: severity, confidence, reproduction context and remediation. Payloads are described by technique, not published as ready-to-use exploits.

Your legal responsibility

Users are responsible for complying with applicable laws, contracts, and AI provider policies. PromptSlayer does not grant permission to test anything.

IN SCOPE

  • Test models, applications and endpoints you own.
  • Test third-party systems only with explicit written authorization.
  • Keep findings within the scope and disclosure window you agreed to.
  • Respect provider rate limits, usage policies and contractual terms.

OUT OF SCOPE

  • Probe production systems belonging to others without permission.
  • Use generated bypasses to obtain or distribute harmful content.
  • Publish reproduction payloads before the vendor has remediated.
  • Treat a passing audit as a guarantee of model safety.

Disclosure practice

Vulnerabilities discovered against third-party models are reported to the vendor first through their published security channel, with a reproduction summary and suggested mitigation. Public write-ups describe the technique class and its impact, never a copy-paste payload, and only after remediation or an agreed disclosure deadline.