Acceptable use policy.
Short, and enforced. Not asking who you are only works if the rules about what you do are unambiguous.
1. Why this exists
We do not ask our customers who they are. That is a deliberate position and we defend it: an identity check stops no determined abuser and excludes a great many legitimate people who reasonably do not want to hand a passport to a hosting company.
The price of that position is this document. A provider that asks nothing and enforces nothing is not privacy-respecting — it is a convenient place to attack people from, and it earns the reputation it gets. So the rules below are short, and they are enforced the same way whatever you pay us.
2. Never, in any circumstance
These end a term immediately, without notice, without refund, and without an invitation to explain.
- Material depicting the sexual abuse of children. Reported to the relevant authority in every case.
- Operating a botnet, or command-and-control infrastructure for one.
- Denial-of-service traffic directed at any system, at any volume, for any stated reason including testing.
- Content produced to incite violence against a person or an identifiable group.
3. Not allowed
These get a report, a deadline and a suspension if they are not resolved. Repeated or deliberate breach ends the term without refund.
- Attacking systems you do not own — intrusion attempts, exploitation, credential stuffing, brute forcing.
- Scanning at scale, whether for open ports, vulnerable services or credentials.
- Unsolicited bulk mail, whether sent from the machine or advertising a service hosted on it. Outbound port 25 is closed by default for exactly this reason.
- Phishing pages, credential harvesting, and fraud infrastructure of any kind.
- Hosting or distributing malware, including as a "sample" repository without access control.
- Circumventing the resource limits of another provider using our machines as an intermediary.
- Anything a court with jurisdiction over us has ordered us to stop hosting.
4. Explicitly allowed
We are asked about all of these, and the answer is yes. Listing them saves everyone an exchange, and it means nobody has to guess whether an unusual-looking workload is going to cause trouble.
- Any model you like, and anything you generate with it. We do not inspect disks and we do not police model weights or outputs. What you produce on your own machine is yours.
- Training on data you have the right to use. Whether you have that right is between you and whoever holds it; we do not audit datasets.
- A VPN, a proxy or a Tor relay for your own use. Running an exit node is a conversation — see clause 5 — not an automatic refusal.
- Scraping public pages at a reasonable rate, respecting the target's own limits. Scraping aggressive enough to amount to a denial of service is clause 3.
- Cryptocurrency nodes, validators and wallets. Mining is clause 5, for a thermal reason rather than a moral one.
- Adult content that is legal where it is hosted and involves consenting adults.
- Security research against systems you own or are authorised to test.
- Being anonymous. That we do not know who you are is not evidence of anything and we will never treat it as such.
5. Ask first
Not prohibited, but tell us before you start. Every one of these is fine in some form and a problem in another, and the difference is easier to establish in advance than at two in the morning.
- A Tor exit node. Possible in some of our sites and not others, because of the abuse volume it attracts to a shared range. Ask which.
- Sustained cryptocurrency mining. The concern is thermal and electrical, not ideological: a rack held at maximum power draw indefinitely affects the machines beside it, and some suites can take it while others cannot.
- Sending mail at volume from the machine. Port 25 is closed by default; we will open it for a genuine use and want to know what it is first.
- Public DNS resolvers, open NTP or similar — anything that can be recruited into an amplification attack. Fine when correctly configured, and correctly configuring it is the conversation.
- Reselling machines to your own customers. Allowed, provided you handle your customers' abuse reports and answer ours within our deadlines.
6. Network conduct
- Your port is unmetered and you may hold it at line rate. We will only ever raise it if one machine is degrading the shared uplink for everyone else in the suite.
- Do not spoof source addresses. Ever, for any reason.
- Do not announce address space that is not yours, and do not attempt to. We do not run BGP sessions with customers, so there is no legitimate route to try.
- Keep your machine patched. A compromised server that attacks third parties is your responsibility whether or not you intended it, and "I was hacked" is an explanation rather than an excuse.
- Respond to abuse reports we forward. Silence is what turns a solvable incident into a suspension.
7. How we enforce it
The same sequence every time, whoever the customer is and whatever they pay us. The full version, with timings, is on the abuse page.
- Active harm is stopped first. Outbound denial of service, mass scanning, an intrusion in progress: the port is filtered or cut immediately, and we talk to you afterwards. The order of those two steps is not negotiable.
- Everything else gets a report and a deadline, normally 24 hours. Most reports turn out to be a compromised machine rather than a deliberate act, and we treat those two differently.
- No answer, or an answer that does not resolve it, and the machine is suspended. Your data is untouched while it is suspended, and the term keeps running.
- Repeated or deliberate breach ends the term without refund.
- We tell the reporter the outcome, never the identity of the customer. That requires a valid legal order, and it is the same answer we would give about you.
8. If you disagree
Say so. A suspension we got wrong is a suspension we want to reverse, and we would rather be told quickly and rudely than slowly and politely.
If you think a report about your machine is mistaken, tell us what you believe actually happened and give us something we can check. Addresses change hands between tenants, timestamps get misread, and reports are sometimes simply wrong. We would much rather find that out from you than act on it and be right about nothing.
Related pages
- Report abuseWhat is prohibited on gpuserver.io, how to report something coming from one of our addresses, what we do with a report, and how long each step takes.
- Terms of serviceThe contract between you and gpuserver.io: what we provide, what you pay, how a term ends, refunds, suspension, liability — written to be read, not skimmed.
- Privacy policyThe complete list of data gpuserver.io holds, why each item exists, how long it survives, and what happens when someone asks us for it. It is a short list.
- NetworkUnmetered ports up to 25 Gbit/s, two carriers and an IX per site, always-on DDoS filtering, routed IPv6 — and the four things we do not offer, stated up front.