CYPHERYN Responsible Use Policy
The rule
You may use CYPHERYN for authorized defensive security and lawful OSINT activities.
You may not use CYPHERYN to attack, compromise, harm, stalk, defraud, or unlawfully investigate other people or systems.
Permitted examples
- Scanning your own domain or infrastructure.
- Investigating your organization's public attack surface.
- Assessing a client's infrastructure under valid authorization.
- Defensive threat intelligence and lawful OSINT research.
- Preparing for an authorized penetration test.
Prohibited examples
- Scanning targets without required authorization.
- Attempting unauthorized access or stealing credentials.
- Deploying malware or conducting destructive attacks.
- Using collected information for harassment, stalking, fraud, or impersonation.
- Circumventing access controls without authorization.
These examples are illustrative, not exhaustive. Follow applicable law, contracts, provider rules, and the rights of others.
Active testing
Passive public-data collection and active interaction are different. Before active collection, record a current authorization that identifies the scope, authorizer, purpose, permitted activity, and validity period. Stop if scope or authority is uncertain.
Report concerns
Report product vulnerabilities through the process on the Security page. Do not test CYPHERYN infrastructure beyond the authorization provided there.