Spotify agrees on security researching as long as it's not disrupting the service. Any disrupting analysis method is forbidden and I would not proceed in auditing something without permission before having a security audit contract signed by the company operating the service.