Researcher Code of Conduct
The Researcher Code of Conduct establishes the rules, ethical guidelines, and behavioral expectations for all security researchers (Hunters) registered on the AXUM SEC Technology PLC platform. This code covers authorized testing boundaries, responsible disclosure, confidentiality, communication standards, and consequences for violations. All researchers must read, understand, and agree to this code before participating in any bug bounty or security testing program.
Researcher Code of Conduct
Effective Date: May 13, 2026 Version: 1.0 Issued By: AXUM SEC Technology PLC Applicable to: All registered Security Researchers (Hunters)
1. Introduction
AXUM SEC Technology PLC ("AXUM SEC", "Company", "we", "us", "our") is committed to fostering a trusted, ethical, and professional community of security researchers. This Code of Conduct ("Code") establishes the standards of behavior expected from every researcher ("Hunter", "you", "your") registered on the AXUM SEC platform.
By registering for, accessing, or using the AXUM SEC platform, you agree to abide by this Code of Conduct. Violation of this Code may result in suspension or termination of your account, forfeiture of bounties, and reporting to law enforcement authorities.
Our Core Values:
- Ethical First – Always act with integrity and within the law
- Protect, Don't Harm – Your goal is to secure, not destroy
- Respect Confidentiality – What you find stays between us and the client
- Disclose Responsibly – Give companies time to fix before public disclosure
- Continuous Learning – Grow your skills while helping others
2. Scope of This Code
This Code applies to all activities conducted on or through the AXUM SEC platform, including:
- All bug bounty programs (Public, Private, Hybrid, VDP)
- All PTaaS (Penetration Testing as a Service) engagements
- Communication with clients, other researchers, and AXUM SEC staff
- Use of platform features, chat, and collaboration tools
- Disclosure of vulnerability information
3. Authorized Testing Rules
3.1 Scope Compliance
You MUST:
| Rule | Description |
|---|---|
| Test Only In-Scope Assets | Only test systems explicitly listed as "in-scope" for each program |
| Respect Out-of-Scope Notices | Do not test systems marked "out-of-scope" |
| Follow Program-Specific Rules | Each program may have additional rules; you must read and follow them |
| Stop When Asked | If a client asks you to stop testing, you must comply immediately |
3.2 Prohibited Testing Activities
You MUST NOT:
| Prohibited Activity | Explanation |
|---|---|
| Denial of Service (DoS/DDoS) | Any action that disrupts service availability |
| Physical Testing | No physical intrusion, social engineering, or phishing |
| Brute Force Attacks | No automated login attempts unless explicitly permitted |
| Data Destruction or Modification | No altering, deleting, or corrupting data |
| Installing Malware or Backdoors | No persistent access, implants, or backdoors |
| Accessing Other Users' Data | No accessing data belonging to other customers or researchers |
| Using Automated Scanners Without Permission | Only use automated tools if explicitly allowed by the program |
| Testing Third-Party Services | Do not test vendors, partners, or third-party systems unless explicitly in-scope |
3.3 Permitted Testing Methods
You MAY:
| Permitted Activity | Conditions |
|---|---|
| Manual Testing | Always permitted within scope |
| Automated Scanning | Only if allowed by program rules |
| Proof of Concept Development | Must not cause harm or data loss |
| Screenshot Capture | Permitted for evidence, do not share publicly |
| Video Recording | Permitted for evidence, do not share publicly |
4. Responsible Disclosure
4.1 Disclosure Rules
| Rule | Requirement |
|---|---|
| Report Through Platform Only | Submit all vulnerabilities through the AXUM SEC platform, not directly to clients |
| No Public Disclosure | Do not disclose vulnerability details publicly without client permission |
| No Tipping | Do not share findings on social media, forums, or with third parties |
| Respect Embargo Periods | Clients need time to fix; wait for disclosure authorization |
4.2 Disclosure Timeline
| Severity | Recommended Fix Time | Disclosure Authorization |
|---|---|---|
| Critical | 7 days | After fix is confirmed |
| High | 14 days | After fix is confirmed |
| Medium | 30 days | After fix is confirmed |
| Low | 45 days | After fix is confirmed |
| Informational | 60 days | After fix is confirmed or client approval |
Early disclosure without permission is a violation of this Code.
4.3 Hall of Fame and Credit
- Clients may credit you in their Hall of Fame
- You may list findings in your professional portfolio AFTER disclosure authorization
- You may not claim credit for vulnerabilities you did not discover
5. Confidentiality
5.1 What is Confidential
Confidential Information includes:
| Category | Examples |
|---|---|
| Vulnerability Details | Technical descriptions, proof of concept, exploitation methods |
| Client Information | Client names (for private programs), system architecture, internal data |
| Program Details | Reward ranges, scope details, invite-only program information |
| Reports and Comments | Your reports and all communication with clients and AXUM SEC staff |
| Platform Security | Any security issues found on the AXUM SEC platform itself |
5.2 Confidentiality Obligations
You agree to:
- Keep all Confidential Information strictly confidential
- Not share Confidential Information with any third party
- Not use Confidential Information for any purpose outside the program
- Not post screenshots, code, or findings on social media
- Not discuss vulnerabilities in public forums or chat groups
- Securely store any evidence and delete it when no longer needed
5.3 Duration
Confidentiality obligations:
- Begin when you access any Confidential Information
- Continue for 5 years after your account termination
- Continue indefinitely for trade secrets and platform security vulnerabilities
6. Communication Standards
6.1 Professional Conduct
You must communicate:
| Expectation | Description |
|---|---|
| Respectfully | Treat clients, AXUM SEC staff, and other researchers with respect |
| Professionally | Use professional language; no profanity, harassment, or abuse |
| Clearly | Write clear, detailed, and actionable reports |
| Honestly | Do not exaggerate severity or falsify evidence |
| Patiently | Clients may need time to triage and respond |
6.2 Prohibited Communication
You MUST NOT:
- Harass, threaten, or intimidate any person
- Use discriminatory or offensive language
- Spam or flood channels with irrelevant messages
- Impersonate AXUM SEC staff or client employees
- Attempt to manipulate bounty decisions through pressure or threats
6.3 Report Quality Standards
High-quality reports include:
| Component | Requirement |
|---|---|
| Title | Clear, descriptive, and accurate |
| Description | Detailed explanation of the vulnerability |
| Steps to Reproduce | Numbered, clear, reproducible steps |
| Proof of Concept | Code, screenshots, or video evidence |
| Impact Assessment | Business impact and risk explanation |
| Remediation Suggestion | Recommended fix (if known) |
Poor quality, incomplete, or spam reports may be rejected without bounty.
7. KYC and Identity Verification
7.1 Verification Requirements
To receive bounty payments, you must:
| Requirement | Description |
|---|---|
| Identity Verification | Submit government-issued ID for verification |
| Age Verification | Confirmation that you are at least 18 years old |
| Payment Method Verification | Valid PayPal, bank account, or crypto wallet |
| Tax Information | Tax forms as required by applicable law |
7.2 Privacy Protections
- Your identity is kept confidential from clients unless you consent
- Your personal information is processed in accordance with our Privacy Policy
- Only authorized AXUM SEC staff have access to your verification data
- You may request deletion of your verification data after account closure
7.3 Consequences of Failed Verification
- You will not receive bounty payments until verification is complete
- Your account may be suspended if verification is not completed within 30 days
- Fraudulent or false identity information will result in permanent ban
8. Intellectual Property
8.1 Your Reports
- You retain ownership of your vulnerability reports
- You grant AXUM SEC and the applicable Client a perpetual, irrevocable license to use the report for security purposes
- You may not submit reports that infringe on third-party intellectual property
8.2 Client Data
- All client data accessed during testing remains the property of the client
- You have no ownership rights to any data discovered during testing
- You must delete all client data after the program concludes or upon request
8.3 Platform IP
- The AXUM SEC platform, its code, design, and content are the property of AXUM SEC Technology PLC
- You may not copy, reverse engineer, or attempt to extract platform source code
9. Consequences of Violations
9.1 Violation Tiers
| Tier | Violation Type | Consequences |
|---|---|---|
| Minor | Poor report quality, minor communication issues | Warning, temporary submission restriction |
| Moderate | Testing out-of-scope, minor confidentiality breach | Account suspension (30 days), forfeiture of related bounty |
| Severe | Malicious testing, data destruction, extortion | Permanent ban, forfeiture of all bounties, legal action |
| Critical | Illegal activity, criminal hacking, data theft | Immediate permanent ban, reported to law enforcement, legal prosecution |
9.2 Specific Violation Consequences
| Violation | Consequence |
|---|---|
| Testing out-of-scope | Warning, report rejected, -5 Reputation |
| Submitting false reports | Account suspended, forfeiture of bounties |
| Disclosing vulnerabilities publicly | Permanent ban, legal action |
| Sharing Confidential Information | Permanent ban, legal action |
| Extortion or threats | Immediate permanent ban, reported to law enforcement |
| Data destruction or modification | Immediate permanent ban, legal prosecution |
| Impersonation | Immediate permanent ban |
| Harassment or abuse | 30-day suspension (first), permanent ban (repeat) |
9.3 Appeals Process
If you believe a violation determination was in error, you may appeal:
| Step | Process | Timeline |
|---|---|---|
| 1 | Submit appeal to security@axumsec.com | Within 14 days of notice |
| 2 | AXUM SEC Security Team review | 10 business days |
| 3 | Final determination communicated | 5 business days after review |
Appeals are reviewed by a different team member than the one who issued the violation.
10. Dual Roles and Conflicts of Interest
10.1 Working for Multiple Clients
- You may participate in multiple programs simultaneously
- You may not share information between programs
- Each program's findings remain confidential to that program
10.2 Employment Conflicts
- If you work for a company that is a client, disclose this to AXUM SEC
- You may not test your employer's systems through the platform
- You may not use platform knowledge to benefit your employer inappropriately
10.3 Researcher-Client Relationships
- You may not accept direct payment from clients outside the platform
- You may not enter into private agreements with clients without AXUM SEC consent
- All bounty payments must go through the AXUM SEC platform
11. Bug Bounty Program-Specific Rules
11.1 VDP (Vulnerability Disclosure Program)
- No monetary bounties
- Recognition-only rewards (Hall of Fame, swag)
- Public disclosure allowed only after client authorization
11.2 Private Program Rules
- You are bound by additional confidentiality
- You may not disclose your participation in private programs
- Program details (client name, scope, rewards) are confidential
11.3 Public Program Rules
- Open to all verified researchers
- Standard disclosure timeline applies
- Hall of Fame recognition for valid reports
11.4 PTaaS Engagement Rules
- You are assigned specific targets and testing windows
- You must follow the Statement of Work (SOW)
- You must submit daily progress reports
- You may not test outside the specified window
12. Safe Harbor
12.1 Legal Protection
AXUM SEC provides safe harbor for researchers who:
- Comply with this Code of Conduct
- Test only within authorized scope
- Disclose vulnerabilities responsibly
- Do not violate applicable laws
12.2 What Safe Harbor Means
- We will not pursue legal action against you for authorized testing
- We will advocate for you if clients initiate legal action for compliant testing
- We will not support legal claims against researchers acting in good faith
12.3 When Safe Harbor Does NOT Apply
Safe Harbor does NOT protect you if you:
- Test outside authorized scope
- Disclose vulnerabilities publicly without authorization
- Cause damage, data loss, or service disruption
- Engage in extortion or threats
- Violate any law
13. Reporting Violations
13.1 How to Report
If you witness or suspect a violation of this Code:
| Method | Contact |
|---|---|
| security@axumsec.com | |
| Platform | Report user through platform interface |
| Confidential | ethics@axumsec.com (for sensitive reports) |
13.2 What to Include in Your Report
- Your name and contact information (anonymous reports accepted but may limit investigation)
- Description of the violation
- Evidence (screenshots, messages, dates, times)
- Names of individuals involved
13.3 Protection for Reporters
- We prohibit retaliation against individuals who report violations in good faith
- Reports are kept confidential to the extent possible
- Anonymous reporting is accepted
14. Amendments to This Code
- AXUM SEC Technology PLC may update this Code of Conduct from time to time
- Material changes will be notified via email to registered researchers
- Continued use of the platform after changes constitutes acceptance
- You may terminate your account if you do not agree with changes
15. Contact Information
| Purpose | Contact |
|---|---|
| Code of Conduct Questions | conduct@axumsec.com |
| Report Violations | security@axumsec.com |
| Confidential Reporting | ethics@axumsec.com |
| General Support | support@axumsec.com |
| Phone | +251943733593 |
| Address | AXUM SEC Technology PLC, Addis Ababa, Ethiopia |
16. Acknowledgment
By registering for, accessing, or using the AXUM SEC platform, I acknowledge that:
- I have read, understood, and agree to abide by this Researcher Code of Conduct
- I understand the consequences of violating this Code
- I agree to test only within authorized scope
- I agree to disclose vulnerabilities responsibly
- I agree to keep all Confidential Information confidential
- I understand that violation may result in account termination and legal action
Signature (Electronic Acceptance): _____________________
Name: _____________________
Date: _____________________
Version: 1.0 (May 13, 2026)
Issued By:
AXUM SEC Technology PLC
Addis Ababa, Ethiopia
www.axumsec.com
"Ethical hacking is a privilege, not a right. Protect, don't harm. Disclose, don't exploit."