Locinode provides systems specifically for cybersecurity training. Permission is limited to the target and resources assigned to your active Locinode challenge. Using Locinode never grants permission to test unrelated systems.
In scope
- The challenge target assigned for your active session.
- Artifacts intentionally supplied with that challenge.
- The disposable workstation and tools provided for the mission.
- Activity required by the stated objective when it remains inside the assigned environment.
Out of scope
- Third-party websites, services, APIs, accounts, or infrastructure.
- Locinode's production control plane unless separate written authorization explicitly says otherwise.
- Other players, their accounts, sessions, private messages, or data.
- Networks or hosts not identified as part of the active challenge.
- Using a training workstation as a launch point toward unrelated internet systems.
Public availability is not permission
A system being reachable from the internet does not mean it is available for security testing. Authorization should come from the owner and define the systems, time period, and activity allowed.
Report platform problems
If you notice unexpected behavior in Locinode itself, use the platform's Report problem function. Do not treat a suspected issue in the production service as an invitation to continue testing beyond what is necessary to describe it.
Scope is a professional skill
Real security assessments use rules of engagement. Knowing when to stop, how to distinguish an assigned asset from a neighboring one, and how to document uncertainty are security skills. Locinode includes scope language because responsible practice is part of the curriculum.