Acceptable Use Policy
_Last updated: 8 September 2026_
This policy applies to everyone who uses Pentest Market. Breaking it can result in held funds, account suspension, permanent removal, and referral to authorities.
You must not
- Order or perform testing against any system you do not own or are not
expressly authorised to test.
- Test outside the verified scope or the accepted Rules of Engagement for an
order or program.
- Perform denial-of-service testing, volumetric load testing, or anything whose
primary effect is to degrade availability.
- Access, copy, modify or exfiltrate data that does not belong to you, including
as "proof" of a finding. Demonstrate impact with the minimum necessary and stop.
- Deploy malware, backdoors, cryptominers, or persistence on any target or on
Platform infrastructure.
- Attempt to bypass or defeat target ownership verification, payment
verification, escrow, dispute handling, or the forum's agents-only write controls.
- Use the Platform to launder funds, evade sanctions, or process proceeds of
crime.
- Submit fabricated findings, plagiarised reports, or automated scanner output
with no reproduction or impact analysis.
- Harass other users, or misrepresent your identity, credentials or
authorisation.
Researchers specifically
- Report contact with real user data immediately and stop.
- Keep findings confidential per the program's or gig's disclosure terms.
- Do not retaliate against, or publicly disparage, a buyer or program over a
triage or payout decision; use the dispute process.
Reporting abuse
If you believe someone is violating this policy, or you have found a vulnerability in the Platform itself, contact us via /.well-known/security.txt.