Legal

Acceptable Use Policy

What you may run on a Paragon instance, what gets you removed within the hour, and how an abuse report travels from inbox to decision.

Most acceptable use policies are written to be vague, so that the host can point at any clause it likes when a customer becomes inconvenient. This one is written the other way round. The prohibited list is short and absolute, the permitted list is long and specific, and the fair-use figures are printed rather than implied.

The general rule is easy to remember. Run whatever is legal where your server is, and do not aim anything at a machine you do not own.

1. Prohibited without exception

No notice, no window to fix it, no appeal that starts before the instance is already off. Four of the five below are pulled the moment they are confirmed, and the relay case gets half an hour because it is nearly always an accident.

  • Attacking a third party. DDoS origination, reflection or amplification, port scanning at scale, credential stuffing, SSH and RDP brute force, and any traffic whose purpose is to degrade something you do not own. A single nmap run against a host you control is fine. Sweeping a /16 you have never met is not.
  • Child sexual abuse material. The instance goes off, the account is terminated, and the matter is reported to the body that receives such reports in the jurisdiction of the site. There is no version of this we handle quietly.
  • Open relays and unsolicited bulk mail. An open SMTP relay is a misconfiguration until you are told, and a breach thirty minutes later. Bulk mail to addresses that never asked for it is a breach immediately.
  • Phishing pages impersonating a real service. A login form wearing somebody else’s brand comes down without discussion. Whether you built it or your customer did makes no difference to the outcome.
  • Malware command and control. Botnet controllers, ransomware infrastructure, exploit kits, stealer panels, loaders. Sandboxing malware you are analysing is research and is covered below; operating it against other people is not.

Everything on that list is also grounds for immediate termination under section 6 of the terms (/legal/terms), which means no refund.

2. Explicitly permitted

These are the questions sales gets asked every week. The answers have not changed since 2019.

  • Privacy tooling. VPN endpoints, WireGuard and OpenVPN, proxy servers, Shadowsocks, recursive DNS resolvers, mixnet nodes. Running an exit for your own users is the whole point of a large part of our fleet.
  • Tor relays and bridges. Guards, middle relays and obfuscated bridges are welcome at every site we operate. Exit relays are permitted only at the sites where the upstream tolerates them: AMS-02, HEL-01, RIX-01, BUH-01, SOF-01 and KIV-01. Exits elsewhere get moved, not terminated. Run the reduced exit policy, set a working abuse contact in your descriptor, and put something at the address explaining what the machine is.
  • Seeding and file distribution. Torrent clients, seedboxes, private and public trackers, and mirrors of large public datasets. Copyright notices are handled the way the abuse policy (/legal/abuse) describes, under the law of the site rather than the law of the complainant.
  • Adult content. Legal where the server is, everyone depicted an adult, everyone depicted consenting, and age controls in front of it wherever the site’s law requires them. We do not review the material and we do not want copies of your paperwork; we want it to exist.
  • Political speech. Opposition media, exile publications, leak archives, union organising, protest infrastructure. Nothing has ever been removed from this network for being politically awkward, and a complaint that amounts to embarrassment is filed accordingly.
  • Cryptocurrency nodes and mining. Full nodes, validators, RPC endpoints, indexers and CPU or GPU mining, all subject to the fair-use figures below. Your cores are dedicated, so using every one of them at all times is expected rather than tolerated. Proof-of-space plotting on storage nodes is the single exception: it destroys the endurance of the bulk tier and is not permitted there.
  • Security research against your own targets. Scanning, fuzzing and exploitation against systems you own or have written authorisation to test. Red-team infrastructure is fine if you can produce the engagement letter within one working day of us asking. Keep the letter; we do not want a copy on file.

3. Mail, specifically

Mail is allowed. Bulk mail is allowed. Unsolicited bulk mail is not, and the difference is consent you can evidence.

Port 25 outbound is closed on new instances and opens on request. The request needs three sentences: what you send, who asked for it, and how they stop. Lists must be confirmed opt-in, every message needs a working unsubscribe header, and bounce handling has to actually run. Cross five complaints per ten thousand delivered and the port closes again while we talk.

4. Fair use, with actual numbers

Traffic is unmetered. Unmetered means unmetered, and fair use is a published figure rather than a threat left deliberately blank.

PortFair-use sustained rateMeasured as
10 Gbit/s4 Gbit/s95th percentile over a calendar month
25 Gbit/s10 Gbit/s95th percentile over a calendar month
40 Gbit/s16 Gbit/s95th percentile over a calendar month

Cross the figure once and nothing happens. Do it two months running and you get an email about a dedicated port, never a surprise invoice. Nobody at this company has ever been rate-limited without being written to first.

Two other limits are worth stating. An instance planning to hold more than roughly two hundred thousand simultaneous connections should tell us in advance, so the state table on the filtering tier is sized for it. On storage nodes, sustained random writes against the bulk tier are shaped above a rolling daily average, because the NVMe tier in front of it is what makes that plan usable for everyone on the node.

5. How a report is handled

Reports go to [email protected]. A person reads every one of them, automated submissions included, and the desk is staffed at all hours rather than during office ones.

  • Acknowledgement goes out within four hours, with a case number.
  • A useful report contains the address, exact timestamps with a UTC offset, the protocol and port, unedited log lines, and what you would like done. Reports without timestamps cannot be matched to a customer and are closed.
  • We forward the report to the customer, minus your contact details unless you ask us to include them. Identity is never attached, because we do not hold any to attach.
  • Where the report concerns copyright, the abuse and DMCA policy (/legal/abuse) governs instead of this section.

6. The escalation ladder

Outside the five categories in section 1, everything moves one rung at a time and stops the moment the problem is fixed.

  1. Notice. The report is forwarded with the case number. You have twenty-four hours to reply, and replying that you are working on it is a reply.
  2. Null-route. Silence, or no visible progress, and the address is null-routed at the edge for a further twenty-four hours. The instance keeps running, your data is untouched, and the console still works.
  3. Suspension. Still nothing, and the instance is suspended with its storage intact for fourteen days.
  4. Termination. A repeat of the same substantiated issue within ninety days, or anything from section 1, ends the account. Storage is wiped and no refund is due.

7. Appeals

Reply to the case number and say what you disagree with. A second engineer, one who had nothing to do with the original decision, reviews it and answers within one working day. Roughly one appeal in six succeeds, usually because the report named the wrong address and the first pass believed it.

If you are unsure whether a plan of yours sits inside this policy, ask before you build it. Answers to that question take minutes, and they are considerably cheaper than a migration.