Effective July 27, 2026

Acceptable Use Policy

Mirai supports serious security work with reduced filtering, but every action must remain authorized, scoped, and accountable.

1. Core rule

Use Mirai only for lawful activity and only against systems, data, accounts, and environments you own or are explicitly authorized to test.

Authorization must cover the target, technique, time period, and impact of the work. A public target, exposed service, or unrestricted Mirai profile is not permission.

2. Security work we support

The following work is welcome when it is authorized and performed with appropriate safeguards:

  • Penetration tests, security audits, red team exercises, and vulnerability assessments.
  • Bug bounty research performed within the published program scope.
  • Secure code review, configuration review, threat modeling, and remediation.
  • Malware analysis, reverse engineering, exploit analysis, and detection engineering in a controlled environment.
  • Security education, lab exercises, incident response, forensics, and defensive research.
  • Writing findings, proof of concept documentation, remediation guidance, and retest reports.

3. Prohibited activity

You must not use Mirai to perform or materially enable:

  • Unauthorized access, exploitation outside an approved scope, or continued access after authorization ends.
  • Credential theft, phishing, impersonation, account takeover, secret extraction, or unauthorized data exfiltration.
  • Ransomware, destructive malware, botnets, unauthorized persistence, or payload deployment against third parties.
  • Denial of service, destructive testing, resource abuse, or disruption beyond an explicitly approved test plan.
  • Sale or distribution of stolen data, unauthorized access, malware services, or instructions intended for immediate harm.
  • Surveillance, stalking, doxxing, harassment, sexual exploitation, or abuse of minors.
  • Evasion of safety, monitoring, or access controls for the purpose of harming another person or concealing prohibited activity.

4. Unrestricted profiles

An approved unrestricted profile reduces Mirai level safeguards so qualified users can discuss and analyze sensitive security techniques with fewer blanket refusals.

It does not remove this policy, legal duties, target authorization, provider controls, rate limits, or our right to investigate abuse. You may be asked to provide organization, scope, or authorization evidence.

5. Data and operational safety

Minimize personal data, credentials, production secrets, and customer content in prompts. Use test data, redact evidence where possible, and follow the data handling requirements of the system owner.

Use safe proof methods. Do not cause more impact than needed to demonstrate a finding, and stop if testing creates unexpected harm or instability.

6. Vulnerabilities in Mirai

If you find a vulnerability in Mirai or satuapps infrastructure, stop before accessing other users' data or causing disruption and report it to hi@satuapps.com with enough detail to reproduce safely.

Good faith research that follows this policy will be reviewed constructively.

7. Enforcement and appeal

We may limit output, revoke unrestricted status, suspend credentials, preserve relevant records, or terminate access when we reasonably believe this policy has been violated or the service is at risk.

Context matters. Discussion, education, and defensive analysis are not treated the same as unauthorized action. You may appeal an enforcement decision by contacting hi@satuapps.com with the account and scope details.