Acceptable Use Policy
What you may and may not run on RDPForge infrastructure, how we handle abuse reports, and what happens when a policy is broken.
Effective 14 October 2025. This policy exists to keep our network usable and our IP ranges clean. It is short on purpose. If you are unsure whether something is allowed, ask before you deploy — pre-sales questions about acceptable use are answered honestly and quickly.
Prohibited — immediate termination, no refund
- Spam and unsolicited bulk mail of any kind, including sending, hosting a payload for, or providing infrastructure to a spam operation.
- Phishing — hosting, distributing or operating credential-harvesting pages or campaigns.
- Malware — distribution, staging, or command-and-control infrastructure for botnets, ransomware, stealers or RATs.
- Attacks against third parties — DDoS origination, port scanning at scale, credential stuffing, brute-force campaigns, exploitation of systems you do not own or have written authorisation to test.
- Child sexual abuse material. Reported to the relevant authorities without notice to the account holder.
- Fraud infrastructure — carding, fake shops, money-mule automation, synthetic identity operations.
- Anything that gets our ranges blacklisted at scale, regardless of whether it is individually listed above.
Restricted — allowed with conditions
- Outbound mail. Port 25 is closed by default. To have it opened, open a ticket describing what you will send, from which domain, and confirming SPF, DKIM and DMARC are configured. Transactional and opt-in mail is fine; cold bulk outreach is not.
- Web scraping. Permitted where it respects the target's terms and does not constitute a denial of service. Aggressive crawling that generates abuse reports will be rate-limited or terminated.
- Security research and penetration testing. Permitted against systems you own or have documented written authorisation to test. Keep the authorisation; we will ask for it if a report arrives.
- Tor. Relays and bridges are permitted. Exit nodes are permitted only in Amsterdam, Frankfurt and Warsaw, and only after a ticket, because exit traffic generates abuse volume the other facilities will not accept.
- High-volume proxying and VPN services. Permitted for your own use or a defined user base. Open public proxies are not, because they are abused within hours.
- Adult content. Legal adult content is permitted where all performers are verifiably adults and the content complies with the law of the server's jurisdiction.
Explicitly permitted
To remove any doubt, all of the following are welcome: VPNs for personal or business use, trading bots and algorithmic strategies, game servers, cryptocurrency nodes and wallets, self-hosted applications of any kind, CI/CD runners, media servers for content you own, privacy tooling, and anything else that is lawful in the jurisdiction of the datacenter and does not appear above.
We do not police what you run. We police what harms other people.
Resource fairness
Shared plans are provisioned at a maximum 3:1 vCPU ratio. Sustained 100% CPU across all cores for more than 12 hours on a shared plan may trigger a conversation about moving you to a dedicated-core plan (Titan or Ultra). We will always contact you before taking any action; we do not throttle silently.
Network transfer allowances are stated per plan. Exceeding them results in a notification and an offer to add bandwidth, not an automatic overage charge and not a suspension.
Cryptocurrency mining
Proof-of-work mining is not permitted on shared plans — it is uneconomic for you and it degrades the node for everyone else. Running full nodes, validators, staking infrastructure and RPC endpoints is entirely fine and common on our network.
Jurisdiction and copyright notices
Six of our twenty regions — Iceland, Switzerland, Panama, Romania, Bulgaria and the Netherlands — are selected for their legal environment and are marketed as offshore. Here is precisely what that does and does not mean.
What "DMCA ignored" means here
The Digital Millennium Copyright Act is a United States federal statute. It creates obligations for providers within United States jurisdiction and has no direct legal force over a server located in ReykjavÃk, Zürich, Panama City, Bucharest or Sofia. When we receive a US-form DMCA notice concerning a server in one of those regions we record it and forward it to the customer, but we do not disable content on that basis alone.
In the Netherlands and in our non-offshore regions, copyright notices are forwarded to you and, where the local regime requires action on a specific and substantiated complaint, we act on it. Our United States regions are subject to the DMCA in the ordinary way, and the location pages say so.
What it does not mean
It does not mean we operate outside the law. Every region operates under the law of the country it is in, and where a complaint is properly brought under that law we comply with it. A provider claiming immunity from all legal process anywhere is either misinformed or lying.
Requests for customer information
We disclose customer information only in response to valid legal process issued by an authority with jurisdiction over Atlas Cloud Networks LLC or the relevant facility, and we require the process to be specific. In the offshore regions that means local court process rather than a foreign subpoena. Where we are lawfully permitted to notify you before disclosing anything, we do so.
What exists to disclose is deliberately small: an email address, invoice and payment records, support tickets, hypervisor-level resource metrics and a 90-day authentication log. We hold no identity documents, because we never ask for any. We do not inspect or retain traffic contents, and there is no agent inside your instance.
How we handle reports
- A report arrives at
[email protected]and is triaged within 4 hours, 24/7. - For non-urgent matters we forward it to you with a 48-hour window to respond and remediate. Most cases end here — usually a compromised application rather than deliberate abuse.
- For active harm (ongoing attack traffic, live phishing page, malware C2) we suspend immediately and notify you afterwards.
- You may appeal any action by replying to the ticket. We read appeals and we do reverse decisions when we are shown we were wrong.
We do not disclose customer identity to a reporter. We respond to valid legal process from jurisdictions that bind us, and we publish the aggregate count of such requests in our annual report.
Consequences
| Situation | Action | Refund |
|---|---|---|
| Compromised server causing harm | Suspend, notify, restore on remediation | N/A — service continues |
| First minor violation, remediated | Warning | N/A |
| Repeat violation | Termination | None |
| Prohibited-list activity | Immediate termination | None |
Version history
We keep every version of this document on record. Material changes are emailed to active customers 30 days before they take effect.
- v3.1Oct 2025Clarified position on scraping, VPN operation and security research.
- v3.0Apr 2024Restructured into prohibited / restricted / permitted.
- v2.0Jul 2022Added port 25 policy and mail requirements.
- v1.0Mar 2020Initial publication.