Code of conduct
The short version: be decent, and only hack what you’re allowed to.
MaaSec teaches offensive and defensive security. That knowledge comes with responsibility, and membership means agreeing to use it well.
Be respectful
Everyone starts somewhere. No gatekeeping, no harassment, no condescension toward beginners. Labs are a place to ask “dumb” questions safely.
Stay legal and authorised
- Only test systems you own or are explicitly authorised to test — CTF targets, our lab environment, or in-scope bug bounty programs.
- Report vulnerabilities responsibly through official channels, and stop the moment impact is demonstrated.
- Never use skills learned here to access, damage, or exfiltrate data without permission.
Reporting
If something crosses a line — conduct or ethics — tell a board member or write to acm@maasec.com. Reports are handled discreetly.