New — Iris AI drafts your firewall, routing & rate-limit rules. Explore AI features →

Acceptable Use Policy

Last Updated: August 3, 2026

Draft — pending legal review. This document is a working draft and has not yet been reviewed by a qualified lawyer. It is not legal advice and is not binding until reviewed by counsel and finalized. The notice-and-takedown mechanics in Section 5 in particular need confirmation by counsel (see the reviewer note there).

This Acceptable Use Policy ("AUP") describes activities and content that are prohibited when using the services provided by Ngris ("Ngris", "we", "us") — including our edge platform, secure tunnels, static and application hosting, build and deployment pipelines, APIs, agents, and any code, containers, or workloads you run on or route through Ngris (together, the "Services"). This AUP is incorporated into and forms part of our Terms of Service. By using the Services, you agree to this AUP and are responsible for ensuring that your users, customers, and anyone you allow to use your account also comply with it.

Because Ngris can be used to expose, host, build, and run software you provide — including web applications, static sites, and, where enabled, user-supplied code and container workloads — you are solely responsible for everything you deploy, serve, transmit, or make accessible through the Services ("Your Content"). We do not pre-screen Your Content, and hosting or transmitting it does not mean we endorse or have reviewed it.

1. Prohibited Content and Uses

You may not use the Services to host, run, store, transmit, distribute, link to, or otherwise make available any content or activity that:

  • Is illegal or facilitates illegal activity under any law that applies to you or to Ngris, including fraud, money laundering, sanctions evasion, illegal gambling, or the sale of illegal goods or services.
  • Sexually exploits or endangers minors. Child sexual abuse material (CSAM) is strictly prohibited, will be reported to the appropriate authorities, and results in immediate termination. We will preserve and disclose information as required by law.
  • Infringes intellectual property — including copyright, trademark, patent, trade-secret, or publicity/privacy rights — or distributes pirated software, media, or license-circumvention tools.
  • Is defamatory, harassing, threatening, or incites violence, or promotes terrorism, human trafficking, or violent extremism.
  • Violates privacy or data-protection law, including collecting, storing, or exposing personal data without a lawful basis, or publishing others' personal or confidential information without authorization ("doxxing").
  • Is deceptive, including phishing pages, fake login or brand-impersonation sites, scam or "pig-butchering" pages, or content designed to trick users into disclosing credentials, payment details, or personal data.

2. Malware, Attacks, and Harm to Others

You may not use the Services to build, host, distribute, control, or launch:

  • Malware — viruses, worms, ransomware, trojans, spyware, keyloggers, or any code intended to damage, disable, or gain unauthorized access to systems or data.
  • Command-and-control (C2), botnets, or attack infrastructure, including using a tunnel, endpoint, or deployed workload to coordinate compromised devices.
  • Denial-of-service traffic (DoS/DDoS), amplification/reflection attacks, port scanning, packet flooding, or any attempt to disrupt or overload a network, service, or host — whether third-party or Ngris.
  • Unauthorized access — probing, scanning, penetrating, or breaching the security of any system, network, or account you are not authorized to test, or circumventing authentication, rate limits, or access controls.
  • Credential abuse — credential stuffing, brute-forcing, harvesting, or trafficking in stolen credentials, tokens, or API keys.
  • Spam and unsolicited messaging — bulk email, SMS, or messaging in violation of anti-spam laws (e.g. CAN-SPAM, GDPR/ePrivacy, CASL), or open mail relays and list-washing services.

3. Resource Abuse and Prohibited Workloads

Ngris provides shared and metered compute, bandwidth, and storage. To protect the platform for all users, the following are prohibited unless we have agreed to them in writing:

  • Cryptocurrency mining of any kind — including CPU/GPU mining, "proof-of-work" workloads, mining pools or proxies, and hosting the tooling for them. Our build and deploy environments are for building and serving your application, not for mining or other compute-farming.
  • Deliberate resource abuse — running workloads engineered to consume disproportionate CPU, memory, storage, network, or build minutes; abusing free-tier resources; or operating "grid," "farm," or distributed-compute schemes that are not a genuine use of the Services.
  • Circumventing limits — evading plan quotas, rate limits, resource caps, or billing by, for example, creating multiple accounts, sharing accounts to exceed limits, or exploiting build/deploy pipelines for unrelated compute.
  • Prohibited proxy/anonymization services — open proxies, open VPN exit nodes, or relays operated to conceal the origin of abusive or illegal traffic. (Legitimate use of tunnels and edge routing for your own services is, of course, permitted — that is what Ngris is for.)
  • Scraping and automated abuse — using the Services to scrape or extract data from third parties in violation of their terms or applicable law.

4. Code, Containers, and Third-Party Dependencies

When you build, deploy, or run code or container workloads on Ngris:

  • You are responsible for the security, licensing, and legality of your code and every dependency, base image, or package it pulls in, including keeping them free of known-malicious or license-violating components.
  • You must not attempt to escape, tamper with, or gain access beyond the isolation boundary of your build or runtime environment, or to access other customers' data, workloads, or the underlying host or control plane.
  • You must comply with the license terms of any open-source or third-party software you deploy, and you may not use the Services in a way that violates a third party's terms of service.
  • Your workloads must not intentionally interfere with, degrade, or destabilize the Services or other customers' workloads.

5. Copyright, DMCA, and Takedown Process

We respond to notices of alleged infringement and to reports of illegal or abusive content. If you believe content hosted on or served through Ngris infringes your copyright, or is otherwise unlawful, send a notice to abuse@ngris.com including:

  • Your name, address, and contact details;
  • Identification of the work or right you claim is infringed or violated;
  • The specific URL(s) or endpoint(s) where the content appears;
  • A statement that you have a good-faith belief the use is not authorized by the rights holder, its agent, or the law;
  • A statement, under penalty of perjury, that the information is accurate and that you are authorized to act on the rights holder's behalf; and
  • Your physical or electronic signature.

Where we host the content directly, we generally act on valid notices by removing or disabling access to the reported material, and we may notify the affected customer. Where a customer submits a valid counter-notice, we may follow the counter-notification process before restoring content, subject to applicable law.

Note for reviewers: the notice-and-takedown mechanics above (including designated-agent registration under the U.S. DMCA, and the equivalent obligations under the EU Digital Services Act and other regimes) depend on the jurisdiction(s) in which Ngris operates and the role Ngris plays for a given service. These procedures must be confirmed by counsel — see the governing-law note in our Terms of Service.

6. Reporting Abuse

If you become aware of any content or activity that violates this AUP, report it to abuse@ngris.com, an actively monitored address, with as much detail as possible (URLs/endpoints, timestamps, and a description). We review reports and take action we consider appropriate. Please report suspected security vulnerabilities to security@ngris.com (also actively monitored) instead — see our Security page.

7. Enforcement, Suspension, and Termination

If we determine, in our reasonable discretion, that you have violated this AUP — or if we must act to protect the Services, our other customers, third parties, or ourselves, or to comply with law — we may take any of the following actions, with or without prior notice depending on the severity and urgency:

  • Remove, disable, or restrict access to the offending content, endpoint, deployment, or workload;
  • Throttle, suspend, or terminate the affected endpoint, tunnel, deployment, or account;
  • Suspend or terminate your access to the Services in whole or in part; and
  • Preserve, investigate, and — where required or permitted by law — disclose information to law enforcement or affected parties.

Where practical and appropriate, we will give you notice and an opportunity to remediate, but for severe violations (such as CSAM, active attacks, malware distribution, or conduct that poses an immediate risk to the platform or others) we may act immediately and without prior notice. Our right to suspend or terminate under this AUP is in addition to our rights under the Terms of Service. We are not liable for any action taken in good faith to enforce this AUP, and no fees are refunded for suspensions or terminations resulting from a violation.

8. "As Is"; No Monitoring Obligation

The Services are provided on an "AS IS" and "AS AVAILABLE" basis, as described in our Terms of Service. We have no obligation to monitor Your Content or the Services, but we may do so to operate, secure, and improve the Services and to enforce this AUP. The fact that we do not act on a particular violation does not waive our right to act on it or any other violation later.

9. Changes to This Policy

We may update this AUP from time to time. Material changes will be reflected by updating the "Last Updated" date above and, where appropriate, by additional notice. Your continued use of the Services after changes take effect constitutes acceptance of the updated AUP.

10. Contact

Questions about this AUP? Contact us at support@ngris.com. To report abuse, use abuse@ngris.com.

Ask an AI to summarise this page