RYSZARD BIALACH
TRUSTED USE
← Return to portfolio

RESPONSIBLE ACCESS // PUBLIC POLICY

Responsible & Trusted Use Policy

This portfolio includes cybersecurity research, educational demonstrations, and browser-based tools. They are provided to encourage defensive investigation, responsible experimentation, professional learning, and safer security practices.

POLICY VERSION // 2026-09-v1

Purpose

The site is a public cybersecurity engineering portfolio and experimental learning environment. Its tools and demonstrations are intended for education, defensive analysis, authorized research, professional evaluation, and the development of safer technical and human security practices.

Core rule: Use these tools only with files, systems, accounts, networks, devices, or information you own or have explicit authorization to examine.

Responsible Use

Visitors are expected to use the site in ways that respect authorization, privacy, safety, and applicable law.

  • Analyze only material you are authorized to inspect.
  • Use findings as investigative evidence, not automatic proof of maliciousness, innocence, attribution, or compromise.
  • Protect confidential, personal, regulated, or proprietary information.
  • Use demonstrations to improve understanding, controls, resilience, and cooperative security practices.
  • Escalate real security concerns through appropriate organizational or platform channels.

Prohibited Use

The tools and demonstrations are not intended to support unauthorized or harmful activity.

  • Do not use the site to facilitate unauthorized access, intrusion, surveillance, credential theft, evasion, harassment, or destructive activity.
  • Do not analyze confidential or third-party files without authorization.
  • Do not treat MORPH//NODE as a construction or operational guide for a physical device.
  • Do not use SafeCircle concepts to manipulate, coerce, impersonate, or deceive people.
  • Do not attempt to bypass site controls or use the public tools as a substitute for an authorized malware sandbox or enterprise forensic environment.

Privacy & Local Processing

The public site is intentionally designed to minimize data collection and does not require a user account to explore the portfolio.

ByteWitness

ByteWitness is designed to read selected files locally through browser APIs. The public implementation does not intentionally upload, transmit, execute, or retain the selected file on behalf of the site owner.

Trusted-use acknowledgement

When you accept this policy, the site stores a small acknowledgement record in your browser's local storage. It records the policy version and acceptance time so the site can remember that the current policy has already been acknowledged. This record stays in the browser unless you clear site data or the browser removes it.

External services

Links to services such as GitHub or LinkedIn lead to third-party sites with their own privacy and security practices.

Tool-Specific Boundaries

ByteWitness

ByteWitness performs static inspection only. It does not execute a selected sample. Findings such as embedded signatures, entropy changes, metadata, strings, or structural anomalies are observations that may warrant further investigation.

MORPH//NODE

MORPH//NODE is an abstract cyber-physical threat-modeling experience. It intentionally omits dimensions, propulsion details, construction procedures, operational control code, and other implementation details that would turn the demonstration into a build guide.

SafeCircle

SafeCircle promotes defensive social patterns such as trusted-channel verification, supportive reporting, slowing down high-pressure decisions, protecting accounts, and community cooperation. It is not intended to teach deception or coercion.

Accuracy & Limitations

Cybersecurity evidence is contextual. Static file analysis, demonstrations, educational control scores, and scenario feedback cannot guarantee that a file, device, account, organization, or person is safe or compromised.

  • A suspicious indicator is not automatically proof of malicious activity.
  • An absence of detected indicators is not proof that something is safe.
  • Educational trust or posture scores are illustrative, not certifications.
  • Real investigations should incorporate appropriate endpoint, identity, network, provenance, organizational, and legal context.

Responsible Research

The portfolio favors reproducibility, evidence preservation, least privilege, privacy, transparent assumptions, and clear separation between observation and conclusion. Research should be performed in environments where authorization and containment are established before testing begins.

Security Reporting

If you believe you have identified a security issue affecting this public site, use the site's published security information rather than attempting to exploit or expand the issue.

View security.txt →