Cyberr Community Guidelines
Effective date: April 27, 2026
Welcome
Cyberr is a professional community for people who work in or care about cybersecurity. These Community Guidelines explain how we expect you to behave on the Service, what kind of Content is acceptable, and what is not. They sit alongside our User Agreement, which is the binding contract between you and Cyberr SA (société anonyme). Where the User Agreement uses general language, these Guidelines give practical detail and concrete examples.
Cybersecurity is an unusual field: a lot of what professionals do for a living looks, on the surface, like the very things our Guidelines forbid. We have therefore tried to draw clear lines between legitimate professional discussion — which we welcome — and conduct that endangers other Members, third parties or the Service itself.
If a rule below is unclear in a specific situation, we will look at the spirit of these Guidelines, the User Agreement and applicable law to decide what is acceptable. We will publish further examples and clarifications in our Help Center as new questions arise.
How these Guidelines work
Defined terms used in these Guidelines (such as "Account", "Content", "Member", "SaaS Clients", "Service") have the meanings given in the User Agreement.
These Guidelines are not exhaustive. We may take action against conduct that is harmful to the community even if it is not specifically listed below, where that conduct violates the User Agreement or applicable law.
A breach of these Guidelines is a breach of the User Agreement and may lead to the moderation measures described in Section 8 of the User Agreement, ranging from removal of a single piece of Content to permanent termination of an Account, depending on seriousness, repetition and context.
1. Authentic identity
1.1 Use your real name
Your Account must be in your real name. You may also display a professional handle (such as a long-standing community alias or a research pseudonym) on your profile, but your real name must always be visible to other Members. Anonymous Accounts are not permitted.
1.2 Be the real you
Your profile must describe an actual person - yourself. We do not allow:
- accounts in the name of fictional characters, brands, mascots or pets;
- accounts created on behalf of another person without their authority;
- multiple accounts held by one person;
- accounts that recycle the photo, biography or content of someone else.
A company or other organisation that wishes to be present on Cyberr should use the dedicated organisation features rather than a personal Account.
1.3 Do not impersonate
Do not impersonate a real person, organisation, government body, CERT, CSIRT, security team or news outlet. Parody accounts of public figures or private individuals are not permitted, even if labelled as such.
1.4 Do not inflate your credentials
Be honest about your education, certifications, employment, security clearances and research record. Specifically, do not:
- claim certifications, degrees or clearances you do not hold;
- claim to be a current employee of an organisation that has not employed you;
- claim authorship of research, tools or talks that are not yours;
- claim formal status (founder, officer, advisor, MVP, ambassador) without basis;
- claim involvement in incident response, takedown operations or law-enforcement operations that you were not part of.
Honest summaries, contextualised contributions and team credit are encouraged. Embellishment is not, especially in a security context where credentials are the basis of trust.
1.5 No automation of your presence
Do not use bots, scripts or AI agents to operate your Account on your behalf — including to auto-connect, auto-message, auto-post, auto-comment, auto-like or otherwise simulate engagement. You may use Cyberr's own approved features and interfaces, but you may not drive your Account from outside the Service except as we expressly permit.
2. Respect, safety and dignity
2.1 No harassment or bullying
Do not target other Members or third parties with Content that is intended, or could reasonably be expected, to intimidate, humiliate, silence or distress them. This includes:
- threats of violence, doxxing or "swatting";
- coordinated mass-reporting, dogpiling or pile-on campaigns;
- repeated unwanted contact after the recipient has indicated they want it to stop;
- sexual harassment in any form, including unsolicited sexual messages or images;
- mocking based on appearance, voice, accent, disability or personal circumstance.
Robust professional disagreement is welcome. Personal attacks and hostile campaigns are not.
2.2 No hate speech or discrimination
Do not post Content that attacks people, or promotes hatred against people, on the basis of race, ethnicity, national origin, religion, gender, gender identity, sexual orientation, age, disability or any other protected characteristic.
2.3 Protect minors
The Service is not for children under eighteen. Any Content that sexualises minors, that endangers them, or that targets them with manipulative techniques will result in immediate removal and Account termination, and where appropriate referral to authorities.
2.4 No graphic violence or shock content
Do not post depictions of real-world violence, injury or death for shock value. Documentary or news Content addressing security incidents (for example, reporting on a cyber-physical attack) may be acceptable when posted with editorial care and context.
2.5 No sexual content
Cyberr is a professional community. Pornographic and sexually explicit Content is not allowed, regardless of how it is framed.
2.6 No glorification of violent or terrorist actors
Do not post Content that praises, supports, fundraises for or recruits on behalf of terrorist organisations, violent extremist movements or violent criminal groups. This includes nation-state offensive units operating outside the law of armed conflict where the Content advocates rather than analyses.
Reporting on, analysing or attributing such groups in a research, defensive or journalistic context is welcome, provided it is clearly framed as such and does not function as recruitment material.
2.7 Self-harm and dangerous behaviour
If you or someone you know is in distress, please contact local emergency services or a recognised mental-health helpline. Do not post Content that encourages self-harm, suicide or eating disorders, or that promotes other dangerous activities. We will signpost help where we can.
3. Honest and reliable information
3.1 Do not deceive
Do not knowingly post false or misleading Content, fabricate evidence, doctor screenshots, plant fake artefacts or otherwise try to deceive other Members. This is particularly serious in a cybersecurity context, where false alarms, false attributions and fake "leaks" can cause direct operational harm.
3.2 Cite, attribute, contextualise
When you discuss vulnerabilities, incidents, indicators of compromise (IOCs), threat actors or research findings, link to or otherwise identify the primary source where you can. Distinguish clearly between:
- facts you have personally verified;
- facts reported by a named source;
- analysis or opinion of your own.
Speculative attribution ("this looks like APT-X") should be presented as such.
3.3 Do not manipulate the platform
Do not use coordinated inauthentic behaviour — networks of accounts, sockpuppets, paid engagement, "buy followers" schemes — to amplify your Content, suppress others' Content or distort discussion.
3.4 Synthetic and AI-generated Content
You may use AI tools to help you draft, edit or illustrate Content, but you must:
- review AI output for accuracy before publishing it;
- not pass off AI-generated Content as a personal experience, technical analysis or evidence when it is not;
- clearly label AI-generated images, audio or video that depict real people, real events or real systems in a way a reasonable Member could mistake for an authentic capture;
- never use AI to create deepfake imagery or audio of identifiable real people without their consent.
3.5 Election and civic integrity
Do not post Content that is intended to suppress voting, that misrepresents voting procedures or that fabricates statements by candidates or officials. Cyberr is a professional space, not an electoral platform.
4. Privacy and confidentiality
4.1 Other people's personal data
Do not post the personal data of other people — addresses, phone numbers, identification documents, private email addresses, precise location, financial details, login credentials, medical information — without their clear consent.
4.2 No doxxing
Do not aggregate, publish or share personal information with the apparent purpose of identifying, locating, embarrassing or endangering a person. This applies regardless of whether the underlying information is technically "public".
4.3 Confidentiality from your job
Do not post confidential information belonging to your current or former employer, client or partner — including non-public incident details, internal tooling, customer data, network diagrams, source code or unpublished research — unless you have express authorisation. Generic war-stories, anonymised and consented, are usually fine; specifics that identify the affected organisation or its customers usually are not.
4.4 Images of others
Do not post photographs or videos of identifiable people in private or sensitive contexts (for example, attending a closed event, in their home, or during a security operation) without their consent.
4.5 Recordings of meetings and calls
Do not post recordings or transcripts of private meetings, conference calls, briefings or discussions without the consent of the participants.
5. Intellectual property
5.1 Do not infringe
Do not post Content that infringes another person's copyright, trademark, design rights, patent rights, trade secrets, database rights or moral rights. If you do not have the right to share something, do not share it.
5.2 Open source
When you share or build on open-source code or research, comply with the applicable licence — including attribution, copyleft and notice requirements.
5.3 Reporting infringement
If you believe Content on the Service infringes your intellectual property rights, please use our reporting tools or write to us at support@cyberr.ai with the elements needed to assess your claim.
6. Cybersecurity-specific norms
This section is the operational core of these Guidelines. It complements Section 6.3 of the User Agreement and applies regardless of how you describe your activity (defensive, offensive, research, awareness, journalistic).
6.1 Coordinated vulnerability disclosure
Principle
Vulnerability research is welcome on Cyberr. Disclosing exploitable vulnerabilities in identified third-party products, systems or services in a way that endangers users is not.
You should follow established coordinated vulnerability disclosure ("CVD") practice:
- contact the vendor or maintainer privately, using a security contact, security.txt or recognised reporting channel;
- give them a reasonable opportunity to remediate, typically at least 90 days for software, longer for systems with deployment, supply-chain or hardware constraints;
- coordinate the public disclosure date with the vendor;
- avoid releasing exploitation tooling that confers significant uplift to attackers before remediation is widely deployed.
We recognise that vendors sometimes act in bad faith, that timelines run out, or that exploitation is already in the wild. In those cases, public disclosure may be appropriate; we ask that you explain your reasoning in the post and that you minimise harm in what you publish.
Vulnerabilities in the Service itself are governed by our Coordinated Vulnerability Disclosure Policy (referenced in the User Agreement) — please follow that document, not this section, for issues affecting Cyberr.
Acceptable
- Discussing your research process and findings at a high level.
- Linking to your already-published advisory after a coordinated disclosure date.
- Discussing CVE numbers, severity, affected versions and recommended mitigations.
- Sharing detection rules (Sigma, YARA, Snort, KQL, etc.) for known vulnerabilities and threats.
- Sharing your engagement with a vendor's bug-bounty programme, including your own write-ups, where the programme allows.
Not acceptable
- Posting full proof-of-concept (PoC) exploit code for an unpatched vulnerability, particularly if it is wormable, pre-auth or RCE-class.
- Dropping 0days for clout.
- Disclosing vulnerabilities affecting safety-critical systems (medical, automotive, industrial control, aviation) in a manner that creates a foreseeable risk of physical harm.
- Posting full exploitation chains for vulnerabilities affecting a named, identified victim.
- Threatening to disclose unless paid.
6.2 Malicious code and offensive tooling
Principle
Defenders need to talk about malware, exploitation techniques and offensive tooling. We do not want Cyberr to be a marketplace, distribution channel or recruiting ground for actual attacks.
Acceptable
- Discussing malware behaviour, indicators of compromise and mitigations.
- Sharing IOCs in standard formats (hashes, domains, IPs, YARA rules) with context.
- Sharing detection signatures, forensic artefacts and reverse-engineering write-ups.
- Posting screenshots, decompilation excerpts or partial code samples for educational purposes.
- Linking to a reputable malware repository (such as a recognised academic or vendor source) where the repository itself enforces appropriate access controls.
- Discussing offensive security tools that are already public, well-known and widely used by both red and blue teams, with context about defensive use.
Not acceptable
- Attaching, embedding or linking to live malware samples in a form that is directly executable or trivially weaponisable.
- Distributing stealer logs, infostealer outputs, ransomware builders, phishing kits, credential-stuffing lists, packing/crypting services or "loaders" for sale or for use.
- Sharing access to private command-and-control infrastructure, redirector chains or operational tooling.
- Selling, renting or trading custom malware, 0day exploits, access to compromised systems or persistent footholds.
- Recruiting accomplices, money mules or "specialists" for ongoing offensive operations.
Defanged samples and private research groups
We allow educational discussion of malicious code in clearly defanged form — for example, hashes, redacted code excerpts, neutered URLs (hxxp:// notation, square brackets in domains) — and within private, vetted groups whose stated purpose is research or defence. Even within such groups, do not distribute live, weaponisable artefacts.
6.3 Stolen, leaked and breach data
Principle
Distributing stolen personal data harms real people, regardless of who originally took it and regardless of how interesting the analysis you intend to draw from it.
Acceptable
- Discussing the existence, scope and impact of a breach using publicly reported information.
- Linking to professional aggregation services (such as Have I Been Pwned) that allow individuals to check exposure without redistributing the underlying data.
- Sharing your own research findings about breaches based on data that you do not redistribute.
- Helping affected individuals understand and remediate their exposure.
Not acceptable
- Posting, linking to, or trading combolists, stealer logs, breach dumps, credential dumps or scraped personal-data sets.
- Sharing samples, "tasters" or screenshots that contain real personal data of identifiable individuals.
- Offering "lookup" services on breach data on a per-record basis.
- Reposting leaked corporate documents, source code or internal communications in a way that goes beyond fair, journalistic reporting.
6.4 Targets
Naming a specific person, organisation, system, IP range, application or domain as something you will, might or could attack, scan, exploit or "test" turns Cyberr into an instrument of harm. Do not do it. This includes:
- "I bet I could pwn @bigbankco" posts;
- "free pentest" offers directed at identifiable systems without consent;
- public lists of soft targets, easy victims or "deserve it" candidates;
- calls for crowd-sourced attacks ("let's all scan X this weekend").
When you share legitimate operation results — for example, a public bug-bounty write-up, a CVE you disclosed or a published case study — name the target only as the responsible-disclosure timeline and the target's permissions allow.
6.5 Offensive services and grey-area offerings
Do not advertise, offer, solicit, broker or facilitate any service that involves unauthorised access to systems, networks or data of third parties. This includes:
- hack-for-hire, account recovery / takeover, "ethical" credential extraction;
- spyware and stalkerware aimed at consumers or specific individuals;
- deepfake or synthetic-media services designed to defraud or harass;
- "verification bypass" or "KYC bypass" services;
- bot networks for spam, fraud or amplification;
- harassment-as-a-service, including swarm reporting.
Do not list yourself, your employer or your service in any role, profile section or post that promotes such services.
Legitimate authorised offensive security services — penetration testing, red teaming, adversary emulation, purple teaming, training, advisory — are welcome, provided your offering is clearly tied to authorised engagement on the client's own assets.
6.6 The Service is not your tool
Do not use the Service or any of its features as part of an attack on someone else. Specifically:
- do not use Cyberr profiles, posts, articles or messages to host or link to phishing pages, drive-by-download lures, credential harvesters or malware;
- do not use Cyberr messaging for social-engineering pretexting, even if framed as an "awareness exercise";
- do not use Cyberr search to build target lists for attacks elsewhere;
- do not use Cyberr APIs (where available) outside their documented purpose.
6.7 Red-team, pentest and incident war-stories
War-stories are a natural part of this community, and they are welcome. To share them safely:
- get the client's or employer's permission, and stay within whatever they have allowed;
- anonymise client identity, sector and other identifiers where they are not part of an authorised public case study;
- redact specifics that could enable a copycat (precise payloads against still-deployed configurations, specific internal IPs, customer names);
- focus on lessons learned and defender-useful information rather than on glamorising the breach.
Photos of real client facilities, badges, screens or operations centres should not be posted without express consent.
6.8 Incident attribution
Be careful with attribution. Attaching the wrong threat actor to an incident can cause regulatory, diplomatic and commercial harm. When you attribute, distinguish clearly between confirmed attribution by named authorities, vendor-stated attribution and your own analytic judgement, and provide your reasoning where you can.
6.9 Government, military and law-enforcement contexts
Cyberr is open to professionals working in government, military and law enforcement. Posting in those capacities does not give you a special exemption from these Guidelines. In particular:
- offensive cyber operations of states are a sensitive topic; analysis is welcome, recruitment, planning or operational coordination is not;
- you must not disclose classified or restricted information in any jurisdiction;
- you must not use Cyberr to identify, surveil or pursue individuals outside lawful and authorised processes.
7. Recruitment, business and commercial conduct
7.1 Genuine job and contract opportunities
Job postings, contract offers and project listings on the Service must be for real opportunities. Specifically:
- the role must actually exist and be open at the time of posting;
- the description, location and compensation expectations must be honest;
- you must have authority from the employer or client to post.
Do not use postings as a pretext to harvest CVs, build databases, generate "leads" for unrelated services or run scams.
7.2 Fair and lawful selection
Do not state or imply hiring criteria that are unlawful in the relevant jurisdiction — for example, on the basis of age, gender, ethnicity, religion or disability. Cybersecurity has a hiring problem; help us improve it rather than entrench it.
7.3 Professional sourcing
If you are a professional recruiter or sourcer, you must use Cyberr's dedicated SaaS Clients products to identify and engage candidates. Using a personal Account to source for clients in volume — including bulk connection requests, scripted outreach or pipeline-building — is not permitted.
7.4 Self-promotion and product talk
Self-promotion is fine in moderation. To stay welcome:
- frame your product or service posts so they offer value to the community beyond the sales pitch;
- disclose commercial relationships when you discuss tools, vendors or competitors (see Section 7.5);
- do not carpet-bomb Members with cold sales messages;
- do not present a paid placement as an organic recommendation.
7.5 Disclosing commercial relationships
If you are paid, sponsored or otherwise compensated to mention a product, vendor or service, say so clearly in the post. Affiliate links, sponsored research summaries and brand-funded "thought leadership" must be disclosed.
7.6 Bug bounty and brokered offers
Independent bug-bounty programme participation is welcome. Brokered offers — selling vulnerabilities, exploits, accesses or zero-days through Cyberr — are not.
7.7 Fundraising, donations and crypto
Do not solicit donations on the Service except for the verifiable benefit of recognised charitable, educational or relief efforts. Cryptocurrency promotions, "airdrops", token launches and similar offerings are not appropriate Cyberr Content; technical discussion of blockchain security research is.
8. Spam, scale and engagement
8.1 What counts as spam
The following all count as spam, regardless of how nicely they are written:
- repeatedly posting the same or similar Content;
- bulk private messages with similar wording;
- mass-tagging of Members who do not know you;
- repeated comments unrelated to the post they sit under;
- engagement-bait ("comment YES if you agree", "the algorithm hates this");
- pyramid-scheme, "passive income" and get-rich-quick offers;
- "training programme" offers that promise jobs in cybersecurity in exchange for fees, without delivering substance.
8.2 Do not simulate engagement
Do not buy, sell, exchange, automate or coordinate likes, comments, follows, re-shares or message-equivalent interactions. Engagement on Cyberr should reflect what actual humans actually thought about your Content.
9. Reporting and enforcement
9.1 Tell us when something is wrong
If you see Content or behaviour that you believe breaches these Guidelines, the User Agreement or applicable law, please report it through the in-Service tools or by writing to support@cyberr.ai. We act on signals from the community, on our own monitoring and on notices from authorities.
9.2 What happens when you report
We will review reports in a timely, diligent and non-arbitrary manner. Depending on what we find, we may:
- take no action where the Content is within the rules;
- remove or restrict the Content;
- contact the Member who posted it and ask them to amend or remove it;
- restrict specific features for that Member;
- suspend or terminate the Account.
We will let you know the outcome in line with applicable law.
9.3 Misuse of reporting
Do not flood reports, file knowingly false reports or use reporting to harass other Members. We may suspend reporting privileges where someone repeatedly submits manifestly unfounded reports.
9.4 Appeals
If you believe we acted incorrectly against your Content or your Account, you can appeal in accordance with Section 8.4 of the User Agreement, and you may, where applicable, use the out-of-court dispute settlement options described in Section 8.5 of the User Agreement.
9.5 Range of measures
We aim to use the lightest measure that is effective. Repeated, deliberate or serious violations — and any conduct described in Section 6 of these Guidelines that goes to the heart of why this community can or cannot exist — will lead to permanent Account termination.
10. Updates
We will update these Guidelines as the community grows, as the threat landscape evolves and as we learn from your feedback. Material changes will be announced through the Service, and we will give you a reasonable opportunity to review them before they take effect, in line with Section 13 of the User Agreement.