Acceptable use policy

You have root, and we do not watch what you run. That freedom has a short list of limits, and this is it. The same rules apply whether you bought as a person or as a company.

In effect from 31 Jul 2026

1. What this covers

This policy forms part of the terms of service and applies to every workspace, on both the consumer and the business track. It is a separate document so that it can be updated as abuse changes, without reopening the whole agreement.

2. What you may not do

You may not use a workspace to:

  • mine cryptocurrency, or run any other proof-of-work computation;
  • port scan, brute-force, vulnerability scan, or penetration test any system you do not have written permission to test;
  • take part in a denial-of-service attack, run botnet command-and-control, or amplify traffic at a third party;
  • build or host malware, ransomware, spyware, phishing infrastructure, or credential-stuffing tooling;
  • send spam or bulk unsolicited email, or run an open mail relay;
  • host or distribute child sexual abuse material, or content inciting violence or terrorism, or anything else that is illegal where it is delivered;
  • run pirated or cracked software, or model weights obtained in breach of their licence;
  • infringe anyone's intellectual property;
  • resell, sub-license, or share the workspace with third parties as your own hosting product;
  • circumvent resource limits, rate limits, or platform controls;
  • do anything in breach of EU, US, UK, or UN sanctions and export controls.

3. Securing your own workspace

You are responsible for securing your workspace, including SSH credentials, firewall configuration, and keeping its software up to date. Where your plan has us apply the operating system’s security updates — terms section 7 — that covers those updates and nothing else. You must not negligently permit your workspace to be used for any prohibited purpose.

This is not a formality. The most likely incident on a product like this is not someone deliberately attacking anyone — it is a workspace with a weak password that gets taken over and used to attack someone else. From the outside that traffic is yours. A compromised workspace may be suspended immediately, without notice and without refund, and we will tell you why as soon as we have done it.

4. Where we cannot sell

We cannot provide a workspace to anyone in, or ordinarily resident in, a country or territory under comprehensive sanctions. Today that means Belarus, Cuba, Iran, North Korea, Russia and Syria, along with Crimea and the non-government-controlled areas of Donetsk, Luhansk, Kherson, and Zaporizhzhia.

This is not a restriction we chose or can waive. It applies to us and it applies to the infrastructure we rent, and a breach of it does not risk one account — it risks the upstream relationship every workspace we run depends on. You must not use a workspace on behalf of, or for the benefit of, anyone in those territories.

5. We do not monitor your workspace

You have full root, and what is on your workspace is not visible to us in the ordinary course. We do not scan it, index it, or read it, and we have no system that looks at your files. That is a deliberate design choice and not an oversight.

It follows that we do not know about a problem until someone tells us. Where an abuse complaint, an infrastructure provider, or a legal request requires it, we reserve the right to inspect a workspace, and to preserve evidence, to the extent needed to deal with the specific issue.

6. What happens if this policy is broken

We may suspend or terminate your workspace immediately and without prior notice where we reasonably believe this policy has been breached, where an infrastructure provider, law enforcement, or applicable law requires it, or where continued operation risks harm to our network or to other customers.

No refund is payable on termination for a serious breach. You will reimburse us for costs, fines, or claims we incur as a result of your use of the service.

For something minor or ambiguous we would rather ask you about it first, and normally will. For something actively causing harm we act first and explain immediately afterwards.

7. Reporting abuse

If a workspace of ours is causing you a problem, write to [email protected] with the IP address, timestamps with a time zone, and any logs you can share. That address is read by a person, and reports about traffic in progress get priority.