← Back to home

/ SCOPE & BOUNDARIES

Scope and Boundaries

Version 1.0 | Effective 2026-08-21

This is a courtesy translation. The Chinese version is authoritative.

Odysec is a security research team working across the cyber and physical domains. We publish this statement so prospective clients can judge, before contacting us, whether their needs fall within our scope — and so the public understands our legal position and the limits of our conduct.


1. Legal position

  • Odysec is a private research team, not a law-enforcement agency. We hold no investigative, search, or coercive powers.
  • We are not a licensed private-investigation business and do not accept investigation-type engagements (see section 3).
  • Our "investigation" means technical analysis and research — analysing public information, performing forensics on a client's own devices and systems, and studying attack techniques and threat trends. It does not include surveillance of others.
  • If anyone claims law-enforcement status or investigative authority in Odysec's name, please report it to us immediately.

2. What we do

2.1 Independent research (published)

Domain Content
Cyber Threat intelligence, malware analysis, vulnerability research, tracking of emerging attack techniques
Personal security Exposure-assessment methodology, digital-footprint reduction, data-broker removal, operational security for high-risk situations
Convergence How digital footprints become physical risk: tracker abuse and detection, stalkerware, physical-intrusion risk of smart-home devices, OSINT-driven home-address exposure

All independent research is published under bylines and open to public scrutiny.

2.2 Engagements (confidential)

  • Security assessment and audit (network, systems, configuration)
  • Personal and household digital-exposure assessment and remediation guidance
  • Incident response and digital forensics (client-owned devices, accounts, and systems only)
  • Engaged physical-security assessment and penetration testing (subject to section 4)
  • Training and threat-awareness education

Engagement content and client identity are strictly confidential; see section 7 of the Research Ethics Code.

3. What we do not do

The following are refused without exception — no fee, relationship, or rationale changes this:

3.1 Private-investigation work

  • Locating people or tracing whereabouts
  • Infidelity evidence-gathering; marital or family-dispute investigation
  • Background or personal-history checks without the subject's consent
  • Debtor tracing

3.2 Surveillance of third parties

  • Helping monitor a spouse, partner, ex-partner, child, employee, or any third party
  • Installing, installing on behalf of others, or teaching the installation of monitoring software or tracking devices on another person's device or property
  • Non-consensual locating, communication interception, or audio/video recording
  • Breaking into another person's accounts, phones, or computers

If you are considering monitoring someone, we will not assist — and we suggest reviewing the Stalking and Harassment Prevention Act and Criminal Code art. 315-1. If you are worried that you are being monitored, that is exactly our research area — please get in touch.

3.3 Offensive services and tooling

  • Unauthorised intrusion, scanning, or testing of third-party systems
  • Retaliation-for-hire, taking down others' services, data destruction
  • Selling or brokering vulnerabilities, attack tools, or surveillance software
  • Helping evade law-enforcement investigation

3.4 Other

  • Impersonating law enforcement, public agencies, or any person
  • Commercial hit-jobs or opinion manipulation disguised as research
  • Any payment conditioned on influencing research conclusions
  • Engagement terms that forbid publishing negative findings

4. Preconditions for any engagement

Before accepting an engagement we verify the following; if any cannot be satisfied, we decline:

  1. Client identity and authority — the client must hold authority over the target (owner of the system; the device's own holder).
  2. Written authorisation — scope, time window, permitted methods, explicit prohibitions, emergency-stop conditions, and contacts on both sides.
  3. Extra requirements for physical testing — operators carry the original authorisation letter; a real-time contact channel is established; local police are notified where appropriate.
  4. Forensics device ownership — only devices the client owns or lawfully controls.

We may decline or terminate an engagement at any stage, including upon discovering that its purpose differs from what was represented.

5. Where to go instead

If your need falls outside our boundaries:

Need Suggested channel
Fraud victim, defrauded funds 165 anti-fraud hotline; police report
Criminal matters (intrusion, threats, stalking) Local police criminal-investigation units; protection orders under the Stalking and Harassment Prevention Act
Domestic violence, immediate danger 113 protection hotline; 110
Locating people, civil-dispute evidence Licensed private-investigation agencies; retained counsel
Legal advice, litigation Practising lawyers; bar-association legal aid
Personal-data breach complaints The organisation's data-protection contact; competent authority

We are glad to offer technical direction within our capabilities, but we do not act on your behalf in the above matters.

6. Contact

  • General: contact@odysec.org
  • Security reports: security@odysec.org (PGP fingerprint 1360 6273 6DFC 9D4B C9A1 5312 6FD4 6C88 46C0 DA1B)
  • Ethics complaints: ethics@odysec.org

Related documents: Research Ethics Code, Vulnerability Disclosure Policy.


Version Date Notes
1.0 2026-08-21 Initial release