Skip to main content

Ethical use agreement

Everyone working with offensive security tooling through Encrypt Bytes Labs, whether staff, career-track participants or clients under test, agrees to use that capability exclusively for lawful and ethical purposes.

The purpose of our security work is to find and close weaknesses before someone else does. It is never a licence for illegal, malicious or unethical activity, and the same rules apply whether the target belongs to a client, a partner or ourselves.

Guidelines

  1. 1

    Authorised access only

    Engage in security testing only against systems, networks or applications for which written authorisation exists, and only within the agreed scope and testing window. Unauthorised access is prohibited without exception.

  2. 2

    No malicious intent

    Never act with intent to steal information, disrupt a service, or cause harm to an individual or organisation. Demonstrating a vulnerability stops at proof. It does not extend to exploiting it further.

  3. 3

    Responsible disclosure

    Report any vulnerability discovered to the affected party through the agreed channel, with enough detail to reproduce and remediate it, and allow reasonable time to fix before any wider disclosure.

  4. 4

    Respect for privacy

    Treat any data encountered during testing as confidential. Do not exfiltrate, retain, disclose or reuse it, and record only what is necessary to evidence a finding.

  5. 5

    Compliance with law

    Comply with all applicable laws, regulations and industry standards governing security testing and data handling, including India's Information Technology Act and Digital Personal Data Protection Act, and the GDPR where it applies.

  6. 6

    Professional conduct

    Conduct yourself professionally in every engagement. Do not misrepresent findings, overstate severity, or behave in a way that reflects poorly on the client, the profession or this team.

Breach of this agreement

Breaching these guidelines ends the engagement or placement immediately, and may be reported to the affected party and the relevant authorities.

Questions about this agreement? Write to [email protected].