Z7 Claw Force runs scope-bound external penetration tests. Every intrusive action passes an enforced scope guard and a human-approval gate before it dispatches, and the entire timeline is sealed in an append-only audit trail.
This is how an engagement actually runs: authorization first, recon inside the scope, and a hard stop for human approval before anything intrusive fires. Nothing here touches a real target.
Targets you list are in scope. Anything outside the agreed scope is rejected before it runs, not tested and apologized for later.
Every intrusive action queues for a human decision. Nothing high-risk dispatches unattended, and each approval is recorded with who and when.
Authorization, scope decisions, approvals, and actions are hash-chained into an append-only log that becomes the backbone of the report.
Start with a Rules-of-Engagement intake. We confirm authorization and scope before a single packet leaves the lab.