Acceptable Use Policy

Cal Security & Forensics LLC
This policy forms part of our Terms of Service.

1. The core rule

You must have explicit written authorisation from the system owner before applying any offensive technique, tool, or knowledge obtained through this platform to any system, network, or device you do not personally own.

This is not a disclaimer buried in fine print. It is the condition on which access to this platform is granted. Accepting these terms is your acknowledgment that you understand and will comply with it.

2. What this platform is for

Cal Security & Forensics provides tools, training, and certification for cybersecurity and digital forensics professionals. The intended uses are:

  • Learning and practising techniques in controlled environments you own or have permission to use;
  • Conducting authorised security assessments, penetration tests, and forensic investigations;
  • Preparing for and sitting the CSFA certification examination;
  • Professional development and continuing education.

3. Prohibited conduct

You must not use this platform or any knowledge, tool, or technique obtained through it to:

3.1 Unauthorised access and interference

  • Access, probe, scan, or test any system, network, or device without explicit written authorisation from its owner;
  • Intercept, capture, or analyse network traffic on networks you do not own or administer without authorisation;
  • Exploit, disrupt, degrade, or deny service to any system or network without authorisation;
  • Bypass, circumvent, or defeat authentication, access controls, or security measures on systems you are not authorised to test.

3.2 Malicious use

  • Create, deploy, or distribute malware, ransomware, spyware, or any software designed to cause harm;
  • Conduct phishing, social engineering, or credential-harvesting attacks against real individuals or organisations without their written consent as part of an authorised engagement;
  • Use the platform to facilitate, plan, or execute any criminal activity.

3.3 Data and privacy

  • Collect, exfiltrate, or retain data from systems you are not authorised to access;
  • Submit indicators to the Blue Team threat-intelligence lookup tool where doing so would breach a client agreement, non-disclosure agreement, or legal obligation — see the Privacy Policy for details of how that tool works.

3.4 Platform integrity

  • Attempt to reverse-engineer, decompile, or extract examination questions, answer keys, or proprietary content from the platform;
  • Share, sell, or distribute examination questions, answers, or session content;
  • Circumvent rate limits, access controls, or entitlement checks on the platform itself;
  • Use automated means to access the platform in a way that degrades service for other users.

4. Your responsibility for authorisation

Authorisation is your responsibility to obtain and document before beginning any engagement. Verbal permission is not sufficient. A written scope-of-work, statement of work, or engagement letter signed by an authorised representative of the target organisation is the minimum standard.

"I thought I had permission" is not a defence. "I was testing my own infrastructure" requires that you can demonstrate ownership or administrative control.

If you are unsure whether you have adequate authorisation for a specific activity, do not proceed until you have confirmed it in writing.

5. Consequences of violation

Violation of this policy may result in immediate suspension or termination of your account without refund, reporting to relevant law enforcement authorities, and civil or criminal liability under applicable computer fraud, unauthorised access, and cybercrime laws.

We cooperate fully with law enforcement investigations. We retain logs sufficient to identify accounts and activity associated with a violation.

6. Reporting violations

If you become aware of a violation of this policy — including misuse of platform content or tools by another user — please report it to [email protected].

7. Relationship to Terms of Service

This policy is incorporated into and forms part of the Terms of Service. Defined terms used here have the meanings given in the Terms of Service. In the event of conflict, the Terms of Service govern.

We may update this policy as the platform evolves. Material changes will be notified by email or in the platform. Continued use after the effective date of an update constitutes acceptance.