The principle
The line is active harm to third parties, not offensiveness, controversy or commercial inconvenience. We do not scan your storage, inspect your traffic or profile what you run, so enforcement is complaint-driven and evidence-driven. That is the only approach compatible with not surveilling customers.
Absolutely prohibited
These result in immediate termination without notice, and CSAM is reported to the appropriate authority.
- Child sexual abuse material, in any form, without exception
- Malware command-and-control, ransomware infrastructure, exploit kits, botnet controllers
- Phishing, credential harvesting, and impersonation of financial institutions or public bodies
- Denial-of-service attacks, port scanning at scale, and any attack originating from your instance
- Unsolicited bulk email, and hosting infrastructure that supports it
- Trafficking in stolen credentials, payment data or personal records
Prohibited for platform reasons
These are not moral judgements; they degrade the service for everyone on the same hardware.
- Proof-of-work mining on shared infrastructure
- Deliberate resource exhaustion designed to affect neighbouring instances
- Open relays, open resolvers and unauthenticated proxies, which are recruited into amplification attacks
Explicitly permitted
Listed because other providers commonly prohibit them, and because it is more useful to know what is allowed than to guess.
- VPN endpoints and proxy servers, personal or commercial
- Tor middle relays and bridges anywhere; exit relays in approved jurisdictions with a published abuse contact
- Web scraping and crawling of lawfully accessible public data at reasonable rates
- Adult content that is lawful in the jurisdiction hosting it and involves only consenting adults
- Cryptocurrency nodes, validators, RPC endpoints and trading infrastructure
- iGaming and betting platforms where properly licensed
- Security research and penetration testing with written authorisation from the target owner
- Reselling and white-labelling of our infrastructure as your own product
- Mail servers, including bulk mail to recipients who opted in
How complaints are handled
Complaints are triaged by evidence, not by volume. Automated copyright notices sent to non-US locations are forwarded to you for information and no action follows, because the DMCA procedure has no application outside the United States. Reports of active harm receive a response within hours.
You will always receive the complaint and a stated window to act — normally 72 hours — unless the harm is ongoing and severe. We never disclose customer identity in response to an abuse complaint, because we hold none.
Suspension
Suspension is reserved for active, ongoing harm. When we suspend, network access is cut but storage is preserved and you retain console access to retrieve your data. We do not use deletion as an enforcement tool.
Sanctions
We do not provide service to jurisdictions or persons subject to comprehensive international sanctions. This is a legal constraint on us as a Seychelles company with international transit relationships, not a customer-identification requirement.
OnionVPS Systems L.L.C., Victoria, Mahé, Seychelles. Questions about this document: [email protected]. This page is general information, not legal advice.