This is a different origin from LabMart. It runs on its own EC2 instance behind its own ALB and CloudFront distribution, but is protected by the same WAF web ACL.
Try the WAF against this domain too:
/secret → blocked by uri-block-secret
?q=evil → blocked by evil-string
?q=<script> → blocked by the XSS / Core rule set