// CODE OF ETHICS
Code of Ethics
A single-page agreement for lawful, ethical, authorized, and constructive cybersecurity research at Vexel.
Purpose
I am joining Vexel to learn, teach, research, and contribute to cybersecurity, software development, vulnerability research, and public-interest security work. I understand that cybersecurity skills can be used for both protective and harmful purposes. I agree to use my skills only for lawful, ethical, authorized, and constructive activities.
General Ethical Commitment
I agree to:
- Act lawfully, honestly, professionally, and in good faith.
- Use cybersecurity knowledge to improve security, safety, education, and public benefit.
- Respect privacy, confidentiality, property rights, and intellectual property rights.
- Avoid causing harm to systems, networks, users, organizations, or the public.
- Follow all applicable laws, regulations, contracts, terms of engagement, and organizational policies.
- Report unsafe, unauthorized, illegal, or unethical activity to organization leadership.
Authorization Requirement
I will not access, test, scan, exploit, modify, disrupt, or attempt to compromise any computer, network, device, account, application, cloud environment, or data unless I have clear authorization. Authorization must be one of the following:
- A written agreement, rules of engagement, statement of work, bug bounty policy, vulnerability disclosure policy, or other documented permission.
- A lab, CTF, sandbox, training environment, or system intentionally provided for testing.
- A system that I personally own or have explicit permission to test.
Scope and Rules of Engagement
For any authorized test, assessment, bug bounty, research project, or client engagement, I agree to stay within the approved scope. I will not:
- Test systems, domains, IP addresses, accounts, devices, employees, or third parties outside the approved scope.
- Exceed approved testing methods, time windows, rate limits, or technical boundaries.
- Use destructive techniques unless explicitly approved in writing.
- Conduct social engineering, phishing, physical security testing, denial-of-service testing, malware deployment, credential attacks, persistence, lateral movement, or data exfiltration unless explicitly authorized in writing.
- Continue testing after authorization is revoked, the engagement ends, or I am asked to stop.
Prohibited Conduct
I agree that I will not, under any circumstances connected to Vexel:
- Gain or attempt to gain unauthorized access to systems, networks, accounts, data, devices, or facilities.
- Steal, sell, leak, publish, trade, or misuse credentials, tokens, API keys, private keys, session cookies, personal data, confidential data, or proprietary information.
- Deploy malware, ransomware, spyware, botnets, backdoors, credential stealers, destructive payloads, or unauthorized persistence mechanisms.
- Perform denial-of-service attacks or intentionally degrade the availability of systems or networks.
- Intercept, monitor, sniff, record, or inspect network traffic without authorization.
- Masquerade as another person, organization, employee, vendor, customer, or system without authorization.
- Use organization resources to harass, threaten, extort, stalk, dox, defame, intimidate, or harm others.
- Use discovered vulnerabilities for personal gain, coercion, extortion, retaliation, or public embarrassment.
- Publicly disclose vulnerabilities before completing the organization's approved disclosure process.
- Use the organization's name, logo, email, infrastructure, reputation, or relationships for unauthorized research, commercial activity, or personal projects.
- Violate export controls, sanctions, privacy laws, computer crime laws, intellectual property laws, or contractual obligations.
- Misrepresent my role, authority, findings, credentials, or affiliation with Vexel.
Vulnerability Research and Disclosure
When participating in vulnerability research, I agree to follow responsible and coordinated disclosure practices. I will:
- Minimize access to data and only collect what is necessary to prove the vulnerability.
- Avoid viewing, copying, downloading, modifying, deleting, or transmitting sensitive data unless explicitly authorized.
- Stop testing and notify leadership if I accidentally access sensitive data, production data, personal information, secrets, credentials, or systems outside scope.
- Document findings accurately, professionally, and without exaggeration.
- Give affected vendors, owners, clients, or maintainers a reasonable opportunity to investigate and remediate issues before public disclosure.
- Follow any applicable vulnerability disclosure policy, bug bounty rules, client rules of engagement, or legal agreement.
- Coordinate external communications through approved organization leadership unless I am explicitly authorized to communicate directly. I will not threaten disclosure, demand payment, withhold details for leverage, or imply that a vendor or system owner must provide compensation in exchange for silence.
Client, Partner, and Hardware Research
If Vexel receives hardware, software, cloud access, credentials, test accounts, documentation, or other materials from a company, sponsor, nonprofit, school, government entity, or partner, I agree to use those resources only for the approved purpose. I will not:
- Reverse engineer, modify, publish, resell, transfer, or retain provided materials except as authorized.
- Test connected services, customer environments, production infrastructure, mobile apps, APIs, cloud backends, or third-party systems unless they are clearly included in scope.
- Publish vulnerability details, exploit code, photos, teardown results, firmware, binaries, keys, or confidential information without approval.
- Contact a company as a representative of Vexel unless authorized to do so.
Data Handling and Confidentiality
I agree to protect all sensitive information I encounter, including but not limited to:
- Personal information.
- Client information.
- Credentials, secrets, keys, and tokens.
- Vulnerability reports.
- Exploit details.
- Internal organization documents.
- Unreleased software, firmware, or hardware information.
- Donor, sponsor, student, member, or volunteer information. I will store sensitive data only in approved locations, use appropriate access controls, and delete or return data when instructed. I will not copy sensitive data to personal devices, public repositories, personal cloud storage, Discord, Slack, email, or paste sites unless explicitly approved.
Use of Organization Resources
Organization resources may include labs, cloud accounts, domains, servers, VPNs, tools, email accounts, source code repositories, hardware, credentials, funding, sponsor-provided equipment, and communication platforms. I agree to use these resources only for approved organization activities. I will not use organization resources for:
- Unauthorized scanning, exploitation, or attacks.
- Personal commercial work.
- Cryptocurrency mining.
- Piracy or copyright infringement.
- Harassment or abuse.
- Political campaign activity prohibited for 501(c)(3) organizations.
- Any activity that creates legal, financial, reputational, or operational risk for the organization.
Training, CTFs, and Labs
I understand that cybersecurity training must be conducted in safe and authorized environments. I agree that offensive security practice must be limited to:
- CTF platforms.
- Intentionally vulnerable machines.
- Organization-approved labs.
- Personal systems I own.
- Systems where written permission has been granted. I will not use techniques learned in training against real-world systems without authorization.
Software Development Ethics
When contributing code, tools, scripts, documentation, or research to Vexel, I agree to:
- Follow secure coding practices.
- Avoid intentionally introducing backdoors, hidden accounts, malicious logic, or insecure defaults.
- Respect software licenses and intellectual property rights.
- Avoid committing secrets, credentials, tokens, or sensitive data to repositories.
- Clearly label proof-of-concept code and restrict access when misuse is likely.
- Follow project maintainers' contribution, review, and approval processes.
Conflicts of Interest and Nonprofit Integrity
I understand that Vexel is intended to operate for charitable, educational, scientific, and public-interest purposes. I agree not to use the organization for improper personal benefit, private gain, undisclosed commercial activity, or preferential treatment. I will disclose any actual or potential conflict of interest involving sponsors, vendors, clients, employers, family members, paid work, ownership interests, or personal financial benefit.
Reporting Requirement
If I become aware of illegal, unsafe, unauthorized, or unethical activity connected to Vexel, I agree to promptly report it to organization leadership. This includes:
- Unauthorized access.
- Accidental access to sensitive data.
- Out-of-scope testing.
- Lost or exposed credentials.
- Misuse of tools or infrastructure.
- Unapproved disclosure of vulnerabilities.
- Harassment, threats, or coercive behavior.
- Requests from third parties to perform suspicious or unauthorized work.
No Legal Authority or Protection
I understand that membership in Vexel does not give me special legal authority, immunity, permission to test third-party systems, or permission to violate laws or policies. I understand that claiming to be doing "research," "education," "pentesting," or "ethical hacking" does not make an activity lawful or authorized.
Discipline and Removal
Violation of this agreement may result in one or more of the following:
- Warning or retraining.
- Removal from a project or event.
- Suspension or termination of membership.
- Revocation of access to organization resources.
- Reporting to affected organizations, schools, sponsors, platforms, law enforcement, or other appropriate parties.
- Civil, criminal, academic, or employment consequences.
Acknowledgment
By signing this agreement, I acknowledge that:
- I have read and understand this Code of Ethics and Acceptable Use Agreement.
- I agree to follow it at all times when participating in Vexel activities.
- I understand that I am personally responsible for my actions.
- I understand that violating this agreement may result in removal from the organization and possible legal consequences.
- I understand that this agreement may be updated, and continued participation may require signing the updated version.