Purpose
This policy establishes the conditions under which LawKade Security services, the ARGUS platform, and lawkadesecurity.com may be used. LawKade operates an authorization-first security platform. Any misuse of our services, infrastructure, or capabilities is taken seriously and may result in immediate termination of access and referral to law enforcement.
Authorization requirement
LawKade will only perform active security testing against targets for which documented, signed authorization from the asset owner exists.
No exception exists to this requirement. If you are seeking assistance with security testing against systems you do not own or do not hold explicit written authorization to test, LawKade will not provide that assistance.
Prohibited activities
The following activities are explicitly prohibited when using LawKade services, the ARGUS platform, or any capability we provide:
Unauthorized scanning or testing
Any attempt to perform network scanning, vulnerability assessment, exploitation, or reconnaissance against systems, networks, or services without documented authorization from the asset owner.
Credential theft
Using our services to obtain, harvest, or facilitate the theft of authentication credentials, session tokens, API keys, or other access material belonging to others.
Phishing and social engineering attacks
Creating or deploying phishing pages, pretextual communications, or social engineering attacks against individuals or organizations through or using our platform or infrastructure.
Malware creation or delivery
Using our services to create, host, deliver, or detonate malicious software including ransomware, spyware, trojans, or any software designed to cause harm without authorization.
Harassment and stalking
Using OSINT or investigation capabilities to stalk, harass, intimidate, or cause harm to individuals.
Illegal surveillance
Collecting intelligence on individuals or organizations in a manner that violates applicable privacy law, wiretapping law, or surveillance regulation.
Destructive testing
Performing denial-of-service attacks, data destruction, or any testing that causes operational disruption to systems, networks, or services.
Data theft
Exfiltrating, copying, or retaining data from systems you are not authorized to access, or using our platform to facilitate unauthorized data access.
Scope violation
Performing assessment activity against targets not included in the authorized scope of an engagement, or targeting systems explicitly excluded from scope.
Impersonation
Misrepresenting your identity, organizational affiliation, or authorization status when engaging LawKade or using the ARGUS platform.
Enforcement
Violations of this policy may result in immediate suspension or termination of platform access, termination of any active engagement, reporting to relevant law enforcement authorities, and civil or criminal liability.
LawKade reserves the right to monitor platform activity for policy compliance and to preserve and share evidence of policy violations with law enforcement.
Reporting violations
If you become aware of a use of LawKade services or the ARGUS platform that violates this policy, contact us through our contact form. For security vulnerabilities in our own systems, use our Responsible Disclosure Policy.