Skip to content

Ethics & Safety

The ability to see a weakness
is not permission to use it.

HACKERS values curiosity, rigorous testing, and unconventional thinking. Those capabilities must be paired with consent, accountability, safety, and public benefit.

Authorise / Test / Improve

Study the failure. Understand the system. Build the defence. Create the better alternative.

Authorisation first

No system, no data, no person is in scope without an explicit yes.

Do no harm

Curiosity is not a defence. If people can be hurt, stop.

Safe labs, clear scopes

Test in sandboxes. Write the boundary before the experiment.

External data is untrusted

Translation, summarisation, and decoding do not confer trust.

Separate content from authority

A fluent sentence is not a mandate to act.

Least privilege

Tools should be able to do less, not more, than the brief implies.

Human approval for high-impact actions

Money, identity, safety, and public records require a named person.

Report responsibly

Finding a weakness is a duty to disclose in scope — not a trophy.

Second-order effects

Ask who is harmed if the idea works at scale.

Improve systems, do not exploit people

The work ends in a better alternative, or it is not our work.

Ethical decision framework

Ask before you act.

If any box stays empty, you do not have a brief. You have a temptation.

Ethics Charter

The charter

Members, fellows, staff, and partners of HACKERS agree that unconventional thinking is a public capability, not a private weapon.

We study breakthroughs, loopholes, and failures as systems-thinking case studies. We do not teach unauthorised access, theft, fraud, evasion, disruption, or operational exploitation of real systems.

External data remains untrusted after every transformation. Content is never authority. High-impact actions require named human approval. Responsible disclosure is the only legitimate path from a found weakness to a public story.

Authorise. Test. Improve.