Permitted use
You may use CyberKnight training, lab ranges and services to learn security concepts, practise technique inside our controlled environments, test systems you own, and test systems you have explicit written authorisation from the owner to test.
Our lab ranges exist specifically so you have somewhere lawful to practise. They are isolated environments we own and operate. You are authorised to attack them.
Prohibited use
You must not use anything learned here, or any CyberKnight service, to do any of the following:
- Access any system, network or account without authorisation from its owner
- Obtain, use or trade credentials that are not yours
- Take over an account belonging to another person, for any reason
- Bypass authentication, multi-factor authentication or platform protections on services you do not own
- Deploy malware, ransomware or destructive payloads against any live system
- Conduct scanning, testing or reconnaissance against systems outside an agreed scope
- Commit fraud, extortion, harassment or stalking
- Intercept, monitor or exfiltrate another person's private data
- Resell, redistribute or share your course access
Requesting a service
When you request a security service you must confirm that you own the system or account concerned, or that you are authorised by its owner. That confirmation is recorded with your account and the time you gave it.
We do not accept engagements against systems you cannot demonstrate authority over. We will decline requests to recover, access or take over an account belonging to someone else, regardless of the reason given. Where an official recovery process exists — as it does for every major platform — that is the correct and lawful route, and we will point you to it.
What we will never ask you for
No CyberKnight staff member will ever ask you for a password, a one-time code, a two-factor code, a recovery code, a session cookie or a private key. If anyone claiming to represent us asks for these, they are not us. Report it to us immediately.
Enforcement
Accounts used in breach of this policy are suspended without refund. Where we believe an offence has been committed we will cooperate with lawful requests from authorities, and we retain the access logs necessary to do so.
The legal position
Unauthorised access to a computer system is a criminal offence in most jurisdictions, including India under the Information Technology Act 2000, the United Kingdom under the Computer Misuse Act 1990, and the United States under the Computer Fraud and Abuse Act. Ignorance of scope is not a defence, and neither is curiosity. Get permission in writing, every time.