Last updated July 28, 2026
Redline is a browser extension and dashboard built for penetration testing and bug bounty work — a payload reference, some passive recon, and a place to track findings. By creating an account, you're agreeing to the terms below. If something here doesn't sit right with you, the honest answer is: don't sign up.
This is the part that actually matters. Redline is built for testing systems you own or have explicit, documented permission to test — a bug bounty program's published scope, a signed pentest agreement, your own infrastructure. That's it.
The extension doesn't check your authorization before letting you use a payload. That was a deliberate choice, not an oversight — it means the tool trusts you to know your own scope instead of getting in your way with a permission system that can't actually verify anything real. It also means the responsibility sits entirely with you. If you point this at something you're not authorized to test, that's on you, not on the software.
Unauthorized access to computer systems is illegal in most places — the Computer Fraud and Abuse Act in the US, the Computer Misuse Act in the UK, and equivalents nearly everywhere else. We're not going to pretend to summarize the law for you here. If you're not sure whether what you're about to do is authorized, stop and find out before you use this tool for it.
You're responsible for whatever happens under your account — keep your password and API keys to yourself, and let us know if you think either has leaked. One account per person; don't share logins.
We can suspend or delete an account that's being used to abuse the service, attack infrastructure it has no business touching, or violate the authorized-use section above. We'd rather not have to, but we will.
Whatever you store in Redline — programs, targets, findings, recon results — is yours. If you're self-hosting the dashboard, it lives in a database you control; we don't have access to it. If you're using a hosted instance someone else runs, ask them what their own data practices look like — this document only covers Redline the software, not any particular deployment of it.
Redline is provided as-is. Recon results can be incomplete or wrong, payloads may not work against every target, and reports are a starting point, not a guarantee that a submission will be accepted. Nothing here is a substitute for actually verifying your own findings before you submit them anywhere. We're not liable for decisions you make based on what this tool tells you, or for damages arising from how you use it.
We might update this page as the product changes. If we make a change that meaningfully affects your rights, we'll try to make it obvious rather than quietly editing the date at the top. Continuing to use Redline after an update means you're accepting the new version.
If any of this is unclear, ask before you assume — reach out through wherever you got access to this instance of Redline.