Legal & Compliance
Last updated: 12 September 2026Scope of this notice
This notice describes the basis on which BlackSword Technologies (“BlackSword”, “we”, “us”) conducts its vulnerability research and security engineering work, and the conditions that apply to researchers, research teams, security companies, and government and institutional clients who engage with us. It is provided for general information. Specific rights and obligations are set out in the applicable written agreement.
Legitimate research only
BlackSword works exclusively with vulnerability research that has been produced lawfully and responsibly. By submitting research to us, you represent and warrant that:
- the research is your own work, or you are authorised to share it on behalf of its owner;
- the research was produced without unauthorised access to any system, network, account, or data;
- the research does not include information obtained in breach of any law, contract, or duty of confidence;
- you have the right to disclose the research to us and to permit its evaluation.
We do not solicit or facilitate unauthorised access, criminal exploitation, malware, or attacks against third parties. Research indicating unlawful provenance is declined.
Initial submissions
Initial submissions are limited to a high-level description of the research. Do not submit live exploit code, payloads, credentials, personal data, or information derived from unauthorised access. Additional technical material is requested only after an initial review, and only through channels designated by us and, where appropriate, under a written agreement.
Evaluation and remediation
Submissions are reviewed on technical merit, including significance, validity, affected technology, uniqueness, reliability, and practical security impact. Review does not create any obligation on either party, and does not restrict either party prior to a signed agreement. Any engagement, licence, or disclosure arrangement is governed exclusively by the executed written agreement between the parties.
Export controls and sanctions
Engagements are subject to applicable laws, contractual requirements, export controls, and responsible security practices. We do not engage, and do not permit engagement, where doing so would breach applicable export control, sanctions, or technology-transfer restrictions. Both parties are responsible for complying with the laws that apply to them.
Confidentiality
Sensitive research is handled through controlled communication. Information received is treated as confidential and is shared only where necessary for evaluation, or where required by law. Where an engagement proceeds, confidentiality and non-disclosure obligations are recorded in writing before sensitive technical material is exchanged.
Intellectual property
You retain all rights in research you submit unless and until those rights are expressly transferred under a signed written agreement. Submission alone does not transfer ownership.
Prohibited use
Nothing provided by BlackSword may be used to access, interfere with, or compromise systems, networks, or data without proper authorisation, or to develop or deploy malicious software. Our program exists to support legitimate security research and the remediation of security risk.
No offer or solicitation
Nothing on this website constitutes an offer, solicitation, or commitment to enter into any agreement or to provide any service. Availability of the program may change without notice.
Governing law
BlackSword Technologies operates from the United Arab Emirates. Unless otherwise agreed in writing, engagements are governed by the laws of the United Arab Emirates and subject to the jurisdiction of its competent courts.
Contact
Questions about this notice, or about the compliance posture of a proposed engagement, can be raised through the confidential submission and contact channel on the main site.