All 6 data centres operational

Paid in crypto · No identity check · Root access in under 5 minutes

Trust

Report abuse.

We do not ask our customers who they are. That makes it more important, not less, that we act on what their machines do. Here is what we prohibit, how to tell us, and what happens next.

  • < 4 hto acknowledge a report
  • 24 hfor the customer to respond
  • < 1 hif there is an active attack
  • 1form, no account needed

How to report

Reports reach the same people who rack the machines, and a report about an attack in progress is read within the hour at any time of day.

Send the address and the time window. Those are the two things that decide whether we can act on a report at all — without them there is nothing to look up. Customers report from the console; everyone else should include both in the first message.

What we need from you

A report without these is not something we can act on, however serious the allegation. We do not have a way to search for “a machine doing something bad”; we look up an address at a time.

RequiredThe IP addressOne of ours, exactly as it appears in your logs. This is the only key we can search by.
RequiredA timestamp, with its time zoneUTC preferred. Addresses change hands between tenants, so a report without a time can point at the wrong customer entirely.
Strongly wantedRaw evidenceLog lines, full mail headers, packet counts. Paste them as text — a description of a log is much weaker than the log.
Strongly wantedA way to reach youSo we can come back with questions or tell you it is resolved. It does not have to identify you.
Timestamps matter more than people expect. A term can end and the address be reissued within the hour. A report dated only “last week” may name a machine whose current tenant has nothing to do with it — and acting on it would punish the wrong person while leaving the actual source running.

What happens next

The same sequence every time, whoever the customer is and whatever they pay us.

WITHIN 4 HOURS

Acknowledged, and matched to a machine

You get the reference immediately and a human answer within four hours. We match the address and timestamp to a specific machine before doing anything else — including before contacting the customer.

IMMEDIATELY, IF IT IS ACTIVE

An attack in progress is stopped first

Outbound denial of service, port scanning at scale, or an active intrusion attempt: the port is filtered or cut immediately and we talk to the customer afterwards. The order of those two steps is not negotiable.

WITHIN 24 HOURS

The customer is asked to answer

For everything else, they get the report and a deadline. A compromised machine being cleaned up is a different situation from a machine doing it on purpose, and most reports turn out to be the first.

AFTER THE DEADLINE

Suspension, then termination

No answer, or an answer that does not resolve it, and the machine is suspended. Repeated or deliberate abuse ends the term without refund.

WHEN IT IS DONE

You are told the outcome

Whether the machine was suspended, cleaned, or found not to be the source. We will not tell you who rented it — that requires a valid legal order, and it is the same answer we would give about you.

What is prohibited

The full text is the acceptable use policy. In plain terms:

Attacking other systems

  • Denial of service, in any form or volume
  • Port scanning or brute forcing at scale
  • Intrusion attempts against systems you do not own
  • Operating a botnet or command-and-control

Abusing others

  • Unsolicited bulk mail, from here or advertised here
  • Phishing pages and credential harvesting
  • Malware hosting or distribution
  • Fraud infrastructure of any kind

Content we will not host

  • Material depicting the sexual abuse of children
  • Content produced to incite violence against people
  • Anything a valid court order requires us to remove

The first of these ends a term immediately, is reported, and is the one rule where no explanation is invited.

What is not

We get reports about all of these, and we decline them. Saying so publicly saves everyone the exchange.

Running a model we would not run. What you generate on your own machine is yours. We do not inspect disks and we do not police model weights.

Scraping public web pages at a reasonable rate, in a way that respects the target's own limits. Aggressive scraping that amounts to a denial of service is a different matter.

Running a VPN, a proxy or a Tor relay for your own use. An exit node is a conversation, not an automatic refusal.

Being anonymous. That we do not know who a customer is is not evidence of anything, and we will not treat it as such.

A commercial dispute with someone. We are not a venue for it, and we cannot adjudicate it.

Content you disagree with, where no law is broken and nobody is being attacked. We are a hosting provider, not an arbiter of opinion.

Send them through the same form with the subject set to “Legal or compliance”. What follows applies whoever is asking.

  1. We answer valid orders from a court with jurisdiction over us. We do not answer informal requests, however officially they are phrased, and we do not treat an email signature as an order.
  2. We hand over only what we hold. That is set out in the privacy policy and it is a short list: an email address, invoices, and the IP addresses assigned to a machine. There is no identity document to produce because we never asked for one.
  3. We do not have a login inside your machine. No order can compel us to produce what is on your disks, because we cannot reach it. What we can be compelled to do is hand over the hardware, and that is worth knowing when you decide what to encrypt.
  4. We tell the customer, unless we are forbidden to. If a request comes with a gag we comply with the gag. If it does not, we say what was asked and by whom.

Where we stand

This page exists because the two halves of what we sell only work together.

We do not ask our customers who they are. That is a deliberate position and we defend it: an identity check protects nobody from a determined abuser and it excludes a great many legitimate people who simply do not want to hand a passport to a hosting company.

The price of holding that position is that we have to act, quickly and without excuses, on what a machine actually does. A provider that asks nothing and does nothing is not privacy-respecting — it is just a convenient place to attack people from, and it deserves the reputation it gets.

So: no identity check, no exceptions, at any spend. And a report with an address and a timestamp gets acted on the same day, at any spend. Those two sentences are the whole policy.

Something coming from one of our addresses?

Include the address and the time window; those two decide whether we can act at all.

Sign in

Console, invoices and out-of-band access.

No account yet?

There is no separate sign-up. Your account is created while you place your first order — you choose the email and the password on the payment step, and the console is open by the time the machine is.

Configure a server

Language