Company: HyberX (“Company,” “we,” “us,” or “our”)
1. Zero-Tolerance Policy for Unauthorized Security Testing
The Company maintains a strict prohibition against unauthorized penetration testing, vulnerability testing, security research, scanning, probing, exploitation, or other security testing involving our applications, websites, APIs, infrastructure, networks, systems, accounts, databases, or related services (“Services”).
No user, researcher, customer, contractor, security professional, organization, or other person is authorized to perform security testing against the Services unless the Company has provided explicit prior written authorization.
The fact that a system is publicly accessible does not constitute authorization to test its security.
Creating an account, purchasing a subscription, using a free trial, or otherwise obtaining legitimate access to the Services does not grant permission to conduct security testing.
2. Prohibited Activities
Without prior written authorization from the Company, you must not directly or indirectly:
conduct penetration testing or vulnerability assessments;
perform automated or manual vulnerability scanning;
use tools such as vulnerability scanners, exploit frameworks, fuzzers, intercepting proxies, automated reconnaissance systems, AI security agents, or similar security-testing technologies against the Services;
probe ports, endpoints, APIs, authentication mechanisms, infrastructure, cloud resources, or network services for vulnerabilities;
attempt to bypass, disable, circumvent, or defeat authentication, authorization, rate limiting, access controls, security controls, monitoring systems, or protective mechanisms;
attempt privilege escalation;
exploit or attempt to exploit suspected vulnerabilities;
perform SQL injection, command injection, cross-site scripting, SSRF, XXE, directory traversal, deserialization attacks, authentication attacks, or similar security testing;
perform password spraying, credential stuffing, brute-force testing, or credential attacks;
attempt to obtain access to another user's account, session, data, credentials, files, or resources;
intercept, manipulate, modify, delete, extract, download, copy, or exfiltrate information that you are not specifically authorized to access;
conduct denial-of-service, distributed denial-of-service, stress testing, load testing, resource exhaustion, or availability testing;
conduct social-engineering, phishing, impersonation, or employee-targeted security testing;
reverse engineer or analyze the Services for the purpose of identifying security weaknesses except where such restriction is prohibited by applicable law;
deploy malware, payloads, shells, persistence mechanisms, command-and-control infrastructure, or malicious code;
use third-party infrastructure to test or attack the Services; or
instruct, authorize, assist, encourage, or cause another person, automated agent, or AI system to perform any prohibited activity.
This prohibition applies even where the individual claims to be acting in good faith, for research purposes, for educational purposes, or with the intention of informing the Company of vulnerabilities afterward.
3. Unauthorized Testing Will Be Treated as a Security Incident
Any suspected unauthorized security testing may be treated by the Company as an attempted or actual security incident, unauthorized access attempt, or breach of these Terms, regardless of whether the activity successfully compromises a system.
The Company may immediately:
suspend or permanently terminate associated accounts;
block IP addresses, devices, API keys, domains, networks, payment methods, or other identifiers;
revoke access to the Services;
preserve logs, traffic records, account information, authentication records, device information, communications, and other relevant evidence;
investigate the activity internally or through external cybersecurity specialists;
escalate the matter to Company management and legal counsel;
notify affected customers, infrastructure providers, insurers, or other relevant parties where appropriate;
report suspected unlawful activity to law-enforcement, regulatory, governmental, or other competent authorities where appropriate; and
pursue any civil, contractual, equitable, or other legal remedies available to the Company.
The Company expressly reserves all rights and remedies available under applicable law.
4. Written Authorization Is Mandatory
Anyone wishing to conduct penetration testing, vulnerability research, or any other security assessment of the Services must obtain written permission before beginning any testing.
Requests must be submitted to:
info@hyberx.ai
The request should include:
full legal name of the researcher or organization;
contact information;
organization or employer, if applicable;
purpose of the proposed security assessment;
systems, domains, APIs, IP addresses, or applications proposed for testing;
testing methodology and tools;
proposed dates and duration of testing;
source IP addresses that will conduct testing; and
any other information requested by the Company.
Sending an email requesting permission does not constitute authorization.
Testing may begin only after the Company sends an explicit written authorization approving the assessment.
Silence, an automated email response, acknowledgment of your request, previous communication with Company personnel, or failure by the Company to object does not constitute consent or authorization.
5. Scope of Authorization
Any authorization issued by the Company is limited strictly to the:
systems identified in writing;
testing techniques approved in writing;
source systems or IP addresses approved in writing;
individuals or organization specifically authorized;
dates and times specified; and
other conditions contained in the authorization.
Anything outside the approved scope remains strictly prohibited.
The Company may modify, suspend, or revoke authorization at any time.
Authorization to test one Company asset does not authorize testing of any other Company asset, customer environment, employee account, third-party service, cloud provider, integration, vendor, or infrastructure.
6. Discovery of a Vulnerability Without Authorization
If you accidentally discover a potential vulnerability during normal authorized use of the Services, do not attempt to validate, exploit, reproduce, escalate, or further investigate the vulnerability.
Stop the relevant activity and report the issue immediately to:
info@hyberx.ai
You must not access additional information, retain information belonging to other users, modify information, establish persistence, or publicly disclose the vulnerability without the Company's written authorization.
Reporting a vulnerability after conducting unauthorized testing does not retroactively authorize the testing or waive any rights or remedies available to the Company.
7. No Implied Safe Harbor
Unless the Company has provided explicit written authorization specifying otherwise, the Company provides no implied safe harbor, bug bounty authorization, penetration-testing permission, vulnerability-research authorization, or consent to circumvent security controls.
Statements made by employees, contractors, support personnel, community members, or other persons do not constitute authorization unless the authorization is issued through an official Company-authorized channel by an individual with authority to approve security testing.
8. Monitoring and Evidence Preservation
To protect the security and integrity of the Services, the Company may monitor systems and investigate activity for security, fraud-prevention, abuse-prevention, operational, and compliance purposes to the extent permitted by applicable law.
Where suspected unauthorized security activity is detected, the Company may preserve relevant records and evidence for investigation, dispute resolution, legal proceedings, regulatory compliance, or law-enforcement cooperation.
9. Enforcement
Violation of this Policy constitutes a material violation of the Company's Terms of Service and may result in immediate suspension or termination of access without prior notice.
Unauthorized testing may also expose the responsible individual or organization to civil or criminal consequences under applicable computer misuse, cybersecurity, privacy, data protection, property, or other laws.
The Company reserves the right to seek, where legally available:
injunctive or equitable relief;
compensation for damages and losses;
investigation and incident-response costs;
infrastructure remediation costs;
reasonable legal costs;
contractual remedies; and
any other relief available under applicable law.
Nothing in this Policy limits any rights or remedies available to the Company.
10. Acceptance
By accessing or using the Services, you acknowledge that you have read and understood this Policy and agree that you have no authorization to perform penetration testing, security testing, vulnerability scanning, exploitation, or security research against the Services unless you first receive explicit written authorization from the Company.
If you do not have written authorization, do not test our systems.