1. Lawful authority
You may submit, access, or authorize testing only for systems, accounts, data, and materials you are legally permitted to use. Do not impersonate another person or organization, misstate authority, or submit a third party’s private credentials or targets without permission.
2. Security and network abuse
- Do not probe private, loopback, link-local, metadata, internal, or otherwise unauthorized network addresses.
- Do not use redirects, DNS changes, alternate encodings, ports, oversized responses, compression bombs, or timeouts to evade target controls.
- Do not use Folkbench as an open proxy, vulnerability scanner, credential tester, traffic relay, denial-of-service tool, or persistence mechanism.
- Do not attempt to access secrets, raw evidence, other organizations’ workspaces, internal operations, or non-public systems.
3. Evidence and directory integrity
- Do not fabricate sources, measurements, identities, reviews, incidents, or correction requests.
- Do not manipulate a test environment solely to produce a misleading published result.
- Do not bribe, threaten, coordinate abuse, or exploit automation to alter listing, scoring, publication, or review outcomes.
- Do not remove required context, dates, sample limits, or source labels when reusing Folkbench results.
4. Content and high-impact use
Do not submit unlawful, infringing, deceptive, malicious, privacy-invasive, or exploitative content. Folkbench comparisons are not a substitute for qualified review in healthcare, employment, housing, credit, education, public benefits, law enforcement, or other high-impact decisions.
5. Automation and service protection
Reasonable public browsing is permitted. Automated access must respect published technical controls and may not overload the service, bypass rate limits, defeat access restrictions, scrape private or personal data, or reproduce the directory as a competing misleading service.
6. Enforcement and reporting
Folkbench may reject a target, stop a run, quarantine evidence, remove content, limit access, suspend an account, preserve relevant audit records, or report conduct when reasonably necessary. Decisions consider severity, intent, recurrence, impact, and the possibility of safe remediation.
Report suspected abuse through the contact page without including secrets or active exploit material.