A per-visitor, isolated security lab. A vulnerable target sits beside an attacker shell in your browser, gone in 30 minutes, with an AI coach for every challenge.
Defined as code, rebuilt with one command. A single web server faces the internet. A private control program behind it creates your two throwaway containers, and a separate machine handles monitoring and the public stats page.
Next up: an automated test suite that checks every change before it ships, and an easier way to add new challenges. The goal is a lab that stays reliable and secure on its own, not just on the day it launched.
This is a disposable training lab with no user accounts. It collects as little as possible, and what it does process is for running the lab and keeping it secure — never for advertising, profiling, or sale.
What's processed. A strictly-necessary session cookie routes you to your own containers and is cleared when the session ends. Your IP address is processed transiently to rate-limit session creation (abuse prevention) — kept only as a keyed hash in memory for a few minutes, never stored as a raw address — and may appear in our security monitoring logs, which are retained for a limited period (about 90 days) and then deleted. The lab clears browser storage and cookies on start and stop, so nothing carries between visitors.
The AI guide. If you use the in-lab coach, your messages are sent to our model provider (Amazon Bedrock) to generate replies. Please don't enter personal or sensitive information into the chat.
Why, and for how long. Processing is necessary to provide the lab you requested and to pursue a legitimate interest in security and abuse prevention (GDPR Art. 6(1)(f), Recital 49; CCPA security-purpose). Lab session data is auto-deleted on the 30-minute timer; rate-limit state lives in memory for minutes.
Your choices. To ask what's held about you, or to request erasure or object to processing, email oscarlunatech@gmail.com. Because most data is ephemeral or pseudonymized, there is often little to act on.
This is a free, educational security lab. By launching it you agree to these terms — if you don't, please don't use the lab.
Educational use only. The lab is for learning and demonstration. You may run exploits, tools, and techniques only against the disposable target provided in your own session — never against the host, the platform, other users' sessions, or any system you don't own or aren't explicitly authorized to test.
No abuse. Don't attempt to break out of the session isolation, attack or overload the infrastructure, use the lab to reach third-party systems, mine cryptocurrency, host or distribute content, or do anything unlawful. Sessions are ephemeral, resource-capped, and may be rate-limited or terminated at any time.
Intentionally vulnerable software. The lab deliberately contains insecure software for training, running in an isolated, no-egress environment. Don't rely on it for anything real, and don't enter real or sensitive data into it.
Age. You must be at least 18 years old to use the lab.
No warranty; limited liability. The lab is provided "as is," without warranty of any kind, and may be unavailable or change at any time. To the fullest extent permitted by law, the operator is not liable for any damages arising from your use of it — you use it at your own risk and are responsible for your own conduct.
Questions? oscarlunatech@gmail.com.