Back to the blog
Rules & Guidelines
August 21, 2026 · 3 min read Community

Rules & Guidelines

The ground rules that keep this a place everyone can take part in

For this to stay a place everyone can be part of, we need to be clear about what is expected and what is not. These apply everywhere LEAK has a presence: this blog, the platform, and our community channels. They also apply when something you do elsewhere spills over into this community.

How we treat each other

The part that matters most, and the part we enforce hardest

  • Treat people with respect. Disagree with ideas all you like. Do not make it personal.
  • Assume good faith. Most friction is a misunderstanding, not an attack.
  • Do not gatekeep. Nobody was born knowing this. Just Google it is not an answer, and making someone feel stupid for asking is worse than saying nothing at all.
  • Keep it constructive. Give context, be specific, and help people out when you can.
  • Respect privacy. Do not share anyone's personal information without their consent.
  • Ask before you DM. Keep questions in public where everyone can learn from the answer, and get someone's agreement before messaging them directly.
  • Respect your boundaries. Do not share anything you are not comfortable with, and if someone keeps trying to push past them, tell us.
  • Keep it safe for work. Assume someone is reading over a colleague's shoulder.

Using LEAK safely and legally

We build offensive tooling, so this part is not negotiable

  • Only test what you are allowed to test. Systems you own, or systems whose owner has given you permission in writing. Nothing else.
  • Our infrastructure is not a target. Neither are other members, their machines, or their accounts.
  • No denial of service. Not against us, not against anyone else.
  • If you stumble into real data, stop. Do not pivot, do not download it, and do not look any further than you need to in order to understand what you found. Then tell us.
  • Report security issues to us privately first, at support@leak.software. Give us a reasonable window to fix the problem, and we will agree with you when it can be made public.
  • Do not publish anything that only works as an attack on people who never agreed to be targets.

What is not acceptable

  • Harassment, hate speech, discrimination, or personal attacks of any kind.
  • Publishing private or identifying information about other people.
  • Sharing malware, stealers, phishing kits, or credentials and data taken from someone else.
  • Spam, unsolicited promotion, or mass messaging. Ask us first if you want to share your own project.
  • Illegal activity, or encouraging anyone else into it. That includes asking the community to help you attack something you have no permission to touch.
  • Impersonating LEAK staff or other members of the community.
  • Coming back with a second account after a ban, or using alternate accounts to get around a moderation decision.
  • Derailing discussions on purpose.

How we handle it

We would much rather talk than remove anyone, and most of the time a quiet word is enough. When it is not, the response fits what happened.

  1. A word in private. We explain what crossed the line and why. Most things stop here.
  2. A formal warning. On the record, saying plainly what needs to change.
  3. A temporary suspension. Time away from the community. Coming back early on another account turns this into a permanent removal.
  4. Permanent removal. For serious cases, or when nothing above has worked.

Serious breaches skip the ladder. Harassment, doxxing, and anything that puts people at risk do not get a warning first.

If you see something that crosses a line, email support@leak.software. Reports are handled privately and we will not tell anyone who raised them. If you think a decision about you was wrong, write to the same address and tell us why, and we will look at it again.

These rules will change as the community does. If something here does not sit right with you, tell us. That is exactly what this channel is for.