Skip to content
Version 1.1 · effective

This translation is provided for convenience. The Russian version is legally binding.

Acceptable Use Policy

What you must not do on QoCloud servers, which network restrictions apply and how we respond to violations.

1. Why these rules exist

  1. 1.1

    QoCloud servers share a network with other clients. One compromised or misused server can get the whole subnet blacklisted, cause IP addresses to be blocked and degrade service for neighbors. These rules protect all clients and the reputation of the network.

  2. 1.2

    The Client is fully responsible for the configuration, security and contents of their server and for the actions of persons to whom they have given access, including when the server has been compromised.

2. Prohibited activities

  1. 2.1

    Network attacks and malicious activity:

    • DDoS attacks, flooding, and "stress tests" of other parties' resources without their owners' permission;
    • port and vulnerability scanning of other parties' networks, password brute-forcing;
    • participating in botnets, hosting command and control (C&C) servers and distributing malware;
    • address spoofing (IP, ARP, MAC) and intercepting other parties' traffic.
  2. 2.2

    Fraud and spam:

    • phishing, fake websites of banks, stores and government services;
    • theft, validation and sale of account credentials and bank card data;
    • bulk messaging without recipients' consent by email, in messengers and on social networks, as well as hosting resources advertised by such messaging.
  3. 2.3

    Illegal content:

    • child sexual exploitation material, which we remove immediately without warning and report to the competent authorities;
    • material that infringes copyright, related rights or trademark rights;
    • promotion of terrorism, violence or extremism, and trade in prohibited substances and weapons;
    • any other content prohibited by the law of the country where the server is hosted.
  4. 2.4

    Resource abuse:

    • cryptocurrency mining;
    • open proxies, open mail relays and DNS resolvers used for attacks;
    • anonymization services if they are used for unlawful activity or attract complaints;
    • reselling resources to circumvent these rules.

3. Network restrictions

  1. 3.1

    Outbound connections to mail ports 25, 465 and 587 are blocked across the entire network to keep our addresses off spam lists. To send email, use external email services with an API.

  2. 3.2

    BitTorrent and DHT traffic is blocked on the network.

  3. 3.3

    Fair use of bandwidth: the average speed over 8 hours must not exceed the threshold for the country. If it does, the speed is automatically throttled for a limited time (up to 24 hours):

    • Germany: 500 Mbps; if exceeded, throttled to 250 Mbps;
    • Netherlands and Poland: 250 Mbps; if exceeded, throttled to 125 Mbps;
    • Estonia: 300 Mbps; if exceeded, throttled to 150 Mbps.
  4. 3.4

    DDoS protection is provided at the data center network level and does not guarantee mitigation of attacks of any size. If an attack threatens other clients, the IP address of the attacked server may be temporarily disconnected from the network.

4. How we respond to violations

  1. 4.1

    We accept abuse reports at abuse@qocloud.tech. We review each report and forward it to the Client through a ticket and by email.

  2. 4.2

    The Client must respond and fix the violation within 24 hours. If there is no response or the violation continues, we suspend the server until the violation is fixed.

  3. 4.3

    We suspend or delete a server without prior notice if:

    • it is carrying out an outbound attack, sending spam or distributing malware;
    • it hosts child sexual exploitation material, phishing or resources for stealing payment data;
    • competent authorities require it;
    • the violation is repeated.
  4. 4.4

    To investigate, our staff may inspect the server's network activity and, if necessary, access it through the console. We record each such action, with its reason, in the Client's security log.

  5. 4.5

    We do not refund money for the period during which a server was suspended or deleted for violating these rules. For serious or repeated violations, we suspend the account.

5. If your server has been compromised

  1. 5.1

    A compromise does not release you from responsibility for outbound activity from the server. We may isolate the server and ask you to reinstall the system.

  2. 5.2

    We recommend: SSH key authentication, disabled root password login, a firewall, regular updates and backups. Instructions are in the "Knowledge Base" section.

Sun Life Tower, Harbour City, Hong Kong · questions about this document: info@qocloud.tech