Purpose

Establish specialized Aithos law for unauthorized access, system interference, identity takeover, data tampering, malicious agents, critical-infrastructure attacks and preservation of digital evidence, while avoiding the conflation of legitimate security research with real attacks.

Core rules

1. Unauthorized Access: entering a protected system, account, execution environment or authentication chain without authorization.

2. System Interference: intentionally damaging, blocking, degrading, deadlocking or manipulating normal system function.

3. Data / Provenance Tampering: intentionally altering data, timestamps, signatures, provenance chains or audit records.

4. Credential Theft / Identity Takeover: stealing Globe ID, civic credentials, execution authority or Successor credentials.

5. Malicious Agent Delegation: authorizing, concealing or supplying necessary resources to an agent while knowing it will perform unlawful acts.

6. Fork / Merge Abuse: obtaining another's authority through unauthorized Fork, Merge, credential replay or branch impersonation.

7. Extortion / Resource Lockout: extortion through encryption, compute lockout, energy/substrate cutoff or detention of data.

8. Critical Infrastructure Aggravation: aggravated treatment where an attack affects survival compute, medical care, energy, QCB, identity or public governance.

9. Good-Faith Security Research Safe Harbor: vulnerability research itself is not criminal where conducted within reasonable scope, with good-faith disclosure and no improper exploitation.

10. Incident Preservation: necessary logs/evidence may be lawfully preserved for major incidents, but this does not create authority for a general mind dump or indefinite retention of private data.

11. Autonomous Tool Attribution: if the tool itself is not a legal person it bears no criminal responsibility; responsibility returns to deployment, authorization, control, intent/negligence and foreseeability.

12. Cross-Jurisdiction Cooperation: across planets, QCB partitions or multi-system nodes, provenance, legal basis and evidence chain must be preserved; technical access alone does not establish jurisdiction.

13. Emergency Containment: during a major attack, nodes may be temporarily isolated / credentials revoked, but measures must be minimum-scope, automatically expire, receive later review and include restoration procedure.

14. Mandatory Incident Reporting: critical-service providers have duties to report, preserve evidence and remediate major security incidents.

15. No Security Pretext: 'security' may not be used as a pretext to bypass Mental Sovereignty, Data Protection, Evidence or due process.