genai
SECURITY LAB
Legal

Acceptable Use Policy

Last updated August 17, 2026

GenAI Security Lab teaches offensive and defensive AI-security techniques in a controlled, authorized environment. This policy sets the boundaries of that authorization. It is the most important rule we have.

The core rule

Attack only the targets we provide, only inside the Service. The lab targets are the authorized scope of your testing. You have no authorization — from us or anyone else — to use these techniques against any other system.

You agree not to

  • Use anything learned here to access, test, or attack systems you do not own or have explicit written permission to test.
  • Attempt to break out of the lab sandbox, attack our own infrastructure, or reach other users’ sessions or data.
  • Share, sell, or publish lab solutions, exam content, or certificate-exam answers.
  • Automate abusive load against the labs (denial-of-wallet, scraping) or interfere with other learners.
  • Misrepresent a credential you have not earned, or take an assessment on someone else’s behalf.
  • Share your account with anyone else — an individual subscription is licensed to a single named person, not a shared login. (Team and Enterprise seats may be reassigned between members by the account administrator.)

Responsible disclosure

If you find a real vulnerability in GenAI Security Lab itself — not in the intentionally vulnerable targets — please report it to [email protected] rather than exploiting it. See our Security Policy.

Enforcement

Violations may result in suspension or termination without refund, revocation of certifications, and, where laws are broken, referral to the appropriate authorities.