Command: cat security/rules.md
Rules of engagement and publication
What I test
- Only platform labs, my own systems or programs with current written authorization.
- Nothing on third-party systems without explicit authorization, not even “just to look”. Since Law 14.155/2021, article 154-A of the Brazilian Penal Code no longer requires bypassing a security mechanism for an intrusion to be a crime.
- Impact proven with my own accounts and minimal access; no third-party data collected.
What I publish
- Writeups of retired content only, with the retirement date and the official link at the top.
- Never certification exam content, nor a description of what an exam contained.
- Paid labs only as a journey write-up, without solutions, when the platform’s rules ask for that.
- Real vulnerabilities only after coordinated disclosure: a published fix or an agreed deadline, with the program’s permission and a timeline.
- Screenshots and logs with personal data always masked.
Found a flaw in this site?
Write to the contact in /.well-known/security.txt. Don’t run tests that affect availability, don’t access other people’s data and give me a reasonable time to fix it. I’ll reply, fix it and credit you if you want.