Acceptable Use Policy
This Acceptable Use Policy ("Policy") applies to all use of the BattleTest Service and forms part of our Terms of Service. It is designed to let legitimate security teams test effectively while protecting systems, users, and third parties.
1. Authorisation Is Required
You may test a target only when you own it or have explicit permission from a person authorised to approve the testing. Permission must cover the target, techniques, intensity, timing, and data access involved. You must keep evidence of authorisation and provide it to BattleTest on reasonable request.
A publicly accessible system, bug bounty programme, or vulnerability disclosure policy is not automatically permission for every BattleTest capability. You are responsible for following the programme's scope, rate limits, safe-harbour terms, and reporting requirements.
2. Scope and Safety
- Use the least intrusive permission level and test method reasonably suited to your objective.
- Use dedicated test accounts and non-production credentials where practical.
- Do not access, alter, retain, or disclose more data than necessary to confirm a finding.
- Stop testing and notify the system owner if activity causes unexpected harm, instability, or access to sensitive third-party data.
- Respect target boundaries, maintenance windows, rate limits, and instructions from the system owner.
3. Prohibited Uses
You must not use the Service to:
- access or test systems without adequate authorisation;
- perform denial-of-service activity, destructive testing, ransomware, cryptomining, data destruction, or deliberate service disruption;
- deploy malware, persistence, botnets, phishing, credential theft, credential stuffing, or broad password attacks;
- exfiltrate personal data, secrets, payment data, health data, or other sensitive information beyond the minimum evidence needed for an authorised test;
- evade law enforcement, sanctions, access controls, or a provider's protective measures for an unlawful or abusive purpose;
- harass, stalk, threaten, discriminate against, or endanger any person;
- infringe intellectual property, privacy, publicity, contractual, or other rights;
- probe BattleTest, other customers, or our providers except under a written vulnerability-disclosure or testing authorisation;
- share accounts, bypass plan limits, interfere with the Service, or attempt to extract non-public system instructions, credentials, or model data; or
- resell, sublicense, or provide the Service as a bureau service without written permission.
4. Findings and Disclosure
Validate findings before treating them as confirmed. Handle reports as confidential security information and disclose them only to people authorised to receive them. Follow coordinated-disclosure requirements and do not use a finding for extortion, public pressure, trading, or other improper advantage.
5. Enforcement
We may investigate suspected violations and may rate-limit, pause, or suspend activity while we assess risk. We may remove content, restrict capabilities, or terminate accounts for violations. Where appropriate and legally permitted, we may notify the affected system owner, service provider, or authorities. We will consider context, severity, repetition, cooperation, and whether immediate action is necessary to prevent harm.
To report abuse or appeal an enforcement decision, contact [email protected].
6. Changes
We may update this Policy as the Service and security risks evolve. Material changes will be communicated as described in our Terms of Service.