Report abuse.
We do not ask our customers who they are. That makes it more important, not less, that we act on what their machines do. Here is what we prohibit, how to tell us, and what happens next.
- < 4 hto acknowledge a report
- 24 hfor the customer to respond
- < 1 hif there is an active attack
- 1form, no account needed
How to report
Reports reach the same people who rack the machines, and a report about an attack in progress is read within the hour at any time of day.
What we need from you
A report without these is not something we can act on, however serious the allegation. We do not have a way to search for “a machine doing something bad”; we look up an address at a time.
What happens next
The same sequence every time, whoever the customer is and whatever they pay us.
WITHIN 4 HOURS
Acknowledged, and matched to a machine
You get the reference immediately and a human answer within four hours. We match the address and timestamp to a specific machine before doing anything else — including before contacting the customer.
IMMEDIATELY, IF IT IS ACTIVE
An attack in progress is stopped first
Outbound denial of service, port scanning at scale, or an active intrusion attempt: the port is filtered or cut immediately and we talk to the customer afterwards. The order of those two steps is not negotiable.
WITHIN 24 HOURS
The customer is asked to answer
For everything else, they get the report and a deadline. A compromised machine being cleaned up is a different situation from a machine doing it on purpose, and most reports turn out to be the first.
AFTER THE DEADLINE
Suspension, then termination
No answer, or an answer that does not resolve it, and the machine is suspended. Repeated or deliberate abuse ends the term without refund.
WHEN IT IS DONE
You are told the outcome
Whether the machine was suspended, cleaned, or found not to be the source. We will not tell you who rented it — that requires a valid legal order, and it is the same answer we would give about you.
What is prohibited
The full text is the acceptable use policy. In plain terms:
Attacking other systems
- Denial of service, in any form or volume
- Port scanning or brute forcing at scale
- Intrusion attempts against systems you do not own
- Operating a botnet or command-and-control
Abusing others
- Unsolicited bulk mail, from here or advertised here
- Phishing pages and credential harvesting
- Malware hosting or distribution
- Fraud infrastructure of any kind
Content we will not host
- Material depicting the sexual abuse of children
- Content produced to incite violence against people
- Anything a valid court order requires us to remove
The first of these ends a term immediately, is reported, and is the one rule where no explanation is invited.
What is not
We get reports about all of these, and we decline them. Saying so publicly saves everyone the exchange.
Running a model we would not run. What you generate on your own machine is yours. We do not inspect disks and we do not police model weights.
Scraping public web pages at a reasonable rate, in a way that respects the target's own limits. Aggressive scraping that amounts to a denial of service is a different matter.
Running a VPN, a proxy or a Tor relay for your own use. An exit node is a conversation, not an automatic refusal.
Being anonymous. That we do not know who a customer is is not evidence of anything, and we will not treat it as such.
A commercial dispute with someone. We are not a venue for it, and we cannot adjudicate it.
Content you disagree with, where no law is broken and nobody is being attacked. We are a hosting provider, not an arbiter of opinion.
Formal legal requests
Send them through the same form with the subject set to “Legal or compliance”. What follows applies whoever is asking.
- We answer valid orders from a court with jurisdiction over us. We do not answer informal requests, however officially they are phrased, and we do not treat an email signature as an order.
- We hand over only what we hold. That is set out in the privacy policy and it is a short list: an email address, invoices, and the IP addresses assigned to a machine. There is no identity document to produce because we never asked for one.
- We do not have a login inside your machine. No order can compel us to produce what is on your disks, because we cannot reach it. What we can be compelled to do is hand over the hardware, and that is worth knowing when you decide what to encrypt.
- We tell the customer, unless we are forbidden to. If a request comes with a gag we comply with the gag. If it does not, we say what was asked and by whom.
Where we stand
This page exists because the two halves of what we sell only work together.
We do not ask our customers who they are. That is a deliberate position and we defend it: an identity check protects nobody from a determined abuser and it excludes a great many legitimate people who simply do not want to hand a passport to a hosting company.
The price of holding that position is that we have to act, quickly and without excuses, on what a machine actually does. A provider that asks nothing and does nothing is not privacy-respecting — it is just a convenient place to attack people from, and it deserves the reputation it gets.
So: no identity check, no exceptions, at any spend. And a report with an address and a timestamp gets acted on the same day, at any spend. Those two sentences are the whole policy.
Something coming from one of our addresses?
Include the address and the time window; those two decide whether we can act at all.
Related pages
- Acceptable useWhat you may and may not run on a gpuserver.io machine, what is explicitly allowed, what to ask about first, and the procedure when a machine crosses the line.
- Privacy policyThe complete list of data gpuserver.io holds, why each item exists, how long it survives, and what happens when someone asks us for it. It is a short list.
- Terms of serviceThe contract between you and gpuserver.io: what we provide, what you pay, how a term ends, refunds, suspension, liability — written to be read, not skimmed.
- About usWho runs gpuserver.io, why we buy the hardware instead of reselling it, and the four rules we do not bend — including the ones that cost us sales.