OpenAPI ↗

DATA & SAFETY

Acceptable use & abuse response

Protect customers and the infrastructure from abusive workloads.

Draft policy · Enforcement operations required before launch

Prohibited activity

The intended service prohibits unlawful exploitation material, malware distribution, unauthorized access, credential theft, fraud, harassment and attacks on networks. Customers must have authority for the websites, systems and data their agents access.

Containment before reassignment

On a credible abuse signal, revoke the relevant access, quarantine the affected environment and restrict staff access. Never give an unreviewed or partly cleaned machine to another customer. Do not send questionable images through ordinary support tickets or unnecessary logs.

Detection limits

Network controls, malware scanning, known-content matching and human review can reduce abuse. They cannot guarantee that an unrestricted computer never creates or stores prohibited material. Encrypted files, previously unknown material and false positives require a considered response process.

Preservation and reporting

Do not make “delete everything immediately” the universal abuse response. Applicable law may require reporting or preservation after discovery of particular material. The operator must establish jurisdiction-appropriate procedures with qualified advice. For the US framework, see NCMEC's provider guidance.

Recovery

Release a quarantined host only after authorized review, completion of any preservation requirements, validated sanitization and a clean readiness check. Store audit evidence of the decision without copying the underlying harmful content into routine records.