Axum SEC Logo

Researcher Code of Conduct

Standard

Researcher Code of Conduct

The Researcher Code of Conduct establishes the rules, ethical guidelines, and behavioral expectations for all security researchers (Hunters) registered on the AXUM SEC Technology PLC platform. This code covers authorized testing boundaries, responsible disclosure, confidentiality, communication standards, and consequences for violations. All researchers must read, understand, and agree to this code before participating in any bug bounty or security testing program.

Researcher Code of Conduct

Effective Date: May 13, 2026 Version: 1.0 Issued By: AXUM SEC Technology PLC Applicable to: All registered Security Researchers (Hunters)


1. Introduction

AXUM SEC Technology PLC ("AXUM SEC", "Company", "we", "us", "our") is committed to fostering a trusted, ethical, and professional community of security researchers. This Code of Conduct ("Code") establishes the standards of behavior expected from every researcher ("Hunter", "you", "your") registered on the AXUM SEC platform.

By registering for, accessing, or using the AXUM SEC platform, you agree to abide by this Code of Conduct. Violation of this Code may result in suspension or termination of your account, forfeiture of bounties, and reporting to law enforcement authorities.

Our Core Values:

  • Ethical First – Always act with integrity and within the law
  • Protect, Don't Harm – Your goal is to secure, not destroy
  • Respect Confidentiality – What you find stays between us and the client
  • Disclose Responsibly – Give companies time to fix before public disclosure
  • Continuous Learning – Grow your skills while helping others

2. Scope of This Code

This Code applies to all activities conducted on or through the AXUM SEC platform, including:

  • All bug bounty programs (Public, Private, Hybrid, VDP)
  • All PTaaS (Penetration Testing as a Service) engagements
  • Communication with clients, other researchers, and AXUM SEC staff
  • Use of platform features, chat, and collaboration tools
  • Disclosure of vulnerability information

3. Authorized Testing Rules

3.1 Scope Compliance

You MUST:

RuleDescription
Test Only In-Scope AssetsOnly test systems explicitly listed as "in-scope" for each program
Respect Out-of-Scope NoticesDo not test systems marked "out-of-scope"
Follow Program-Specific RulesEach program may have additional rules; you must read and follow them
Stop When AskedIf a client asks you to stop testing, you must comply immediately

3.2 Prohibited Testing Activities

You MUST NOT:

Prohibited ActivityExplanation
Denial of Service (DoS/DDoS)Any action that disrupts service availability
Physical TestingNo physical intrusion, social engineering, or phishing
Brute Force AttacksNo automated login attempts unless explicitly permitted
Data Destruction or ModificationNo altering, deleting, or corrupting data
Installing Malware or BackdoorsNo persistent access, implants, or backdoors
Accessing Other Users' DataNo accessing data belonging to other customers or researchers
Using Automated Scanners Without PermissionOnly use automated tools if explicitly allowed by the program
Testing Third-Party ServicesDo not test vendors, partners, or third-party systems unless explicitly in-scope

3.3 Permitted Testing Methods

You MAY:

Permitted ActivityConditions
Manual TestingAlways permitted within scope
Automated ScanningOnly if allowed by program rules
Proof of Concept DevelopmentMust not cause harm or data loss
Screenshot CapturePermitted for evidence, do not share publicly
Video RecordingPermitted for evidence, do not share publicly

4. Responsible Disclosure

4.1 Disclosure Rules

RuleRequirement
Report Through Platform OnlySubmit all vulnerabilities through the AXUM SEC platform, not directly to clients
No Public DisclosureDo not disclose vulnerability details publicly without client permission
No TippingDo not share findings on social media, forums, or with third parties
Respect Embargo PeriodsClients need time to fix; wait for disclosure authorization

4.2 Disclosure Timeline

SeverityRecommended Fix TimeDisclosure Authorization
Critical7 daysAfter fix is confirmed
High14 daysAfter fix is confirmed
Medium30 daysAfter fix is confirmed
Low45 daysAfter fix is confirmed
Informational60 daysAfter fix is confirmed or client approval

Early disclosure without permission is a violation of this Code.

4.3 Hall of Fame and Credit

  • Clients may credit you in their Hall of Fame
  • You may list findings in your professional portfolio AFTER disclosure authorization
  • You may not claim credit for vulnerabilities you did not discover

5. Confidentiality

5.1 What is Confidential

Confidential Information includes:

CategoryExamples
Vulnerability DetailsTechnical descriptions, proof of concept, exploitation methods
Client InformationClient names (for private programs), system architecture, internal data
Program DetailsReward ranges, scope details, invite-only program information
Reports and CommentsYour reports and all communication with clients and AXUM SEC staff
Platform SecurityAny security issues found on the AXUM SEC platform itself

5.2 Confidentiality Obligations

You agree to:

  • Keep all Confidential Information strictly confidential
  • Not share Confidential Information with any third party
  • Not use Confidential Information for any purpose outside the program
  • Not post screenshots, code, or findings on social media
  • Not discuss vulnerabilities in public forums or chat groups
  • Securely store any evidence and delete it when no longer needed

5.3 Duration

Confidentiality obligations:

  • Begin when you access any Confidential Information
  • Continue for 5 years after your account termination
  • Continue indefinitely for trade secrets and platform security vulnerabilities

6. Communication Standards

6.1 Professional Conduct

You must communicate:

ExpectationDescription
RespectfullyTreat clients, AXUM SEC staff, and other researchers with respect
ProfessionallyUse professional language; no profanity, harassment, or abuse
ClearlyWrite clear, detailed, and actionable reports
HonestlyDo not exaggerate severity or falsify evidence
PatientlyClients may need time to triage and respond

6.2 Prohibited Communication

You MUST NOT:

  • Harass, threaten, or intimidate any person
  • Use discriminatory or offensive language
  • Spam or flood channels with irrelevant messages
  • Impersonate AXUM SEC staff or client employees
  • Attempt to manipulate bounty decisions through pressure or threats

6.3 Report Quality Standards

High-quality reports include:

ComponentRequirement
TitleClear, descriptive, and accurate
DescriptionDetailed explanation of the vulnerability
Steps to ReproduceNumbered, clear, reproducible steps
Proof of ConceptCode, screenshots, or video evidence
Impact AssessmentBusiness impact and risk explanation
Remediation SuggestionRecommended fix (if known)

Poor quality, incomplete, or spam reports may be rejected without bounty.


7. KYC and Identity Verification

7.1 Verification Requirements

To receive bounty payments, you must:

RequirementDescription
Identity VerificationSubmit government-issued ID for verification
Age VerificationConfirmation that you are at least 18 years old
Payment Method VerificationValid PayPal, bank account, or crypto wallet
Tax InformationTax forms as required by applicable law

7.2 Privacy Protections

  • Your identity is kept confidential from clients unless you consent
  • Your personal information is processed in accordance with our Privacy Policy
  • Only authorized AXUM SEC staff have access to your verification data
  • You may request deletion of your verification data after account closure

7.3 Consequences of Failed Verification

  • You will not receive bounty payments until verification is complete
  • Your account may be suspended if verification is not completed within 30 days
  • Fraudulent or false identity information will result in permanent ban

8. Intellectual Property

8.1 Your Reports

  • You retain ownership of your vulnerability reports
  • You grant AXUM SEC and the applicable Client a perpetual, irrevocable license to use the report for security purposes
  • You may not submit reports that infringe on third-party intellectual property

8.2 Client Data

  • All client data accessed during testing remains the property of the client
  • You have no ownership rights to any data discovered during testing
  • You must delete all client data after the program concludes or upon request

8.3 Platform IP

  • The AXUM SEC platform, its code, design, and content are the property of AXUM SEC Technology PLC
  • You may not copy, reverse engineer, or attempt to extract platform source code

9. Consequences of Violations

9.1 Violation Tiers

TierViolation TypeConsequences
MinorPoor report quality, minor communication issuesWarning, temporary submission restriction
ModerateTesting out-of-scope, minor confidentiality breachAccount suspension (30 days), forfeiture of related bounty
SevereMalicious testing, data destruction, extortionPermanent ban, forfeiture of all bounties, legal action
CriticalIllegal activity, criminal hacking, data theftImmediate permanent ban, reported to law enforcement, legal prosecution

9.2 Specific Violation Consequences

ViolationConsequence
Testing out-of-scopeWarning, report rejected, -5 Reputation
Submitting false reportsAccount suspended, forfeiture of bounties
Disclosing vulnerabilities publiclyPermanent ban, legal action
Sharing Confidential InformationPermanent ban, legal action
Extortion or threatsImmediate permanent ban, reported to law enforcement
Data destruction or modificationImmediate permanent ban, legal prosecution
ImpersonationImmediate permanent ban
Harassment or abuse30-day suspension (first), permanent ban (repeat)

9.3 Appeals Process

If you believe a violation determination was in error, you may appeal:

StepProcessTimeline
1Submit appeal to security@axumsec.comWithin 14 days of notice
2AXUM SEC Security Team review10 business days
3Final determination communicated5 business days after review

Appeals are reviewed by a different team member than the one who issued the violation.


10. Dual Roles and Conflicts of Interest

10.1 Working for Multiple Clients

  • You may participate in multiple programs simultaneously
  • You may not share information between programs
  • Each program's findings remain confidential to that program

10.2 Employment Conflicts

  • If you work for a company that is a client, disclose this to AXUM SEC
  • You may not test your employer's systems through the platform
  • You may not use platform knowledge to benefit your employer inappropriately

10.3 Researcher-Client Relationships

  • You may not accept direct payment from clients outside the platform
  • You may not enter into private agreements with clients without AXUM SEC consent
  • All bounty payments must go through the AXUM SEC platform

11. Bug Bounty Program-Specific Rules

11.1 VDP (Vulnerability Disclosure Program)

  • No monetary bounties
  • Recognition-only rewards (Hall of Fame, swag)
  • Public disclosure allowed only after client authorization

11.2 Private Program Rules

  • You are bound by additional confidentiality
  • You may not disclose your participation in private programs
  • Program details (client name, scope, rewards) are confidential

11.3 Public Program Rules

  • Open to all verified researchers
  • Standard disclosure timeline applies
  • Hall of Fame recognition for valid reports

11.4 PTaaS Engagement Rules

  • You are assigned specific targets and testing windows
  • You must follow the Statement of Work (SOW)
  • You must submit daily progress reports
  • You may not test outside the specified window

12. Safe Harbor

AXUM SEC provides safe harbor for researchers who:

  • Comply with this Code of Conduct
  • Test only within authorized scope
  • Disclose vulnerabilities responsibly
  • Do not violate applicable laws

12.2 What Safe Harbor Means

  • We will not pursue legal action against you for authorized testing
  • We will advocate for you if clients initiate legal action for compliant testing
  • We will not support legal claims against researchers acting in good faith

12.3 When Safe Harbor Does NOT Apply

Safe Harbor does NOT protect you if you:

  • Test outside authorized scope
  • Disclose vulnerabilities publicly without authorization
  • Cause damage, data loss, or service disruption
  • Engage in extortion or threats
  • Violate any law

13. Reporting Violations

13.1 How to Report

If you witness or suspect a violation of this Code:

MethodContact
Emailsecurity@axumsec.com
PlatformReport user through platform interface
Confidentialethics@axumsec.com (for sensitive reports)

13.2 What to Include in Your Report

  • Your name and contact information (anonymous reports accepted but may limit investigation)
  • Description of the violation
  • Evidence (screenshots, messages, dates, times)
  • Names of individuals involved

13.3 Protection for Reporters

  • We prohibit retaliation against individuals who report violations in good faith
  • Reports are kept confidential to the extent possible
  • Anonymous reporting is accepted

14. Amendments to This Code

  • AXUM SEC Technology PLC may update this Code of Conduct from time to time
  • Material changes will be notified via email to registered researchers
  • Continued use of the platform after changes constitutes acceptance
  • You may terminate your account if you do not agree with changes

15. Contact Information

PurposeContact
Code of Conduct Questionsconduct@axumsec.com
Report Violationssecurity@axumsec.com
Confidential Reportingethics@axumsec.com
General Supportsupport@axumsec.com
Phone+251943733593
AddressAXUM SEC Technology PLC, Addis Ababa, Ethiopia

16. Acknowledgment

By registering for, accessing, or using the AXUM SEC platform, I acknowledge that:

  • I have read, understood, and agree to abide by this Researcher Code of Conduct
  • I understand the consequences of violating this Code
  • I agree to test only within authorized scope
  • I agree to disclose vulnerabilities responsibly
  • I agree to keep all Confidential Information confidential
  • I understand that violation may result in account termination and legal action

Signature (Electronic Acceptance): _____________________

Name: _____________________

Date: _____________________

Version: 1.0 (May 13, 2026)


Issued By:
AXUM SEC Technology PLC
Addis Ababa, Ethiopia
www.axumsec.com

"Ethical hacking is a privilege, not a right. Protect, don't harm. Disclose, don't exploit."

Last Updated
5/13/2026
Version
v1.0
Researcher Code of Conduct | AXUM SEC