# security.txt for mlab.sh and all subdomains (*.mlab.sh) # Last updated: 2025-12-30 Contact: mailto:security@mlab.sh Expires: 2026-12-30T00:00:00Z Preferred-Languages: en, fr # ------------------------------ # ❌ UNAUTHORIZED SECURITY TESTING # ------------------------------ Unauthorized security testing, including but not limited to: - Penetration testing - Vulnerability scanning - Fuzzing - Brute-force attacks - Exploit attempts - Denial of Service (DoS/DDoS) - Automated scanning tools is STRICTLY PROHIBITED on this infrastructure. This policy applies to: - mlab.sh - all subdomains (*.mlab.sh) - all associated APIs, services, and infrastructure No implicit or explicit authorization is granted for any form of security testing. # ------------------------------ # ⚖️ LEGAL NOTICE # ------------------------------ Any unauthorized testing or attack activity may be: - Logged and monitored - Reported to hosting providers and relevant authorities - Prosecuted under applicable laws Testing without prior written authorization is considered illegal. # ------------------------------ # 📩 RESPONSIBLE DISCLOSURE # ------------------------------ If you believe you have discovered a legitimate security issue WITHOUT actively exploiting it, you may report it responsibly via: Contact: mailto:security@mlab.sh Please include: - A clear description of the issue - Steps to reproduce (non-intrusive) - Proof of concept ONLY if explicitly requested Do NOT exploit vulnerabilities. Do NOT access data you are not authorized to access. # ------------------------------ # 🛑 SAFE HARBOR # ------------------------------ There is NO safe harbor for unsolicited testing. Only explicitly authorized security assessments, covered by a written agreement, are permitted.