Acceptable Use Policy
What you can't do with NimbusNexus, how we enforce against violations, and how to report abuse. Plain-English summary above every section — not legally binding, but an honest gloss of what's underneath.
This Acceptable Use Policy ("AUP") describes prohibited uses of the NimbusNexus™ cloud service (the "Service") operated by Fortlab Corporation ("Fortlab", "we", "us"). This AUP is part of the Terms of Service ("Terms") at /terms-of-service and applies to everyone who uses the Service, including the Customer and the Customer's end users. If you violate this AUP, we may take any of the actions described in §4 below, up to and including immediate termination of your account.
Why this exists
Cloud infrastructure is powerful and can be misused. This AUP says what we don't allow, how we enforce it, and how to report abuse to us.
As a provider of cloud infrastructure, Fortlab has legal, ethical, and operational responsibilities to prevent the Service from being used to cause harm. This AUP defines the conduct we prohibit and gives us the right to enforce against it. The categories below are illustrative, not exhaustive — Fortlab reserves the right to determine, in good faith, whether conduct violates this AUP.
This AUP applies in addition to the obligations in the Terms. Where the Terms and this AUP overlap (for example, on prohibited content), the stricter rule applies.
Prohibited content
Don't host or distribute content that's illegal, harmful, or that we're legally required to act against.
You may not use the Service to host, store, transmit, or distribute:
Child sexual abuse material (CSAM) or any content that sexually exploits, sexualizes, or endangers minors. This is an absolute prohibition. We report suspected CSAM to the National Center for Missing & Exploited Children (NCMEC) or the equivalent authority in the relevant jurisdiction, and we cooperate with law enforcement.
Content that incites or facilitates violence, including credible threats against specific individuals or groups, content directing or organizing violent attacks, terrorist content as defined under applicable law, and content promoting or recruiting for violent extremism.
Content that infringes intellectual property rights, including copyrighted works distributed without authorization, trademarks used to deceive, and trade secrets disclosed without authorization.
Content that violates privacy or publicity rights, including non-consensual intimate imagery (sometimes called "revenge porn"), doxxing, and unauthorized publication of personal data intended to facilitate harassment.
Content that constitutes fraud or deception, including phishing pages, scam pages, fake login pages impersonating other services, fraudulent storefronts, and material designed to deceive recipients into transferring money, credentials, or sensitive data.
Malware, exploits, and offensive security tools deployed without authorization, including ransomware command-and-control infrastructure, banking trojans, credential stealers, exploit kits, and any tool designed primarily to harm systems you do not own or have permission to test.
Content prohibited by applicable law in jurisdictions where Fortlab operates, including but not limited to US federal law, US state law of the Customer's location, and (for Customers in the EEA, UK, or Switzerland) applicable EU/UK/Swiss law.
This list is not exhaustive. We may act on other content that we reasonably determine causes serious harm.
Prohibited conduct
Don't use the Service to attack, abuse, or interfere with other systems — ours, our customers', or anyone else's.
3.1 Network and security abuse. You may not:
• Probe, scan, or test the vulnerability of any system or network not owned by you or for which you do not have explicit written authorization.
• Launch denial-of-service or distributed-denial-of-service attacks, amplification attacks, or any traffic intended to disrupt other services.
• Conduct unauthorized penetration testing against any system, including systems on the NimbusNexus network. Authorized testing of your own resources is permitted; see §3.6.
• Bypass, circumvent, or interfere with authentication, access controls, or rate limits on any system.
• Spoof, forge, or manipulate network identifiers (IP addresses, headers, source addresses) to disguise activity or impersonate others.
• Use the Service as a relay, proxy, VPN exit, or anonymization layer for activity that would otherwise violate this AUP.
3.2 Spam and unsolicited communications. You may not use the Service to send, relay, or facilitate:
• Unsolicited bulk email ("spam"), unsolicited bulk SMS, or unsolicited bulk messaging on any platform.
• Email or messaging that violates the US CAN-SPAM Act, Canada's CASL, the EU ePrivacy Directive / PECR, or other applicable anti-spam law.
• Email infrastructure (SMTP servers, mailing list managers, email-warming tools) that does not implement standard authentication (SPF, DKIM, DMARC) and unsubscribe handling.
• Messages with forged headers, deceptive subject lines, or misleading sender identities.
If you send transactional or marketing email through the Service, you must maintain a clean sender reputation. We may suspend or restrict your use of email-related ports or features if your sending behavior generates abuse complaints, blacklisting, or excessive bounces.
3.3 Cryptocurrency mining. Cryptocurrency mining workloads — including proof-of-work mining, GPU mining, and CPU mining of any cryptocurrency — are not permitted without our prior written approval. Approval is granted at our discretion based on resource impact, payment terms, and other factors. This prohibition includes mining on shared resources, mining inside containers or VMs that are nominally provisioned for other purposes, and mining-adjacent activity such as testnet mining or contributing hash power to mining pools.
3.4 Resource abuse. You may not:
• Operate workloads designed primarily to consume computing resources without a corresponding business purpose, including workloads designed to game free tiers, trial credits, or referral programs.
• Run workloads that abuse the fair-use principles of any underlying network or platform service.
• Use the Service in a way that disproportionately impacts other Customers' performance.
3.5 AI-related prohibitions. You may not use the Service to:
• Generate, host, or distribute child sexual abuse material, non-consensual intimate imagery, or deepfakes intended to deceive, defame, or harass identifiable individuals.
• Build or operate scraping infrastructure that violates the terms of service or robots.txt of the source site, or that scrapes personal data in violation of applicable privacy law.
• Train or fine-tune models on data you do not have rights to, where the training itself would constitute infringement.
• Operate AI systems that impersonate real people for fraudulent or deceptive purposes, including voice cloning for vishing, deepfake video for impersonation, or text generation that materially misrepresents identity.
• Operate AI systems whose outputs you intend to use in violation of any other section of this AUP.
3.6 Authorized security testing of your own resources. Penetration testing of your own NimbusNexus resources is permitted with the following conditions:
• Testing must be limited to resources you have provisioned and control.
• Testing must not affect other Customers, the underlying NimbusNexus infrastructure, or third parties.
• High-volume or potentially-disruptive testing (including DoS testing) requires advance notice to [email protected] at least 72 hours in advance.
• Vulnerabilities discovered in NimbusNexus infrastructure (rather than your own resources) must be reported under our responsible disclosure procedure to [email protected] rather than exploited.
We will not act on legitimate security testing that follows the conditions above.
Enforcement
When we receive an abuse report, we investigate. Depending on what we find, we may warn you, restrict your account, suspend it, or terminate it. Serious violations get faster action.
Where Fortlab determines, in good faith, that a violation of this AUP has occurred or is in progress, we may take any of the following actions, alone or in combination:
Warning and request to cure. For minor or first-time violations that do not pose ongoing harm, we may notify you and ask you to remediate within a defined period.
Restriction. We may rate-limit, block, or restrict specific features, ports, or workloads associated with the violation while leaving the rest of your account operational.
Suspension. We may suspend access to your account or specific Services pending investigation or remediation.
Termination. We may terminate your account in accordance with §11 of the Terms.
Content removal. Where prohibited content is hosted on the Service, we may remove or disable access to it.
Reporting to authorities. Where required by law or where the violation involves serious criminal conduct (including CSAM, credible threats of violence, or large-scale fraud), we will report to relevant authorities, with or without prior notice to you.
Severity and timing. Most actions follow a graduated response: notice → restriction → suspension → termination. However, the following circumstances justify immediate action without prior notice:
• Suspected CSAM, child exploitation, or imminent threats to life.
• Active attacks on third-party systems originating from the Customer's resources.
• Conduct that exposes Fortlab or other Customers to legal or operational risk.
• Repeated violations after prior warnings.
We log all enforcement actions and the reasons for them.
Reporting abuse
If you see something on NimbusNexus that violates this AUP, send us a report at [email protected].
Reports of suspected AUP violations should be sent to [email protected]. Useful reports include:
• The URL, IP address, or other identifier of the resource involved.
• A description of the violation and any supporting evidence (timestamps, logs, screenshots, headers).
• The reporter's contact information (anonymous reports are accepted but harder to follow up).
We acknowledge credible abuse reports within twenty-four (24) hours, in accordance with §4 of the Terms. We treat reporter information confidentially to the extent practical, though investigations may require us to share information with the affected Customer or with law enforcement where legally required.
We may decline to act on reports that are vexatious, automated, manifestly inaccurate, or outside the scope of this AUP.
Appeals
If we restrict, suspend, or terminate your account and you think we got it wrong, you can appeal.
A Customer subject to enforcement action under §4 may appeal by emailing [email protected] within thirty (30) days of receiving notice of the action. The appeal should include:
• The Customer account and the action being appealed.
• The basis for the appeal, including any new information or context not available at the time of the original decision.
A member of Fortlab's team not directly involved in the original decision will review the appeal and respond within ten (10) business days. The reviewer may uphold, modify, or reverse the original decision. The reviewer's decision is final, subject to the dispute-resolution procedures in §14 of the Terms.
Appeals do not automatically pause the enforcement action. In urgent cases, we may pause the action pending review at our discretion.
Changes to this AUP
We may update this AUP. We'll post the new version and email you at least 30 days before material changes take effect.
Fortlab may revise this AUP from time to time. The current version is posted at /acceptable-use-policy with a revision date. Material changes that expand the scope of prohibited conduct or change enforcement procedures will be announced by email at least thirty (30) days before they take effect, in accordance with §18 of the Terms.
We may, however, make changes effective immediately if required to address legal obligations, security threats, or active abuse — in which case we will notify Customers as soon as practicable.
Contact
Abuse: [email protected]. Security: [email protected]. Appeals: [email protected].
Abuse reports: [email protected]
Security vulnerability reports: [email protected]
Account-action appeals: [email protected]