Acceptable Use Policy
Last updated: September 2026
This Acceptable Use Policy ("AUP") governs use of the StrikeCyber website, client portal and platform (together, the "Services") provided by StrikeCyber Inc. It applies to every person granted access to the Services, and forms part of, and should be read with, our Terms and Conditions and Privacy Policy.
Purpose
We are an offensive security firm. The material that passes through our platform includes vulnerability detail, exploitation evidence, credentials and network topology for real client environments. In the wrong hands, or used outside an authorized engagement, that material is exactly what an attacker needs.
This policy exists to make the boundaries explicit. It is short, and none of it is optional.
Authorization is mandatory
You may use the Services only in connection with an engagement for which valid, current, written authorization exists, and only within the scope that authorization defines.
Unauthorized access to a computer system is a federal crime under the Computer Fraud and Abuse Act, and a crime under the computer misuse statutes of every state. Findings, tooling, techniques and credentials obtained through the Services must never be used against any system outside an authorized scope, including your own systems that are not named in the rules of engagement, and including systems belonging to a parent, subsidiary or affiliate that was not part of the engagement.
If you believe a system should be in scope and it is not, ask us to vary the scope in writing. Do not proceed on an assumption.
Account and credential security
You must:
- Keep your portal credentials confidential and not share accounts;
- Use the multi-factor authentication we require, and not attempt to circumvent it;
- Access the Services only from devices you are authorized to use and which are maintained to your organization's security standards;
- Tell us immediately at info@strikecyber.com if you suspect an account has been compromised, or if a person who held access has left your organization.
We log access and administrative actions in the platform. Those logs exist to protect you as much as us.
Prohibited conduct
You must not:
- Use the Services to access, test or interfere with any system outside an authorized scope;
- Attempt to gain unauthorized access to the Services, other clients' data, or any part of our infrastructure;
- Copy, extract or retain findings, evidence or credentials other than as needed for remediation within your organization;
- Share findings with any third party except as permitted in your engagement agreement, or as needed to remediate under confidentiality;
- Publish or disclose vulnerability detail about a third party's systems without that party's consent and a coordinated disclosure process;
- Use the Services to develop, distribute or deploy malicious code beyond an authorized engagement scope;
- Reverse engineer, resell, sublicense or provide access to the Services to any person outside your organization;
- Use the Services in violation of United States export control law, including the Export Administration Regulations and, where applicable, the International Traffic in Arms Regulations, or provide access to a person who is not eligible to receive controlled technical data;
- Use the Services to harass, defraud or impersonate any person, or in violation of any applicable law.
Handling of findings, data and tooling
Reports and findings we deliver are confidential. Treat them as you would treat a live vulnerability, because that is what they describe until it is remediated.
Distribute them on a need-to-know basis, store them under access control, and remove access when it is no longer needed. Where a report is shared with an auditor, regulator, insurer or customer, share it under confidentiality.
Tooling, scripts and techniques disclosed to you during an engagement are provided for your understanding and remediation. They are not licensed for use against any other environment.
Responsible disclosure
If you discover a vulnerability in the StrikeCyber website, portal or platform, we want to hear about it. Report it to info@strikecyber.com with enough detail for us to reproduce it.
We ask that you do not access, modify or exfiltrate data belonging to us or any other client, do not degrade the availability of the Services, and give us reasonable time to remediate before disclosing publicly. We will acknowledge your report, keep you informed, and will not pursue action against good-faith research conducted within these limits.
Monitoring
We monitor the Services for security, availability and compliance with this policy. Monitoring is proportionate and directed at protecting client data. It is not a general surveillance of your work.
Suspension and enforcement
We may suspend or terminate access immediately, and without notice where the risk warrants it, if we reasonably believe this policy has been breached, if authorization for an engagement has been withdrawn or is unclear, or if continued access would put client data or either party at legal or safety risk.
Serious breaches, including unauthorized testing, will be reported to your organization and, where we are legally obliged or where a third party's systems have been affected, to law enforcement or the affected party.
Changes
We may update this policy from time to time. The current version is always available at this page, and the date it was last updated appears above.
Contact
Questions about this policy can be sent to info@strikecyber.com, or by mail to StrikeCyber Inc., 3723 Greenville Ave STE 55230, Dallas, TX 75206.
