Version 2.0 · effective 28 August 2026 · supersedes the version last updated 01/10/2025
Applies to: every person who accesses or uses the TryHackMe platform, whether on a free account, a paid individual subscription, an organisation account, or access supplied through an authorised reseller
1. What this policy is, and why it is short on legalese
TryHackMe gives you real attack tools, real vulnerable machines and real techniques. That is the whole point, and it is also why we need a clear set of rules about where you may use them.
This policy sets those rules. It is written in plain language because it has to be understood by a sixteen-year-old on a free account and by a security manager rolling us out to four hundred people. Where a phrase looks unusually precise, that is deliberate and the precision matters legally.
One sentence version: everything you learn here is yours to use, and the only systems you may point it at are the ones we assign you or the ones you have written permission to test.
2. Who this policy binds, and how it fits with our other terms
This policy binds you personally, as an individual user, whether you signed up yourself or your employer, school, university or a reseller bought your access.
It sits alongside:
our Terms of Use if you hold an individual account
our Business Terms of Use if your access comes through an organisation
our Privacy Policy, and our AI Terms of Use where you use AI-assisted features
If your organisation bought access for you, your organisation has also agreed to be responsible for your compliance with this policy. That does not reduce your own responsibility under it.
You accept this policy when you create an account and again when we ask you to accept a new version. If you do not accept it, you may not use the platform.
3. Age
You must be at least 13 years old to create an account.
If you are under 18, we may restrict or turn off some content and some community features on your account, and some content may be available only through a school or college account rather than an individual one. Where your access comes through a school, college or other organisation whose learners include people under 18, that organisation is responsible for obtaining any consent its own law requires, and may ask us to apply further restrictions to its learners' accounts.
Where we have reason to believe an account holder is under 13, we will suspend the account.
4. Authorisation: the rule that matters most
You may use the techniques, tools, scripts, exploits and credentials you obtain through TryHackMe only against:
(a) the specific lab environments, machines, applications, networks and IP ranges we have assigned to you inside the platform; or
(b) systems, networks, accounts and data that you own, or for which you hold documented, current, written authorisation from the owner covering the testing you intend to carry out.
That phrase is precise on purpose. "Documented" means it exists in a form you can produce. "Current" means it has not expired and has not been withdrawn. "Written" means recorded, not remembered. "Covering the testing you intend to carry out" means the permission actually extends to what you are about to do, not to something adjacent.
Nothing in the platform authorises you to attack anything outside it. No room, path, walkthrough, lab brief, certification, hint, community post, support reply or communication from us constitutes authorisation, permission or a defence in relation to any system other than the lab environments assigned to you. If a lab teaches you a technique, that is instruction, not consent from the owner of some other system.
You are responsible for complying with the computer misuse, cybercrime, unauthorised access and interception laws of your own country and of any country whose systems your activity touches. In the UK that includes the Computer Misuse Act 1990. In the United States it includes the Computer Fraud and Abuse Act. Many other countries have equivalent or broader laws, and some criminalise possessing or distributing hacking tools more widely than the UK does.
5. Stay inside your lab
Lab environments are sandboxed. Keep your activity inside them.
You must not:
5.1 use any TryHackMe-provided infrastructure, including AttackBox, our VPN, cloud lab instances and any machine or container we provision for you, as a launch point, proxy, relay, staging host, command-and-control server, tunnel or scanning platform against anything outside your assigned lab environment;
5.2 pivot, route, tunnel or forward traffic out of a lab environment to any system on the internet, on your own network, on your employer's network, on your school's network, or on any other third party's network;
5.3 attempt to escape lab isolation, break out of a container or virtual machine, reach the underlying host, hypervisor, orchestration layer or management network, or access any part of our infrastructure that a lab is not intended to expose;
5.4 attack, scan or interfere with another user's lab instance, machine, session, account, submissions or progress;
5.5 connect a lab environment to any production system, or use one to process, store or transmit real business or personal data.
If you find yourself outside a lab environment, stop, disconnect, and tell us. Reporting it is not an admission of wrongdoing and we would much rather hear it from you.
6. Our own systems, and how to test them properly
The platform has two parts and they are treated very differently.
Lab environments and lab content are in scope for you. They are deliberately vulnerable. Attacking them is what you are here to do.
The TryHackMe platform itself is not in scope. That means our websites and applications, our account and authentication systems, our billing systems, our admin and reporting consoles, our APIs, our content delivery, our lab orchestration and management layer, our infrastructure, and other customers' tenants and data.
You must not scan, probe, test, exploit, attempt to gain unauthorised access to, or interfere with any of it, except strictly in accordance with our Vulnerability Disclosure Policy, or where no such policy is published, with our prior written permission obtained by contacting us at support@tryhackme.com.
That is the only permitted route for security testing of the platform. Where a Vulnerability Disclosure Policy is published, it tells you what is in scope, how to report, what we commit to, and what we ask of you in return. We would genuinely like to hear from you: given who our users are, responsible reports are one of the most useful things we receive.
If you discover a vulnerability in the platform by accident, in the course of ordinary use, you must report it through that policy and must not explore it further, exploit it, access data it exposes, or tell anyone else about it until we have addressed it.
7. Your account and your credentials
7.1 One account per person. Accounts are personal to you.
7.2 Do not share, sell, rent, transfer, lend or publish your account or credentials, and do not let anyone else use your account, including a colleague, classmate or family member.
7.3 Do not use anyone else's account, or credentials you did not obtain legitimately.
7.4 Do not use more than one account to gain an advantage in a competition, leaderboard, streak, ranking or certification, or to evade a suspension.
7.5 Keep your credentials secure. Where your account has administrative rights over an organisation's tenant, enable multi-factor authentication.
7.6 Tell us promptly if you believe your account has been compromised.
8. Content integrity: flags, solutions and certifications
This section protects the thing that makes the platform work. A challenge that everyone already has the answer to teaches nobody anything.
8.1 Active content. Do not share, publish, post, stream, sell or otherwise distribute flags, answers, solutions, exploit code written for a specific room, or step-by-step walkthroughs for any content that is currently active on the platform. That includes private sharing in group chats, Discord servers and code repositories, and it includes posting to your own blog or video channel.
This does not stop an instructor, lecturer or team lead teaching, discussing or reviewing content with their own learners inside an organisation account licensed for it. That is what those accounts are for. Keep it inside the organisation.
8.2 Retired content. You may publish writeups for content we have designated as retired, in line with our writeup guidance. Where content is not marked as retired, treat it as active.
8.3 Certification and examination content is protected permanently. Do not share, reproduce, describe, discuss, record, transcribe, reconstruct or distribute any part of a TryHackMe certification or examination, including questions, tasks, target environments, flags, answers, scoring, or your own account of what the exam contained. This applies during the exam, after it, whether or not you passed, and whether or not the exam is still offered. There is no retirement window for exam content.
8.4 Examination conduct. Do not give or receive help during an examination, do not use another person's work, do not have anyone else sit an examination for you, and do not use unauthorised resources where the examination rules prohibit them.
8.5 Organisation content. Where your organisation has created custom content, or where content has been made available only to your organisation, do not share it outside that organisation.
8.6 Do not encourage, solicit, pay for or knowingly benefit from anyone else doing any of the above.
9. No extraction, no scraping, no automated access
9.1 Do not systematically download, copy, harvest, mirror, index or compile the platform's content, in whole or in substantial part, and do not build any dataset, database, archive, compilation or embedding from it.
9.2 Do not access the platform using any bot, crawler, scraper, spider, headless browser, automation framework, AI agent, large language model, reinforcement learning agent or multi-agent system, or any other automated means, except through an interface we have expressly provided for that purpose and in accordance with its documentation.
9.3 Do not use the platform's content, including rooms, learning paths, questions, answers, flags, hints, walkthroughs, lab images, network topologies and certification materials, to train, fine-tune, ground, evaluate, benchmark or otherwise develop or improve any artificial intelligence or machine learning model, large language model, neural network, algorithm or system. This applies whether or not what you are building competes with us.
9.4 Do not circumvent, disable or interfere with rate limits, access controls, authentication, licensing, entitlement checks, geographic restrictions or any other technical measure we use to protect the platform.
9.5 What sections 9.1 and 9.2 are not about. They are about pointing automation at the platform and about extracting our content in bulk. They are not about how you learn.
Keeping your own notes is fine. Using our AI-assisted features as intended is fine, and is governed by our AI Terms of Use. Asking an AI assistant in your own browser to explain a concept to you is fine, unless the room or the examination you are working on tells you not to, in which case that instruction applies. What is not fine is handing an agent your credentials and letting it work through the platform for you, or using our content as training data.
10. No real-world harm
10.1 Do not use the platform to develop, test, refine, stage or host tooling, payloads, infrastructure or techniques intended for use against any third party without that party's authorisation.
10.2 Do not use the platform to store, host, distribute or stage malware, ransomware, stolen credentials, exfiltrated data or breach material for real-world deployment or trade. Working with malware samples inside an assigned lab, as the lab intends, is fine. Using our infrastructure as your armoury is not.
10.3 Do not knowingly upload, enter or process real personal data belonging to other people in a lab environment, in a challenge, or in any content you create. Use synthetic data. This matters particularly for social engineering, OSINT and reconnaissance content, where the exercise is only lawful if the target is not a real person who has not consented. If a lab asks you to research a target, research the fictional one it gives you.
10.4 Do not use the platform to plan, coordinate, facilitate or carry out any unlawful act.
10.5 Do not use knowledge, skills or tooling acquired through the platform to harm anyone. We cannot enforce this by technical means, but it is the reason all of the above exists.
11. Community and interactive features
The platform includes forums, discussion areas, chat, leaderboards, profiles, writeup areas, competitions and other places where users interact.
You must not use them to:
11.1 bully, harass, intimidate, threaten, stalk, humiliate or abuse anyone;
11.2 post content that is discriminatory or that promotes hatred on the basis of race, ethnicity, national origin, religion, sex, gender, gender identity, sexual orientation, disability, age or any other protected characteristic;
11.3 harm, endanger, sexualise, groom or exploit any child, or post any content that sexualises a child;
11.4 impersonate any person or organisation, or misrepresent your affiliation with one;
11.5 post unsolicited advertising, promotional material, spam, chain messages, pyramid schemes or recruitment content;
11.6 publish anyone's personal information without their consent, including doxxing;
11.7 advertise, offer or solicit account sharing, account sales, exam-sitting services, answer packs, cheating services or access to protected content;
11.8 post terrorist content, or content that encourages, glorifies or provides instruction for terrorism.
We moderate community areas but we do not pre-vet every contribution, and we do not guarantee that we will see something before you do. If you encounter content that breaches this policy, report it.
Where a school, college or other organisation asks us to restrict or disable community features for its learners, we will do so for those accounts.
12. Standards for content you contribute
Anything you contribute to the platform, including rooms, writeups, forum posts, profile content, competition submissions and messages, must:
12.1 be accurate where it states facts, and genuinely held where it states opinions;
12.2 comply with the law of England and Wales and of any country from which it is posted;
12.3 not infringe anyone's copyright, database right, trade mark or other intellectual property right;
12.4 not be defamatory, obscene, offensive, hateful, inflammatory, deceptive or misleading;
12.5 not contain malicious code intended to affect other users or our platform, except where you are contributing content through a programme we run for that purpose and in accordance with its rules;
12.6 not breach any duty of confidence you owe to anyone, or disclose your employer's or client's non-public information.
If you contribute a room or challenge, you are also responsible for making sure it is safe to run, that it does not reach outside its own environment, and that it does not contain real personal data or third-party content you do not have the right to use.
13. Sanctions, export control and where you access from
13.1 Do not access or use the platform if you are subject to UK, EU, US or United Nations sanctions, or if you are owned or controlled by a person who is.
13.2 Do not access the platform from, or provide access to any person in, a territory subject to comprehensive sanctions or a territory we have blocked. Where we block access from a territory by technical means, circumventing that block, including by VPN, proxy or any other method, is a breach of this policy.
13.3 Do not use the platform in breach of any applicable export control law, and do not re-export, transfer or provide access to platform content in breach of one.
13.4 Some content is restricted and made available only under additional conditions. Do not attempt to obtain access to restricted content other than through the process we specify.
14. What we monitor
We are straight with you about this because you will work it out anyway.
We log platform activity, including authentication, lab launches, sessions, submissions, flag entries, network activity within lab environments, and administrative actions. We do this to run the service, keep it available, secure it, detect and investigate abuse, enforce this policy, meet our legal obligations, and provide reporting to organisations that have bought access for their people.
Where your access comes through an organisation, that organisation's administrators can see your activity and progress within their tenant.
We do not read the content of your lab sessions for any purpose other than those set out above, and our Privacy Policy explains how we handle your personal data.
15. Enforcement
If we believe you have breached this policy, or if we need to act to protect the platform, other users or a third party, we may take any of the following steps, in any order, and we do not have to start at the top.
| Step | What it means |
|---|---|
| Warning | We tell you what the problem is and ask you to stop |
| Restriction | We remove points, badges, ranking, leaderboard placement or writeup privileges, or restrict community access |
| Content removal | We remove or make inaccessible content you posted |
| Suspension | We suspend your access, or specific features, temporarily |
| Termination | We close your account permanently and, where we are entitled to, do so without refund |
We may also, where the circumstances justify it: revoke a certification you obtained; void an examination result; suspend access for every user in an organisation's tenant where the breach is systemic; report the matter to law enforcement or a regulator; and take legal action.
Where your access was bought by an employer, school, university or other organisation, we may tell that organisation, where we consider it necessary and proportionate to do so. We will not do it to embarrass you, and for a minor first breach we would normally deal with you directly.
We may act immediately and without notice. Some breaches of this policy are potentially criminal acts happening on our infrastructure in real time, and where that is the case we will stop it first and discuss it afterwards. Where your access came through an organisation or a reseller, we may suspend you without notifying them first.
Serious breaches lead to immediate permanent termination. These include attacking a third party from our infrastructure, escaping lab isolation, attacking the platform other than as section 6 permits, sharing certification or examination content, using the platform for a real-world attack, and any conduct that endangers a child.
You must cooperate with any investigation we carry out, and give us the information we reasonably request.
16. Appeals
If we suspend or terminate your account, or void a certification or examination result, you may appeal.
Appeal within 30 days, using the route in the notice we send you.
Tell us what you think we got wrong, and give us anything you want us to consider. If your case depends on having had permission to test something, this is where you produce it.
We will respond within 10 business days.
Your appeal will be considered by someone who was not involved in the original decision.
Where the decision was a permanent termination or the revocation of a certification, and you are not satisfied with the outcome of the appeal, a second-level review will be carried out by a panel that includes someone outside the team that made both earlier decisions. That review is final.
We do not charge for appeals and we do not require you to accept anything in order to make one.
17. Organisation accounts
Where access is bought by an employer, school, college, university, government body, managed service provider or reseller, that organisation must:
17.1 ensure that every one of its users accepts this policy and is made aware of it before they are given access;
17.2 be responsible for its users' acts and omissions in relation to the platform as if they were its own;
17.3 not permit anyone who is not an authorised user to access the platform, and not pool, share or rotate accounts between people;
17.4 tell us promptly if it becomes aware of a breach of this policy by one of its users, and cooperate with our investigation, including by identifying the user;
17.5 where its users include people under 18, comply with the additional conditions we set for those accounts.
Where access was supplied through a reseller, the reseller cannot vary this policy, cannot give you permission to do anything this policy prohibits, and is not authorised to make any statement on our behalf about what is permitted. If a reseller has told you something inconsistent with this policy, this policy governs.
18. Changes to this policy
We may change this policy. Where a change is material, we will give notice and ask you to accept the new version before you continue using the platform. Where the change is minor, we will update the version and date at the top. Continuing to use the platform after a change takes effect means you accept it.
Each version records the date it took effect.
19. Governing law
This policy is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising out of or in connection with it. Nothing in this section affects any right you have to bring proceedings in your country of residence where the law of that country gives you that right and it cannot be excluded by agreement.
20. Contact
Reporting a security vulnerability in the platform. Section 6 sets out the only permitted route for testing the platform, and how to reach us before you start.
Reporting a breach of this policy, or content that concerns you. Use the reporting option in the platform where one is available. Otherwise email support@tryhackme.com and tell us your message concerns this policy.
Appealing a decision. Follow the route in the notice we sent you. It tells you where to send your appeal and the deadline.
Anything else. support@tryhackme.com.
TryHackMe Ltd, 128 City Road, London EC1V 2NX. Company number 11673275.