Acceptable Use Policy

Skip to main content

Acceptable Use Policy

This policy says what Vallic Cloud may not be used for. It applies to every environment, machine and domain on the platform, to everyone you invite into your account, and to what your own visitors and customers do through your site.

We would rather explain a rule than enforce one. If something here is ambiguous for what you are building, ask us first and we will answer in writing. What we cannot do is treat silence as permission after the fact.

Immediately prohibited

These end an account without a warning step, because by the time we see them the harm is already being done to somebody else.

Attacks on other people's systems

  • Denial-of-service traffic of any kind, whether you generate it or rent it.
  • Port scanning, vulnerability scanning or brute-forcing hosts you do not own — including hosts belonging to another customer of the same provider.
  • Sending packets with a forged source address.
  • Operating command-and-control infrastructure, distributing malware, hosting phishing pages or credential-harvesting sites.
  • Deliberately circumventing the isolation between environments, tenants or machines on this platform.
  • Tampering with audit logs, or attempting to obscure what an account has done.

Material that is illegal in itself

  • Child sexual abuse material. We report this to the authorities and preserve evidence. We do not warn the account holder first.
  • Content that incites violence or terrorism, or that constitutes unlawful hate speech under EU or member-state law.
  • Material that infringes another party's copyright, trademark or database rights, once we have been properly notified.
  • Sale of forged documents, stolen credentials or personal data obtained without consent.

Unsolicited mail

  • Bulk mail to recipients who did not ask for it, however the list was acquired.
  • Mail with forged, disguised or misleading headers, envelope senders or return paths.
  • Operating an open relay, an open proxy, or a mail service that does not authenticate its senders.
  • Harvesting addresses from the web or from any source the addressee did not consent to.

We act on a credible spam report whether or not the mail left our network. A list rented and mailed elsewhere, pointed at a landing page here, is the same conduct.

Not allowed on this platform

These are not necessarily unlawful. They are workloads this platform is not built for, and running them degrades it for everybody else or exposes us to costs we have not priced.

Cryptocurrency mining and adjacent work

Mining, farming, plotting, staking infrastructure and proof-of-work of any kind. It consumes exactly the resource the machine was sold to provide, at a price that only works if somebody else is paying for the hardware.

Workloads that are not a web application

  • Public VPN, proxy, anonymisation services or Tor exit nodes.
  • Public file-sharing, one-click hosting or torrent trackers.
  • Bulk media transcoding, real-time computer vision, distributed compute, or AI training runs that exist to consume the machine rather than to serve a site.
  • Game servers, streaming relays and voice servers.

This is a managed platform for web applications. If your workload is something else, a general-purpose cloud will serve you better and cheaper, and we will say so rather than take the money.

High-risk and safety-critical systems

Vallic Cloud is not designed, tested or certified for use where failure could lead to death, personal injury, or severe environmental damage. Do not use it for the operation of medical devices or life support, aircraft or air traffic control, nuclear facilities, weapons systems, or the real-time control of vehicles or industrial safety equipment.

Business models we will not carry

  • Gambling and betting, unless you hold a licence valid in every jurisdiction you serve and have shown it to us in advance.
  • Pornography and adult content.
  • Sale of prescription medicines, controlled substances, weapons or ammunition.
  • Multi-level marketing, matrix and pyramid schemes, "investment opportunities" promising a return, and lead generation for any of them.
  • Impersonation of a person or organisation you are not.

Automated systems and AI

If your application calls a model, that is your integration and your key. Two rules follow from it.

  • Do not expose credentials — yours or a third party's — to end users, in client-side code, or in a repository we deploy from.
  • Do not use the platform to attack a model provider: prompt injection against somebody else's system, jailbreak attempts, or automated abuse of an API you are not authorised to use at that rate.

Crawling and scraping deserve a note of their own. Crawling a site that permits it is ordinary. Crawling one that has told you not to — by robots.txt, by terms, or by blocking you — is not, and a crawler that ignores rate limits is an attack whatever it was written for.

Your visitors are your responsibility

If your site lets people upload, post or send things, you are responsible for what they upload, post and send.

We do not require you to pre-moderate. We do require that you have a way to receive a complaint and act on it, and somebody who reads it — so that when we forward one, a person answers.

As an EU hosting provider we have obligations of our own under the Digital Services Act. Where we receive a valid notice about content you host, we will pass it to you with a deadline before we act on it ourselves, except where the content is in the immediately-prohibited list above.

Security, and what we expect of you

We patch the host, the container runtime and the platform's own software. You are responsible for your application: its dependencies, its credentials, and the code you deploy.

A compromised site is not a breach of this policy — it happens to careful people. Leaving one running once you know about it is.

  • Keep your application and its dependencies patched.
  • Do not commit credentials to a repository we deploy from.
  • Container images you run on an extra machine are your code: keep them patched, and everything in this policy applies to what they do.
  • Do not disable the platform's agent, firewall rules or update mechanism.
  • Tell us promptly if you believe an environment has been compromised. We will help.

Resource use

Every plan states what it gives you — cores, memory, disk and outbound traffic — as usable figures, after the platform's own overhead. Using what you bought is never a breach of this policy, including using all of it, all month.

What is a breach is working around the limit: running work on one environment that belongs to another, using staging or development environments as production capacity, or splitting one application across several accounts to avoid a plan boundary.

How we enforce this

Our strong preference is to reach a person and fix the problem. The order we work in:

  1. We contact you with what we have seen and a deadline — usually 24 to 72 hours depending on severity.
  2. We limit the blast radius. Where something is actively harming others — an attack in progress, a spam run, a compromised host — we suspend the affected environment first and tell you immediately afterwards. We try to keep the rest of your project running.
  3. We suspend the account, for repeated breaches or where we cannot reach anyone.
  4. We terminate, for the immediately-prohibited list, or where a suspension has not been resolved.

Your data. Where we suspend or terminate for a breach, we keep your data for 30 days and will give you an export on request, unless a law or a court says otherwise. We do not hold data hostage over a dispute.

If you think we are wrong, say so. Reply to the notice or write to us. A suspension that turns out to be our mistake is reversed and credited.

Reporting abuse

If something hosted here is harming you, report it. That form reaches the people who can act on it and you will get a reference by email. You do not need an account.

For law-enforcement and formal legal requests, use the same form and say so — it is routed differently.

Changes

We give at least 30 days' notice by email to account owners before a change that narrows what is allowed. Changes that only clarify existing rules, or that are required by law, may take effect sooner.