Community
Community Guidelines
These guidelines explain what the room is for and what gets someone removed from it. They apply to posts, comments, messages, profiles and communities. Our Terms of Service are the contract; this page is the culture.
Contents
1. Who this room is for
People who do security work: red and blue teams, researchers, engineers, analysts, leaders, and people seriously learning the craft. Every account is reviewed by a person before it gets in. Vendors and recruiters are welcome as practitioners; they are not welcome as vendors and recruiters.
2. Credibility is checkable here
A verification badge on Tunnyl says exactly what a reviewer checked: a certification confirmed with its issuer, an employer confirmed through a work address, original security work on GitHub, or a public record such as a talk or a CVE credit. It never says more than that. Claims on a profile that were not checked are shown as self-reported.
- Do not claim credentials, roles or work that are not yours.
- Do not impersonate a person, a company or a research group.
- If you find a badge that was granted on false evidence, report the profile. We revoke and we say why.
3. How we argue
Disagreement is the point of a room like this. Keep it about the work.
- Attack the analysis, not the analyst. No slurs, no harassment, no piling on.
- Say how you know. Link the source, the sample, the CVE, the write-up. "Trust me" is not evidence.
- Correct in public, but plainly. Being right does not license contempt.
- Do not post private conversations, screenshots of DMs, or anyone's personal information.
4. No selling, no recruiting
The feed is not a channel. Product pitches, "DM me for pricing", affiliate links, unsolicited recruiting messages and lead-generation posts are removed on first report. Talking about a tool you built is fine when the post is about the work and says that you built it.
5. Vulnerabilities and offensive work
This is a security community; exploits, malware analysis and offensive tooling are normal topics. What is not:
- Publishing a vulnerability in a live product before the vendor has had a reasonable disclosure window, unless it is already public.
- Posting working exploits, credentials or data for systems you do not own or have authorisation to test.
- Sharing stolen data, leaked credentials or doxxing material, even "for research".
- Asking for help attacking a specific target you are not authorised to test.
6. Safety
- You can block anyone. A blocked person cannot message you or send you a connection request.
- Direct messages are end-to-end encrypted. Moderators cannot read them; if you report a message, include what happened.
- Your privacy settings control who can message you and see your connections.
- You can download everything we hold about you, and delete your account, from Settings → Account.
7. Reporting and what happens next
Every post, comment, profile and conversation has a Report action. Reports go to a moderator, never to the person reported. A moderator reads it, looks at the content, and does one of four things: dismisses it, warns the author, removes the content, or suspends the account. The author is told when action is taken. Reporting in bad faith, to silence someone you disagree with, is itself a violation.
8. Consequences
Most problems end with a removed post and a note. Repeated or serious violations end with suspension. Impersonation, selling credentials or data, and harassment end with removal on the first confirmed report. Questions or appeals go to [email protected].