Skip to main content
BuruOps Acceptable Use and Cyber Security Shield
STATUTORY DEFENSE • COMPUTER MISUSE ACT 1990

Acceptable Use Policy (AUP)

This Acceptable Use Policy defines the lawful parameters, operational boundaries, and security rules governing access to BuruOps Intelligence Lab websites, public code artifacts, demonstration sandboxes, and advisory telemetry endpoints.

Prohibited Activities Report Security Issue Compliance Portal

1. Application & Scope

This policy applies to any individual or automated system interacting with buruops.com, its subdomains, public git repositories, API documentation, or interactive terminal components. Unauthorized attempts to bypass access controls or probe external infrastructure through our systems constitute a breach of this policy and may trigger criminal proceedings under the Computer Misuse Act 1990.

2. Strictly Prohibited Exploitative Activities

You must not engage in, facilitate, or promote any of the following activities on or through BuruOps infrastructure:

Unauthorized Vulnerability Exploitation & Scanning

Automated volumetric port scanning, web application fuzzing, SQL injection payload execution, or directory brute-forcing against BuruOps web servers without prior written authorization from our Principal Engineer.

Denial of Service (DoS & DDoS)

Any deliberate action intended to degrade, disrupt, saturate, or crash BuruOps network endpoints, server memory, CPU capacity, or downstream APIs.

Malicious Content & Credential Harvesting

Transmitting malware, trojans, ransomware, or attempting cross-site scripting (XSS) or CSRF attacks through technical inquiry forms, contact fields, or email channels.

Automated Scraping & AI Training Mining

Systematic bulk scraping, headless browser parsing, or extraction of BuruOps technical audit frameworks, proprietary threat telemetry, or research publications for unauthorized commercial re-use or foundation model pre-training.

3. Legitimate Defensive Research Safe Harbor

We recognize that security researchers may discover unintentional bugs or misconfigurations during routine exploration. Researchers acting in good faith, conforming to our Vulnerability Disclosure Policy and ISO/IEC 29147, are shielded by our Safe Harbor commitment and will not face legal action under the Computer Misuse Act 1990.

4. Technical Enforcement & Incident Escalation

BuruOps maintains active intrusion detection and automated layer-7 rate-limiting systems. In the event of a detected violation:

  • Offending IP addresses, ASN ranges, and user agents will be permanently blacklisted across our edge firewalls.
  • Detailed forensic telemetry and PCAP logs will be compiled.
  • Serious malicious incursions will be immediately escalated to the National Cyber Security Centre (NCSC) and the National Crime Agency (NCA) National Cyber Crime Unit under Sections 1, 2, and 3 of the Computer Misuse Act 1990.

5. Inquiries & Authorizations

For technical inquiries, bug reporting, or to request authorized testing scopes, contact our Principal Infrastructure Engineer at principal@buruops.com.