Law & jurisdiction

What content is not allowed on your servers?

Short answer

Child sexual abuse material, which we report to the appropriate authority. Malware command-and-control, ransomware infrastructure and exploit kits. Phishing and credential harvesting. Spam and unsolicited bulk mail. Attacks originating from your instance. Content illegal in the jurisdiction hosting it. Everything else lawful is permitted, including content other providers refuse.

The line is active harm to third parties, not offensiveness, controversy or commercial inconvenience. Political speech, security research, adult material that is lawful where it is hosted, cryptocurrency infrastructure, privacy services, competitive intelligence and journalism are all normal workloads here.

We do not scan your storage, inspect your traffic or profile what you run. Enforcement is complaint-driven and evidence-driven, which is the only approach compatible with not surveilling customers.

  • Prohibited: CSAM, malware C2, ransomware, phishing, spam, outbound attacks
  • Prohibited: proof-of-work mining on shared hardware, for neighbour impact rather than ideology
  • Permitted: VPNs, Tor relays and bridges, scraping of public data, adult content lawful in the host jurisdiction, security research with written authorisation, iGaming where licensed
  • Exit relays: permitted in approved jurisdictions with a published abuse contact