New B200 spot capacity is live in US East from $1.69 per GPU-hour. See availability
Legal

Acceptable use policy

What you may and may not run on our GPUs, and what happens when someone crosses the line.

Version of 15 September 2026 · ask about a clause

1. The rule in one line#

Do not use our machines to harm people or other systems, and do not use them for something the law where you or we operate forbids. Everything below is that sentence, made specific enough to enforce fairly.

2. Never allowed#

  • Child sexual abuse material, in any form, generated or stored. This ends the account immediately and is reported to the authorities.
  • Malware: writing, hosting, distributing or controlling it — including command-and-control infrastructure, ransomware and credential stealers.
  • Intrusion: unauthorised access attempts against systems you do not own or have written permission to test.
  • Denial of service: originating, coordinating or amplifying attacks, including stress-testing services that are not yours.
  • Spam and phishing: bulk unsolicited messaging, impersonating a person or an organisation, or hosting a page designed to collect someone else's credentials.
  • Fraud: card testing, account-takeover tooling, or automated abuse of a third party's service.
  • Content that is illegal where it is served, including material that infringes someone else's rights when you have been told and have not acted.
  • Sanctioned parties and destinations, or any use that breaches export control rules applicable to the hardware.
  • Targeted harassment, doxxing, or building systems whose evident purpose is to harm identifiable people.

3. Network conduct#

  • Do not scan, probe or brute-force hosts you do not control.
  • Do not spoof addresses, forge headers, or hide the origin of traffic you send.
  • Do not run open relays, open proxies or open resolvers that can be abused by others.
  • Do not deliberately saturate shared links. Instances share network capacity; using all of it is a form of denial of service against your neighbours.
  • Outbound mail is not a feature of the platform. If you need to send mail, use a provider built for it.

4. Allowed, with a word first#

Some lawful workloads change how we plan capacity. They are allowed, and we ask that you tell us in advance through the contact form or a ticket, so that nobody is surprised:

  • Sustained maximum-power workloads, including cryptocurrency mining, on the on-demand and reserved tiers. On spot capacity they are not permitted: they distort the pool everyone else shares.
  • High-volume outbound crawling, which can look identical to an attack from the outside.
  • Public-facing services with a large user base, so that we know a node failure will affect more than you.
  • Anything involving regulated data — health, financial or biometric — so that we can tell you honestly whether the platform is appropriate. Today we hold no compliance certification; see trust & security.

5. Security testing#

Testing systems you own, from your own instance, is fine. Testing ours is welcome under the disclosure policy, with its limits: no denial of service, no touching other customers, no social engineering. Testing a third party without written authorisation is not fine anywhere, and is the fastest way to lose an account.

6. What we do about breaches#

6.1 Our first move is proportionate: for something ambiguous, a message; for something active and harmful, the instance is suspended immediately and we talk afterwards.

6.2 Repeated or deliberate breaches end the account. Credit on an account closed for a breach of this policy is not refunded.

6.3 We do not act on volume of complaints, and we do not act on an anonymous assertion with no evidence. We do act on logs, headers, timestamps and captures.

6.4 Where we are legally required to preserve or hand over material, we comply with valid, properly served requests — and no more than that.

7. Reporting#

Report abuse coming from our address space through the abuse form. Include the address or instance reference and a timestamp in UTC; that is what makes a report actionable. We acknowledge within 12 hours and come back to you on the outcome.


The other documents#