- Zero tolerance, immediate termination, no appeal: CSAM, botnets & C2, credential phishing.
- Prohibited: spam, network attacks, scanning or exploiting third parties, mining that steals CPU from neighbors, malware distribution.
- Explicitly allowed under stated conditions: Tor relays everywhere, Tor exits in Iceland and Switzerland, VPN/proxy, seedboxes on unmetered plans, legal adult content (not Russia), mirrors, game servers.
- Abuse reports through the Abuse department in the ticket desk are read by a human. Escalation runs warning → suspension → termination; zero-tolerance items skip the ladder.
- We act on valid court orders from the hosting jurisdiction and on verified abuse. Nothing else moves us.
01 Scope
This policy applies to every service on every plan in every location, and it is part of the Terms of Service. Breaking it risks the service. Breaking it egregiously, or repeatedly, risks the account.
Two principles frame everything below. First: we do not monitor server contents — enforcement is complaint- and evidence-driven, because monitoring would require the logs our Privacy Policy promises not to keep. Second: content that is illegal in the jurisdiction where the server physically sits is prohibited. That is the one legal regime we enforce proactively, because it is the one that can reach the rack.
02 Zero tolerance — immediate termination
Three categories end the service and the account on verification, with no warning and no appeal.
Child sexual abuse material
CSAM in any form, in any jurisdiction, discovered by any means. Terminated on verification. We report to the child-protection hotline competent for the hosting jurisdiction — the INHOPE member hotline where one exists — and preserve evidence where that jurisdiction’s law requires it. There is no second server. If this paragraph reads as harsh, it is not harsh enough.
Botnets & command-and-control
Operating C2 infrastructure, participating in a botnet, renting compute to one, or hosting panels, loaders, or staging for one. The abuse desk has seen every excuse in this category; none has ever been true.
Credential phishing
Pages, kits, mailers, or redirect infrastructure designed to harvest other people’s credentials, payment data, or wallet keys. “Security research” phishing of third parties without their written authorization is phishing.
03 Prohibited
Spam and unsolicited bulk email. No UBE, and no supporting it: no bulk-mail relay services for third parties, no list-washing, no snowshoe setups across IPs. Port 25 is filtered by default on every service; it opens on request after 30 days of account age for legitimate mail. A verified spam verdict closes it permanently and counts as a strike against the account. Submission ports (587/465) are open from day one.
Network attacks. Originating denial-of-service attacks, amplification or reflection attacks, or participating in stresser/booter activity. Our 1 Tbps+ edge exists to absorb attacks on you; it is not a license to become the thing it filters.
Port scanning and exploitation of third parties. Scanning networks you do not own or lack written permission to test, brute-forcing credentials, exploiting vulnerabilities in other people’s systems. Authorized security research conducted from your VPS against targets you have permission for is fine — keep the authorization, because if a complaint lands we will ask to see it.
Crypto mining by CPU steal. Mining that exceeds your allocated vCPU — CPU steal from the host or from neighbors on shared nodes — is prohibited, full stop. It is theft of a measurable resource from identifiable victims, and our hypervisor metrics make it trivial to prove. If you want to mine strictly inside your allocation, open a ticket first; on standard shared nodes the answer is no, on dedicated arrangements it can be yes.
Malware distribution. Hosting or relaying malware, exploit kits, droppers, or ransomware infrastructure. Research samples in a controlled, non-routable lab setup: ticket us first so the desk has context.
Fraud and interference. Using our network to defraud third parties, and anything that degrades the node, the network, or other customers’ services — whatever form that takes next year.
04 Allowed, with conditions
Most AUPs in this industry are a list of fears. Ours is also a list of permissions. These workloads are explicitly welcome, under the conditions shown:
| Use | Status | Conditions |
|---|---|---|
| Tor relays (guard / middle) | Allowed | All locations. No conditions beyond this policy. Our abuse desk knows what a relay is — you will not get the form-letter treatment. |
| Tor exit relays | Allowed | Iceland and Switzerland only. Reverse DNS must identify the node as a Tor exit (e.g. tor-exit.your-domain.tld), your contact in the relay descriptor must stay current, and abuse tickets must be answered within 48 hours. |
| VPN & proxy services | Allowed | All locations — the most common workload we host. You remain responsible for what exits your IP; abuse generated by your users counts as your abuse. See the setup guide. |
| Seedbox / torrents | Allowed | Unmetered plans (SV-Pro and above) for sustained heavy use; metered plans within their transfer. Public-tracker DMCA notices are ignored per policy; jurisdiction-illegal content still applies everywhere. |
| Adult content (legal) | Conditional | All locations except Russia, where local law forbids it. 18+ labeling required; age-verification and record-keeping per the hosting jurisdiction’s law. Any drift toward prohibited categories is §02, not a warning. |
| Mirrors (distros, datasets) | Allowed | All locations. If you expect sustained multi-TB egress on a metered plan, tell us — we’ll place you on a node that suits it. |
| Game servers | Allowed | All locations. UDP-heavy workloads are fine. The always-on edge mitigation covers common game-protocol floods. |
| Mail servers | Conditional | Port 25 opens on request after 30 days of account age. Proper rDNS/SPF/DKIM expected. Bulk mail of any kind is §03 spam, however honest the list. |
If your workload is not listed anywhere in this document, the default is that it is allowed. If it is listed as prohibited, the default is that we mean it.
05 Reporting abuse
Reports go through the Abuse department in the ticket desk. Include evidence: full log excerpts with timestamps and timezone, source and destination IPs, and one sentence on what you want us to see. A screenshot of an IP address is not evidence.
Every report is read by a human on the abuse desk — the same engineers who run the network, not a script and not a tier-1 queue. Triage happens the same business day; active attacks move faster than that.
Two expectations to set. We do not confirm outcomes to reporters beyond acknowledging receipt and, where appropriate, closure — customer privacy applies to everyone, including people you report. And reporters who flood the desk with bad-faith complaints (yes, mostly copyright trolls) are rate-limited to the standard reply: valid court order from the hosting jurisdiction.
06 The escalation ladder
Ordinary violations climb a ladder. The severity of the abuse decides how fast we climb it.
| Step | What happens |
|---|---|
| 1 · Warning | A ticket with the evidence and what must change. Typical window to respond: 24–72 hours depending on severity. Most cases end here — most abuse is a compromised WordPress, not a criminal enterprise. |
| 2 · Suspension | Service offline, data intact. Used when warnings are ignored or the abuse is ongoing — a live spam run, an attack in progress. Lifted when you respond and the problem is fixed. |
| 3 · Termination | Repeat violations, refusal to fix, or severity that makes the first two steps pointless. Data is wiped per the ToS timeline. |
The ladder compresses with severity. An active DDoS source does not get a 72-hour warning; it gets a null-route and then a ticket, in that order — the warning period would be someone else’s outage. Zero-tolerance categories (§02) skip the ladder entirely, and the account goes with the service.
07 Law-enforcement requests
We respond to valid court orders issued in the jurisdiction where the affected service runs. Everything else — foreign subpoenas, DMCA notices, police emails from other countries, letters on impressive letterhead — receives the same one-line reply: valid court order from the hosting jurisdiction.
Where local process allows, we challenge or narrow overbroad orders before complying with them. Unless an order legally forbids disclosure, we tell you it exists before we act on it.
What an order can actually obtain is documented honestly in the Privacy Policy: a billing ledger row and your tickets. There is no activity data to seize because none is created.
The warrant canary is updated monthly and PGP-signed. It exists for the things we cannot talk about, and it has been continuous since April 2021.
08 Changes
Material changes to this policy take effect no sooner than 30 days after announcement on the warrant canary page and a site-wide banner — the same mechanism as the Terms of Service. Continuing to run a service after the effective date is acceptance.