Liberty Security Services Liberty Security Services AS21990Autonomous System

Policy

Abuse Handling Policy

Liberty Security Services, LLC — AS21990

How we receive, triage and act on reports of abuse originating from 206.109.108.0/23 or from AS21990.

Where to send a report

abuse@as21990.net — for traffic coming out of our address space: spam, phishing, scanning, compromised hosts, attack traffic.

This is also the registered abuse contact for AS21990 and for the prefix in ARIN's Whois, so an automated reporting system reaches the same desk a person does. You do not need to find this page first.

If it is happening right now, use noc@as21990.net instead — an attack in progress, a routing incident, anything affecting live traffic. That address reaches the operations desk directly, and outside staffed hours it reaches the engineer on call. abuse@ does not.

What to include

A report we can act on without a second exchange contains:

We accept reports in English, in plain email. There is no form and no ticket portal to register for.

What we commit to

abuse@ is monitored during staffed hours, 07:00–21:00 Eastern. Reports are triaged by severity: traffic actively harming a third party is dealt with ahead of a spam complaint, and we will say so rather than work a queue in order.

We publish no acknowledgement or resolution times. That is deliberate. A published target that is routinely missed is worse than no target at all, and we have not measured ours — the volume that would tell us what we can actually sustain does not exist yet. What we commit to is that a report reaches a person, gets read, and gets acted on according to what it is.

If a target matters for your reporting process, ask and we will tell you what we are currently doing rather than what we would like to be doing.

Security vulnerabilities in infrastructure we operate are handled separately, and those do carry published response commitments — see the Vulnerability Disclosure Policy.

How a report is handled

1. AcknowledgeWith a reference you can quote back to us
2. IdentifyEstablish which customer or system held the address at the time stated. This is the step your timestamp makes possible.
3. NotifyPass the evidence to the responsible party with a remediation deadline
4. VerifyConfirm the activity has actually stopped, rather than taking an assurance that it has
5. EscalateWhere it has not — see below
6. CloseTell you the outcome, where we are able to

We do not disclose customer identity to reporters. We act as the intermediary. If you need identity rather than remediation, that is legal process, not an abuse report — see below.

Escalation and disconnection

Where abuse continues after notice, or where the activity is severe enough that notice-and-wait is the wrong response, we may:

Disconnection is a last resort for ordinary abuse and requires management approval. It is not a last resort where activity is causing active harm to third parties: an attack in progress may be filtered immediately and discussed afterwards. Actions taken under this policy remain subject to the customer's service agreement.

Abuse directed at us

Reports about attacks against AS21990's own infrastructure are welcome at noc@as21990.net. If you are the one attacking us, we are not going to email you about it.

What this policy is not