← Back to home

/ RESEARCH ETHICS CODE

Research Ethics Code

Version 1.0 | Effective 2026-08-21 | Applies to all members, collaborating researchers, external advisors, and research interns

This is a courtesy translation. The Chinese version is authoritative.


1. Purpose

Odysec's research spans both the cyber and physical domains, and both may involve real people facing real risks. This code defines what we may and may not do in the course of research, and the principles we follow when judgment is difficult.

This code is public: anyone may hold us to it. Engagements, collaborations, or research directions that conflict with this code will not be undertaken, regardless of compensation.

2. Core principles

When a judgment call is ambiguous, we weigh it in the following order:

  1. Avoiding harm outweighs research value. If the conduct of a study would itself put a person at risk, we do not conduct it, however valuable the findings.
  2. Informed consent is a precondition for research involving people. No explicit, revocable consent — no research.
  3. Data minimisation. We collect, retain, and disclose only what the research purpose requires, and destroy it when the retention period ends.
  4. Accountability. Research is published under team or individual bylines; errors are corrected publicly, never quietly abandoned.
  5. Public interest over commercial interest. No sponsorship or engagement may influence research conclusions.

3. Cyber research rules

3.1 Testing boundaries

  • Proofs of concept run only in our own isolated environments or against targets with written authorisation.
  • We do not scan, probe, attempt logins on, or otherwise actively test unauthorised systems. Articles 358–360 of Taiwan's Criminal Code (offences against computer use) provide no research exemption.
  • "The system looks unmaintained", "it was only a light scan", and "no damage was done" are not justifications for unauthorised testing.

3.2 Malware and sample handling

  • Samples are analysed only in offline, isolated environments — never on daily working machines, and never with shared folders mounted.
  • We do not distribute directly weaponisable exploit code. PoCs in technical articles demonstrate the principle; key details are withheld where necessary.
  • Samples are not passed to third parties lacking handling capability or a legitimate research purpose.

3.3 Breached data

  • We do not proactively download, collect, or purchase breach datasets.
  • Where research requires contact with breached data, we inspect only the minimum needed for verification, retain no personally identifiable information, and destroy the data once verification completes.
  • We do not use breached data to query or correlate specific individuals.
  • On discovering a significant breach, we notify the affected organisation and competent authorities before any publication.

4. Physical and personal-safety research rules

Research subjects in the physical domain are often real people; the rules here are stricter than for cyber research.

4.1 Informed consent (non-negotiable)

Any research involving real people — tracker-detection testing, stalkerware verification, personal exposure assessment, social-engineering exercises — requires:

  • Written consent stating the purpose, methods, data use, retention period, and risks;
  • The right to withdraw at any time, with existing data destroyed at the subject's request;
  • Subjects who are volunteers or the researchers themselves;
  • For minors or persons requiring additional protection, guardian consent and elevated safeguards.

4.2 Absolute prohibitions

  • Locating, tracking, surveilling, recording, or intercepting communications of any person without their consent.
  • Collecting evidence of a specific person's movements or conduct without that person's own engagement of our services.
  • Assisting anyone, under the guise of research, to monitor a spouse, partner, child, employee, or any third party.

Relevant law: Criminal Code art. 315-1 (offences against privacy), the Stalking and Harassment Prevention Act, and the Personal Data Protection Act. A research purpose is not a defence under any of these laws.

4.3 Physical security testing (when engaged)

When engaged to test access control, physical intrusion, or social engineering:

  • A client-signed written authorisation must state the scope, time window, permitted methods, explicit prohibitions, emergency-stop conditions, and on-site contacts;
  • Operators carry the original authorisation letter and, if challenged by security staff or law enforcement, present it immediately and stop testing;
  • A real-time channel to the client's internal contact is established in advance; local police are notified where appropriate;
  • No methods that could endanger anyone; testing stops if bystanders may be alarmed.

5. Vulnerable and high-risk subjects

Where research involves survivors of domestic violence or stalking, journalists, human-rights workers, or other high-risk individuals:

  • Identity protection comes first: reports contain no re-identifiable detail, including combinations of indirect identifiers;
  • Data is kept for the minimum period, encrypted, with access limited to those who need it;
  • Cases are never used as marketing material, even de-identified;
  • We are technical researchers, not social workers, lawyers, or law enforcement. Where there is immediate danger, or a protection order or criminal complaint is needed, we refer the person to police, social services, or counsel — we do not act in their place.

6. Independence and conflicts of interest

  • We accept no payment or sponsorship conditioned on influencing research conclusions.
  • Externally funded research discloses its funding source upon publication.
  • Members with financial or personal stakes in a research subject recuse themselves or disclose the interest in the report.
  • We do not accept engagement terms that forbid publishing negative findings.

7. The line between confidentiality and publication

Odysec runs two tracks:

  • Public research: self-initiated research is published in full, under bylines, open to scrutiny.
  • Confidential engagements: client matters — content, identity, and findings — are strictly confidential and disclosed only with the client's written consent. Generalisable issues found during engagements may be published separately, fully de-identified and client-approved.

Confidentiality survives the end of the engagement. It may not be used to shield conduct that violates this code.

8. Violations

  • Any member who observes a violation reports it to the team lead immediately; matters that cannot be resolved internally go to an external ethics advisor.
  • Serious violations end research participation; unlawful conduct is handled according to law, with full cooperation.
  • Anyone who believes Odysec has violated this code may write to ethics@odysec.org; we commit to responding within 14 working days.

9. Revisions

This code is reviewed annually, or immediately after any significant incident. Revision history is public; old versions are never deleted.

Version Date Notes
1.0 2026-08-21 Initial release