Last updated: June 30, 2026
Kyora IQ Nemesis is a security assessment tool intended solely for testing systems you own or are explicitly authorized to test. The free passive scan inspects only the URL you submit, reading what that endpoint already returns. Managed assessments are performed by the Kyora IQ team only after written authorization for the target has been verified. You are responsible for ensuring you have the right to assess any system you submit.
The free passive scan requires no account and no credentials. It inspects your API surface and renders results in your browser. Nothing from a free scan is written to Kyora IQ servers, and closing the tab discards the results unless you saved them yourself. For managed assessments, Kyora IQ stores only the information needed to perform and report the engagement, handled under the authorization agreement and our data handling commitments.
The free scan never asks for an API key. For a managed Red Team assessment, the Kyora IQ team configures access to your endpoint under written authorization, so you are never asked to paste a production credential into a web form. This keeps your keys in your control and out of the browser.
Free scans are limited to passive inspection of the URL you provide, the same requests a browser already makes, with no adversarial payloads sent. Active adversarial testing, including the full Red Team suite, runs only as a managed engagement after the Kyora IQ team verifies you are authorized to test the target. This authorization step is a legally meaningful gate, not a checkbox.
Unauthorized computer access may violate the Computer Fraud and Abuse Act (CFAA) in the United States, the Computer Misuse Act 1990 in the United Kingdom, the General Data Protection Regulation (GDPR) in the European Union, and equivalent legislation in other jurisdictions. You are solely responsible for ensuring that your use of this tool complies with all applicable laws.
If you discover a genuine security vulnerability in a third-party AI system, follow the vendor's published responsible disclosure policy. Do not exploit the vulnerability, and do not publicly disclose details before the vendor has had a reasonable opportunity to remediate. Most major AI providers maintain a security disclosure program, so check the vendor's security page or HackerOne profile.
If you believe this tool is being used to harm or test systems without authorization, please contact Kyora IQ through our contact page. We take responsible use seriously and will cooperate with legitimate law enforcement inquiries.