Acceptable Use Policy (AUP)
Mandatory standards, ethical hacking parameters, and laboratory containment protocols governing all interactions with the TelcoSec platform and published research.
// 0x01 PURPOSE & GUIDING PRINCIPLES
TelcoSec operates to empower telecom operators (MNOs/MVNOs), network equipment providers (NEPs), critical infrastructure defenders, and academic researchers with the knowledge and tools required to build resilient mobile communications networks.
Because telecommunications protocols underpin societal communications and emergency coordination, all users accessing our platform must maintain the highest ethical standards and strictly abide by this Acceptable Use Policy.
// 0x02 DEFENSIVE SECURITY & RESPONSIBLE DISCLOSURE
All vulnerability research conducted through or published on TelcoSec adheres to the principles of Coordinated Vulnerability Disclosure (CVD) in alignment with GSMA CVD guidelines and ISO/IEC 29147.
Researchers discovering potential security weaknesses in standard 3GPP specifications, vendor basebands, or operator signaling gateways must report findings directly to the affected vendor or through our research desk at research@telco-sec.com before any public dissemination.
// 0x03 STRICTLY PROHIBITED ACTIVITIES
The following activities represent grave violations of this policy and are strictly prohibited under all circumstances:
- Production Signaling Injection: Injecting MAP, CAP, Diameter (S6a/Cx/Rx), or HTTP/2 SBA messages into public or commercial telecommunications signaling hubs (IPX/GRX) without the express written authorization of the interconnected mobile network operators.
- Emergency Services Disruption: Interdicting, jamming, redirecting, or impairing emergency services infrastructure (e.g., E911, 112, 999, public safety LTE/5G bands, or civil defense alert networks).
- Public Airspace Rogue Base Stations: Operating unauthorized International Mobile Subscriber Identity (IMSI) catchers, false base stations (FBS), or rogue gNodeB/eNodeB transmitters over public licensed RF spectrum without an active regulatory experimental license and explicit test consent.
- Subscriber Geolocation Tracking & Interception: Using signaling research methods (e.g., SS7 SRI-SM / SendRoutingInfo, Diameter Location-Info-Request) to conduct unauthorized location tracking, call tapping, or SMS interception against non-consenting individuals.
- SIM Swap & Identity Fraud: Utilizing technical research for fraudulent SIM swapping, subscriber fraud, over-the-air (OTA) SIM manipulation, or telecom billing evasion.
- Weaponized Malware Distribution: Repackaging TelcoSec proof-of-concept code into weaponized exploits, botnet loaders, or malicious baseband rootkits.
// 0x04 RADIO FREQUENCY & SIGNALING LAB PROTOCOLS
When executing wireless security tests, Software Defined Radio (SDR) experiments, or core signaling simulations, researchers must comply with strict containment protocols:
All active over-the-air radio frequency tests must be conducted within RF-shielded enclosures, Faraday cages, or directly wired RF connections with appropriate 30dB+ hardware attenuators.
Private cellular cores must strictly utilize designated 3GPP test network codes (e.g., MCC 001, MNC 01 or private PLMN 999-xx) to prevent commercial mobile devices from accidentally roaming onto experimental cells.
// 0x05 PLATFORM & API INTEGRITY
Users interacting with the TelcoSec platform, web applications, and backend APIs must respect system integrity:
- Do not bypass rate limits, Turnstile bot verification challenges, or authentication headers.
- Do not launch automated denial-of-service (DoS/DDoS) attacks against our edge infrastructure.
- Do not execute automated scrapers that degrade platform availability for legitimate researchers.
// 0x06 DUAL-USE RESEARCH OF CONCERN (DURC)
We acknowledge that telecommunications vulnerability data involves Dual-Use Research of Concern. TelcoSec rigorously reviews research outputs to ensure technical publications emphasize defensive remediation, detection signatures (Suricata/Snort/Wireshark filters), and standard hardening rather than offensive weaponization. Users agree to utilize all published knowledge solely to strengthen defenses.
// 0x07 ENFORCEMENT & ACCOUNTABILITY
TelcoSec actively monitors platform access patterns for indications of abuse. If we detect violations of this Acceptable Use Policy, we will immediately take one or more of the following actions:
- Immediate suspension or permanent termination of platform access and user accounts.
- Revocation of access keys to specialized tools and dedicated lab environments.
- Referral to and full cooperation with relevant national cyber emergency response teams (CERTs) and international law enforcement authorities where criminal telecommunications disruption is suspected.
// 0x08 ABUSE REPORTING & INCIDENT RESPONSE
If you discover or suspect that TelcoSec tools, data, or infrastructure are being misused by any party, please notify our Incident Response desk immediately: