RESPONSIBLE TESTING

Acceptable use

Use this service only for systems you own, administer or are authorised to test. The toolbox is intended for troubleshooting, defensive security, network operations, service validation, education and legitimate research.

Prohibited activity

  • Attempting to test private, loopback, reserved or link-local systems through the public service.
  • Using repeated requests to create load, evade rate limits, harass another party or disrupt a service.
  • Using results to support unauthorised access, exploitation, credential attacks or privacy invasion.
  • Automating the public interface without written permission from 39D.
  • Misrepresenting a diagnostic result as proof of wrongdoing or ownership.

Public-tool limitations

Tests are deliberately constrained. Port checks use a small allow-list, command durations are capped, HTTP redirects are revalidated and persistent monitors can only be added by the site administrator. These controls are part of the product rather than defects to be bypassed.

Enforcement

Requests may be rate limited, logged, blocked or investigated when activity appears abusive. Access can be withdrawn without notice to protect the service and third parties.