Legal

Acceptable Use Policy

SecByte teaches defensive and authorised offensive security practice. This policy sets the boundaries for using our platforms, training environments and professional services.

Last updated: 30 August 2026

1. Authorised testing only

Every practical technique taught by SecByte is intended for use inside our own training environments or against systems for which you hold documented, written authorisation from the system owner. Security testing without that authorisation is unlawful in most jurisdictions. Our professional services are delivered only under a signed engagement agreement and a defined scope agreed with the asset owner.

2. What SecByte does not sell

SecByte does not sell, supply or facilitate: malware or ransomware, credential-theft services, unauthorised access to any system or account, stolen data or credentials, surveillance of individuals without lawful basis, denial-of-service capability, or exploitation services against third parties. Requests for such work are refused and may be reported to the relevant authorities.

3. Platform conduct

  • Do not attack, scan, overload or attempt to gain unauthorised access to SecByte systems outside a designated training environment.
  • Do not share, resell, scrape or republish exam questions, question banks, lab content or course material.
  • Do not share your account, impersonate another candidate, or misrepresent your identity.
  • Do not upload malicious files, unlawful content, or content you do not have the right to submit.
  • Do not use SecByte services to harass, threaten or defraud anyone.

4. Training environments

Deliberately vulnerable labs and capture-the-flag challenges are isolated for practice. Techniques learned there must not be applied outside them. Attempting to pivot from a lab to production infrastructure, other tenants, or the wider internet is a serious breach.

5. Enforcement

Breaches may result in warning, suspension of access, invalidation of exam attempts, revocation of credentials, termination of the account without refund, and — where the law requires it — referral to law enforcement. Decisions may be appealed under the process set out in the Code of Conduct.

6. Reporting abuse

Report suspected misuse of SecByte services or a security issue in our platform to contact@secbyte.org. See the Security page for responsible-disclosure guidance.

Questions about this document? Email contact@secbyte.org or call +880 1680 032529. SecByte LLC, a limited liability company registered in the State of Wyoming, United States.