Acceptable use policy
Four prohibitions, and a long list of things we explicitly permit that other hosts will not. This page is short on purpose — a policy that reserves every right is a policy that means nothing.
Most acceptable use policies are drafted to give the provider unlimited discretion: a page of vague prohibitions on anything "objectionable," "excessive," or "harmful to our reputation," which in practice means the provider can terminate you for any reason and point at a clause afterwards.
Ours is the opposite. It is deliberately narrow, exhaustive, and written so you can tell in advance whether your project is welcome here. If it is not on the prohibited list, it is allowed.
1. Prohibited without exception
Four categories. There is no appeal, no warning, and no grace period for any of them.
1.1 Child sexual abuse material
Storage, transmission, generation or facilitation of CSAM, in any form, including synthetic or AI-generated material. Detection results in immediate termination, immediate destruction of the instance, and referral to the relevant authority in the jurisdiction where the hardware sits. We do not require a court order to act on this and we will not.
1.2 Malware infrastructure
Command-and-control servers, ransomware payment or key infrastructure, exploit kits, malware distribution points, phishing pages impersonating a real organisation, and stealer log collection endpoints.
1.3 Bulk unsolicited messaging
Sending unsolicited bulk email or SMS, operating a snowshoe relay, or hosting the infrastructure for either. Outbound port 25 is closed by default on new instances and we open it on request after a short conversation about what you are sending.
1.4 Attacks against third parties
Denial-of-service attacks, booter or stresser services, mass port scanning, credential stuffing, brute-force campaigns, and exploitation of systems you do not own or have written authorisation to test.
2. Explicitly permitted
Because the question is asked constantly, here is a non-exhaustive list of things that are welcome on VPSDEN and that many hosts refuse:
- Tor relays and exit nodes, in every region. We run exits ourselves and have since 2014. Use a reduced exit policy blocking SMTP, run the standard exit notice on port 80, and take a dedicated IP so complaints do not touch your other services.
- I2P routers, VPN endpoints and proxies, commercial or personal.
- BitTorrent, seeding and leeching, including trackers and indexes. Not permitted in a jurisdiction where the specific content is unlawful — that is your call and your risk, and it is why we publish the Jurisdiction Matrix.
- Adult content that is lawful where the server sits and involves only consenting adults.
- Cryptocurrency nodes, miners, validators, mixers, and exchange infrastructure.
- Whistleblowing platforms, SecureDrop instances, and leak sites. Tell us and we will help you harden it, free.
- Political, religious and dissident content, including material unlawful in the country you happen to live in.
- Journalism, including publication of leaked documents.
- Harm-reduction, sexual health and LGBTQ+ resources, including in regions where such material is restricted elsewhere.
- Circumvention tooling — censorship bypass, mirrors of blocked sites, bridge distribution.
- Security research, including exploit development, fuzzing infrastructure, and vulnerability disclosure platforms.
- Anything merely controversial, commercially inconvenient, or embarrassing to a large organisation.
3. How we enforce
3.1 What we do not do
We do not inspect the contents of your instance. There is no agent, no deep packet inspection, no IDS on customer traffic, and no filesystem scanning. On disk-backed plans with zero-knowledge LUKS — the default — we are cryptographically unable to do so. We act on reports, not on surveillance.
3.2 What happens when we receive a report
- Copyright complaints are forwarded to you for information. We take no action. The DMCA does not apply in any region we operate, and outside Malaysia we act on copyright only under a binding order from a court where the hardware sits. Malaysia has a statutory notice route with a 48-hour clock — see the copyright policy.
- Reports outside the four prohibited categories are forwarded to you. We take no action.
- Credible reports within the four categories get a request for explanation with a 24-hour window, except for CSAM, which is acted on immediately without notice.
- Where a violation is confirmed, the instance is suspended. You have 7 days to retrieve your data — except for CSAM, where the instance is destroyed immediately.
3.3 Network-level intervention
If an instance is actively harming the network — saturating a port, participating in an attack, or triggering an upstream nullroute — we may filter or suspend it immediately and discuss it afterwards. This is an availability measure protecting other customers, not a content judgment.
4. Reporting abuse
Send reports to [email protected]. The OpenPGP key that would let you encrypt a sensitive report is not published yet; if the evidence itself is sensitive, say so and we will agree a channel before you send it. Include the IP address, the timestamp with a timezone, and evidence. We acknowledge within 24 hours and tell you what we did.
Reports of CSAM are prioritised above everything else in this company and handled within the hour, at any time of day.
5. Why the list is this short
A reasonable question: if we do not look at what customers do, why prohibit anything at all?
Three reasons, and none of them is that we disapprove.
- These four categories end hosting companies. They are what causes transit carriers to withdraw service, facilities to terminate colocation contracts, and authorities to seize racks rather than serve orders. Enforcing them is what keeps this service available to everybody else — it is an availability measure, not a moral one.
- CSAM is different. It is not a policy position and it is not jurisdiction-dependent. It is the one category where we act without process, without notice, and without hesitation.
- A shorter list is a stronger promise. Every additional prohibition is discretion we could later use against a customer we found inconvenient. Four is what we can defend, so four is what we wrote.
If you are unsure whether your project fits, ask us before you buy. We answer in writing, we answer honestly, and if the answer is no we will say so rather than take your money and terminate you in a month.
6. Common questions
What is not allowed on VPSDEN?
Four categories: child sexual abuse material; malware command-and-control, ransomware infrastructure and exploit-kit hosting; bulk unsolicited email and SMS; and attacks launched from our network against third parties including DDoS, port scanning, credential stuffing and vulnerability exploitation. Everything outside those four is permitted, including content that is merely controversial, commercially inconvenient, or illegal in a country you are not hosted in.
Are Tor exit nodes allowed on VPSDEN?
Yes, in every region, and we will not respond to abuse complaints about them by suspending you. We ask that you use a reduced exit policy blocking SMTP, run the standard Tor exit notice on port 80, and use a dedicated IP address so complaints do not affect your other services. VPSDEN has operated exit relays of its own since 2014.
Questions about any of this?
We answer legal questions from prospective customers, in writing, before you buy anything.
No email · No KYC · Pay in Monero · Deployed in under a minute