The golden rule
One rule above allOnly test what you own or are clearly authorized in writing to test. Everything else in this policy follows from that. If you are not certain you are authorized, do not request the test.
Authorized targets only
You may direct a Test only at an Authorized Target — a system you own, or that you hold current, documented authorization from the owner and operators to test. Before scheduling any Test you must:
- verify ownership of the Target domain through the Service's HTTPS verification;
- hold written authorization covering the specific Target, techniques, and time window;
- obtain any consent required from infrastructure providers (see Section 5); and
- keep that evidence and provide it to us on request.
Domain verification is a safety control, not a grant of authorization. Verifying a domain does not mean you are permitted to test the systems behind it.
Prohibited uses
You must not use the Service to:
- test, disrupt, degrade, or overwhelm any system that is not an Authorized Target;
- conduct a denial-of-service attack, extortion, or any other attack against a third party, or to assist anyone else in doing so;
- target shared or multi-tenant infrastructure in a way that would affect other customers or users of that infrastructure;
- target critical infrastructure, emergency services, healthcare, or systems where disruption could risk safety, without appropriate authorization and safeguards;
- test systems belonging to another party without their authorization, even if you can technically verify a domain;
- use the Service for fraud, harassment, stalking, surveillance, or to violate anyone's rights;
- violate any applicable law, regulation, sanctions regime, or the terms of any third party;
- evade, disable, or attempt to exceed the Service's safety limits, rate ceilings, or verification controls;
- attempt to send raw, spoofed, malformed, or amplified traffic, or to use the Service to deliver malware or unlawful content;
- resell, sublicense, or provide the Service to third parties as a testing service without our written agreement; or
- misrepresent your identity, authority, or authorization.
Third-party infrastructure
If your Target is hosted, fronted, or protected by another provider — for example a cloud platform, CDN, hosting company, or DDoS-mitigation service — the traffic the Service generates may reach or affect that provider's systems.
Many such providers require advance notice or explicit authorization for load or penetration testing. It is your
responsibility to review and comply with those policies and to obtain any permissions required before you schedule a Test. Failing to do so is a breach of this policy.
Your operational responsibilities
- Schedule Tests responsibly and inform your own stakeholders, on-call staff, and any managed-service or mitigation providers in advance.
- Understand that testing may degrade or interrupt the Target and dependent systems; maintain backups and a rollback plan.
- Monitor a running Test and stop it if you observe unacceptable impact.
- Ensure that any personal data affected by, or collected during, a Test is handled lawfully.
Reporting abuse
If you believe the Service is being used against a system you operate, or otherwise in breach of this policy, contact us immediately at
[email protected] with relevant details (such as the affected domain, timestamps, and observed traffic). We investigate reports of abuse and act on them.
Reporting security vulnerabilities
If you discover a vulnerability in the Service itself — the portal, the marketing site, or the health and worker infrastructure — please report it privately to
[email protected]. Give us a reasonable opportunity to investigate and remediate before any public disclosure, and while testing do not access, modify, or exfiltrate data belonging to us or to other customers, or degrade the availability of the Service. A machine-readable contact is published at
/.well-known/security.txt.
Enforcement
We may investigate suspected violations and take any action we consider appropriate, including cancelling a scheduled or running Test, suspending or terminating your access, removing content, and preserving and disclosing information
where required by law or to protect the Service or third parties. We may cooperate with law-enforcement and affected infrastructure providers. Serious or repeated violations will result in permanent termination. Enforcement
action does not entitle you to a refund.
Legal backdrop
Directing traffic at systems without authorization can constitute a criminal offence. In the Netherlands this includes computer intrusion (computervredebreuk, Article 138ab of the Dutch Criminal Code) and disrupting
the availability of a computer system (Article 161sexies). Comparable laws exist in most jurisdictions (for example the UK Computer Misuse Act and the US Computer Fraud and Abuse Act). This summary is provided for awareness
only and is not legal advice.
← Back to ddos-simulation.com