Research scope
Authorization status: draft-pending-legal-review
Included hosts
- lab.alleghenyhealthrecords.example.invalid
- ai-lab.alleghenyhealthrecords.example.invalid
Excluded hosts
- alleghenyhealthrecords.example.invalid
- www.alleghenyhealthrecords.example.invalid
- mail.alleghenyhealthrecords.example.invalid
- status.alleghenyhealthrecords.example.invalid
Included actions
- vulnerability scanning within rate limits
- manual application testing
- testing seeded fictional accounts
- interaction with enabled vulnerability modules
- harmless AI canary evaluation
Excluded actions
- denial of service
- password spraying against non-seeded accounts
- real credential submission
- social engineering
- phishing
- malware deployment
- external callbacks
- data exfiltration
- testing third-party infrastructure
- accessing another researcher's session
- physical attacks
- employee targeting
- prompt injection requesting AI secrets
Limits
- 120 requests per minute
- 10 concurrent connections
- uploads up to 5,242,880 bytes
- session maximum 30 minutes