OUR ETHICAL LINE.
ERRORHACKER is a cyber-defense education studio. We teach, defend, and coach — we never attack, take unauthorized actions, or run grey-market ops. This page states exactly what we do and refuse to do, in plain English.
Legitimate, defensive, educational.
Books, playbooks, and structured courses covering OSINT, defensive security, personal privacy, and ethical bug-bounty hunting.
Advisory sessions for victims of scams, hacks, or doxing. We coach you through the platform's official recovery process and post-incident hardening. We never access your accounts.
Free WHOIS, IP intel, CVE search, subdomain enumeration and username OSINT — the same public-data lookups any security researcher uses to learn.
Structured mentorship for aspiring bug-bounty hunters on HackerOne, Bugcrowd, and Intigriti. Curated writeups, methodology, disclosure discipline.
Private community access, live AMAs with senior operators, and monthly deep-dive walkthroughs of publicly-disclosed CVEs and case studies.
B2B penetration testing and configuration reviews — only under a signed engagement scope from the asset owner. No exceptions, no verbal agreements.
The clear no-line.
- Unauthorized account recovery — we do NOT log in to, take over, or manipulate accounts on your behalf. We only coach you through the platform's official channels.
- Fake social-media engagement — no fake followers, likes, views, comments, or bot networks. We do not sell traffic that violates platform Terms of Service.
- Unauthorized access to third-party systems — pentesting requires a signed scope. No agreement, no engagement. Ever.
- Doxing, stalkerware, revenge campaigns, or personal-vendetta ops of any kind.
- SIM-swap, synthetic-identity, credential-stuffing, or financial-fraud services.
- Selling exploits, zero-days, or offensive tooling to unvetted buyers.
- Working with clients whose stated goals violate applicable law in their jurisdiction or in ours.
How we enforce this
- ✓ Every consultation intake includes a signed statement of consent + scope.
- ✓ All B2B pentests require a written Statement of Work signed by an authorized signatory of the asset owner.
- ✓ Chat channels are monitored by senior operators — misuse is refunded and reported.
- ✓ All payments are processed through vetted, licensed providers. No cash-in-hand ops.
- ✓ We publish an updated version of this charter every quarter.
Spotted a service or piece of content on ERRORHACKER that seems to cross this line? Email root@errorhacker.site — every report is reviewed within 24 hours and, if valid, the offending page is taken down while we investigate.
Want to work with us?
Start with the free recon tools or browse our education library. If you need advisory work, request a consultation.
