Acceptable Use Policy
DRAFT — under review, not yet in effect. This document has not been finalized and does not yet govern use of the service.
This Acceptable Use Policy ("AUP") covers what you may and may not do with an OpenAgent box. It is part of the Terms of Service. Your boxes run on cloud infrastructure we operate, so abuse from your box can put our account and other users at risk. When you break these rules, we act.
The core rule
Don't do anything that harms the platform, other users, or third parties. Everything below is a specific case of that rule.
Prohibited uses
You may not use a box to do, host, facilitate, or attempt any of the following:
- Spam — sending, proxying, or serving unsolicited bulk or commercial messages.
- Cryptomining.
- Security testing you're not authorized to run — network or application scanning, phishing, or penetration testing against systems you do not own or have explicit written permission to test.
- Copyright infringement — piracy, torrents, unlicensed mirrors, or bots built to violate others' rights.
- Abusive link-shortening or redirection services that generate abuse complaints.
- Violent or harassing content — including doxxing and non-consensual intimate imagery ("revenge pornography").
- Malware and attacks — distributing malicious code, running botnet command-and-control, or launching denial-of-service (DoS/DDoS) attacks.
- Unauthorized access — credential stuffing, brute-forcing, or accessing accounts, data, or systems you have no right to.
- Child sexual abuse material (CSAM). Zero tolerance. We remove it, terminate the account immediately, and report it to the authorities.
- Illegal activity of any kind under applicable law.
- Sanctions and export-control violations — use by sanctioned persons or from embargoed jurisdictions, or to move controlled technology unlawfully.
- Evading limits — bypassing usage caps, rate limits, credit requirements, or signup controls.
- Re-reselling your box — you may not resell, sublicense, or hand a further third party direct access to your box or your OpenAgent account.
Several of these flow down directly from our own infrastructure provider's rules, which bind us and therefore bind you — see the Terms of Service.
Resource and abuse limits
Boxes run behind operational limits to keep the platform healthy: a cap on how many boxes one account can run, rate limits on provisioning and signups, and a prepaid-credit requirement before a box exists. By default a box has open outbound internet access, but its cloud-metadata endpoint and other users' boxes are always blocked. Deliberately probing, overloading, or working around these limits is itself a violation. Exact limits are set operationally and may change.
What happens when you break these rules
We respond proportionately, and we reserve the right to act immediately and without notice in serious cases (such as CSAM, an active attack, or a legal demand):
- Warning — where the situation allows, we tell you what's wrong and give you a chance to fix it.
- Suspension — we suspend the offending box or your account. A suspended box keeps its disk but stops running.
- Termination — for serious or repeated abuse we destroy your boxes and close your account. Prepaid credits tied to abuse are not refunded.
Reporting abuse
See something being run on OpenAgent that breaks these rules? Email support@openagent.example.