Offensive techniques taught by ShieldCore Academy are for authorised, in-scope testing only. Using them without documented authorisation is unlawful in most jurisdictions.

01 Scope

This policy applies to all users of shieldcoresec.com, the training platform, lab environments, client portals, community channels and any deliverable or material we provide. It is incorporated into our Terms and Conditions.

02 Prohibited Conduct

Users may not:

  • Use our services, tooling or training for any illegal activity.
  • Conduct unauthorised hacking — scanning, exploitation, credential attacks, social engineering or persistence against any system without documented authorisation from its owner.
  • Abuse training labs, including using them to attack external targets.
  • Attempt to attack, degrade or probe ShieldCore Security infrastructure.
  • Resell, share, republish or redistribute course materials or deliverables.
  • Upload malware or malicious code to our systems outside designated sandboxes.
  • Harass, threaten or impersonate others, or share content that is unlawful, hateful or infringing.
  • Circumvent access controls, licence limits, rate limits, watermarking or account restrictions.
  • Use automated scraping, bulk downloading or model-training extraction against our content.

03 Training Lab Rules

  • Lab activity must remain within assigned lab networks and target ranges.
  • Do not pivot to, tunnel through, or route traffic toward the public internet.
  • Do not attack other students' instances, accounts or credentials.
  • Do not exfiltrate lab images, flags, solutions or write-ups to public repositories.
  • Do not use lab compute for mining, proxying, hosting or unrelated workloads.

04 ShieldCore Infrastructure

Testing our production systems, websites, email infrastructure or staff is prohibited unless carried out under our coordinated disclosure process and within the boundaries we confirm in writing. Denial-of-service testing, physical intrusion and social engineering of ShieldCore personnel are never authorised.

05 Course Materials & Resale

Access is licensed to a single named individual. Sharing credentials, mirroring content, reselling access, or reproducing materials for another training provider is a material breach and may also infringe copyright. We use watermarking and access analytics to detect distribution.

06 Malicious Code

Malware samples may be handled only inside designated analysis sandboxes provided for that purpose, following the handling instructions given. Uploading malicious code, live payloads or destructive tooling to our websites, ticketing systems, shared drives or client portals is strictly prohibited.

07 Enforcement

Violations may result in immediate account termination without refund, revocation of certificates and lab access, removal from cohorts and community channels, and termination of client engagements. We may preserve and disclose relevant logs and evidence to affected parties, payment processors or law enforcement where lawful or legally required, and may pursue civil remedies.

08 Reporting Abuse & Vulnerabilities

Report abuse to abuse@shieldcoresec.com. If you believe you have found a security vulnerability in our systems, report it to disclosure@shieldcoresec.com with enough detail to reproduce it, and allow us reasonable time to remediate before any public disclosure. Please do not access, modify or exfiltrate data belonging to others while testing.

09 Contact

Abuse: abuse@shieldcoresec.com
Legal: legal@shieldcoresec.com

This page is maintained by ShieldCore Security to describe our current practices. It is provided for information only, is not legal advice, and does not constitute independent certification or verification of any control. Where a signed master services agreement, statement of work, or data processing agreement exists, that document governs.