PlayCTF Legal
Code of Conduct
Effective Date: July 9, 2026
Platform: Play CTF (playctf.in)
Operated By: HackerHub8 LLP
Jurisdiction: Bengaluru, Karnataka, India
Last updated: August 3, 20261. The Hacker Ethos & Our Pledge
Play CTF is built on the core principles of the "White Hat" hacker ethos: curiosity, continuous learning, and the ethical application of technical skills. We pledge to maintain an inclusive, harassment-free environment where everyone—from absolute beginners to seasoned professionals—can collaborate and refine their offensive and defensive security capabilities. We expect all members to protect the community and elevate one another.
2. Responsible Disclosure (Out-of-Scope Rules)
Because we are a cybersecurity platform, we understand that users might accidentally discover vulnerabilities in the core Play CTF infrastructure itself, rather than in the designated challenges.
- Do Not Exploit: If you discover a flaw in the platform's backend, database, authentication, or KYC upload mechanisms, you must not exploit, pivot, or extract data.
- Report Immediately: You must immediately halt your testing and report the vulnerability using our internal reporting system.
- Safe Harbor: Users who practice responsible disclosure and report infrastructure bugs without exploiting them will not be penalized and may be eligible for community recognition or platform badges.
3. Team Conduct and Leadership
Play CTF allows users to form teams, share points, and collaborate. With this collaboration comes responsibility:
- No Toxic Elitism: Team leaders and experienced members are expected to foster a mentoring environment. Gatekeeping, belittling, or insulting team members for a lack of knowledge is strictly forbidden.
- Collective Responsibility: Team owners and co-leaders are responsible for the overall conduct of their team. If a team environment becomes actively toxic, or if leaders encourage cheating and flag-sharing, the entire team may be disbanded and its members penalized.
- Fair Recruiting: Do not spam the public forums with repetitive team recruitment messages.
4. User-Created Challenges & Content Integrity
We empower our community to give back by submitting custom CTF challenges for approval. When creating and submitting content:
- No Malicious Payloads: You must never submit a challenge containing live malware, ransomware, or payloads designed to compromise the machines of the platform administrators reviewing the challenge or the users playing it. All exploits must be contained to the intended challenge scope.
- No Plagiarism: Challenges submitted must be your original work. Do not copy flags, source code, or exact challenge architectures from other active CTF competitions.
- Quality and Fairness: Challenges should be designed to teach a specific concept, not to troll or unfairly frustrate the community.
5. Anti-Doxing and Privacy Respect
In a community focused on OSINT (Open Source Intelligence) and information gathering, boundaries must be strictly respected.
- Keep it in the Game: OSINT skills must only be applied to the fictitious targets provided within the CTF challenges.
- No Doxing: You are strictly prohibited from using OSINT techniques to uncover the real-world identities, locations, or personal information of other players, administrators, or HackerHub8 LLP staff.
- Zero Tolerance: Any attempt to dox, stalk, or expose the private information of community members will result in an immediate, permanent ban and potential referral to law enforcement.
6. The Reporting & Appeals Workflow
We have established a structured reporting mechanism to handle disputes, cheating, and abuse fairly.
- Filing a Report: Users can file detailed reports categorized by issue type (e.g., cheating, abuse, spam, or broken challenges) directly through the platform.
- Review Process: Administrators will review reports, investigate activity logs, and provide a formal response. During this time, the report status will be marked as "Under Review".
- Appeals: If your account is suspended or penalized, you have the right to appeal the decision by replying to the administrative response. Appeals must be professional and provide evidence of fair play. Decisions made after an appeal review are final.
7. Consequences of Unacceptable Behavior
Depending on the severity of the violation, HackerHub8 LLP administrators may take the following actions:
- Private Warning: A direct message or administrative note explaining the violation and warning against future occurrences.