Acceptable Use Policy
Last updated: August 2026
This Acceptable Use Policy ("AUP") governs the use of the StrikeCyber website, client portal and platform (together, the "Services") provided by StrikeCyber Pty Ltd (ACN 677 052 041). It applies to every person granted access to the Services, and forms part of, and should be read with, our Terms and Conditions and Privacy Policy.
Purpose
Our Services support offensive security testing, so responsible use is not optional — it is fundamental. This policy sets out what is and is not acceptable, so that all testing is lawful, authorised, in scope and safe. If anything in this policy is unclear, ask us before you act.
Authorisation is mandatory
You may only use the Services in connection with testing of systems that you own, or are expressly authorised in writing to test. You must not use the Services, or any information, tooling or output obtained through them, to access, test, scan, disrupt or attack any system, account or data without proper authorisation.
Scope, targets, timing, permitted techniques and rules of engagement are defined in your engagement agreement and must be followed at all times. If you discover that testing is straying outside the agreed scope, stop and contact us.
Account and credential security
If you are granted access to the client portal:
- You are responsible for keeping your credentials secure and for all activity under your account.
- You must not share credentials, or allow access by anyone who is not an authorised user.
- You must use multi-factor authentication where it is offered.
- You must notify us immediately of any suspected unauthorised access or credential compromise.
Prohibited conduct
You must not:
- Use the Services for any unlawful, fraudulent, harmful, deceptive or malicious purpose.
- Attempt to access, test or attack any account, environment, data or system without authorisation, including other clients' data or our own infrastructure beyond what an engagement permits.
- Exceed the agreed scope or rules of engagement, or continue testing after authorisation has ended.
- Interfere with, degrade, overload or disrupt the Services or the infrastructure on which they run.
- Reverse engineer, decompile, copy, resell or redistribute the Services, our methodologies or our tooling, except as expressly permitted.
- Use findings, reports or tooling obtained through the Services to extort, defraud, attack or harm any organisation or individual.
- Upload, deploy or distribute malicious code outside an authorised and agreed engagement.
- Exfiltrate, retain or disclose data beyond what is necessary to demonstrate a finding and permitted by the engagement.
- Misrepresent your authority or identity, or use the Services on behalf of a third party without authorisation.
Handling of findings, data and tooling
Information accessed through the Services — including findings, reports, evidence and any data encountered during testing — is confidential. You must handle it in accordance with your engagement agreement and applicable law, store it securely, use it only for its intended purpose, and not disclose it except as permitted. Any data incidentally accessed during authorised testing must be minimised, protected and reported to us, not retained or used.
Responsible disclosure
If you become aware of a vulnerability in the Services themselves, or in StrikeCyber's own systems, please report it to us promptly and privately at info@strikecyber.au, and do not exploit it or disclose it publicly before we have had a reasonable opportunity to respond.
Monitoring
We may monitor and log use of the Services to protect their security and integrity, investigate suspected breaches of this policy, and meet our legal obligations. Activity within the client portal is logged.
Suspension and enforcement
We may suspend or terminate access to the Services, without notice, where we reasonably believe this policy has been breached, or where continued use poses a security, legal or reputational risk. Serious or unlawful conduct may be reported to the relevant authorities, and may be the subject of legal action.
Changes
We may update this policy from time to time. The current version is always available on this page, and the "last updated" date above shows when it last changed.
Contact
Questions about this policy, or reports of misuse or vulnerabilities, can be directed to info@strikecyber.au or 1300 654 898.
