Acceptable Use Policy
Effective 1 January 2026
What you may and may not do with NullVault. This policy forms part of the Terms of Service.
1. The short version
Use the network for lawful purposes, on systems you are allowed to touch, at a volume that does not harm anyone. Everything below follows from that.
2. Prohibited outright
These result in immediate termination without refund, and reporting to the relevant authorities where we are required or it is clearly warranted:
- Child sexual abuse material, in any form, at any point in the chain.
- Unauthorised access: credential stuffing, brute forcing, exploiting vulnerabilities, or accessing any system you do not have permission to access.
- Attacks on infrastructure: DDoS, amplification, resource exhaustion, or any traffic intended to degrade a third party's service.
- Fraud: carding, payment testing, account takeover, phishing, or hosting phishing content.
- Malware distribution, botnet command and control, or ransomware operations.
- Spam, bulk unsolicited messaging, or evading a platform's anti abuse controls at scale.
- Human trafficking, terrorism, or material that incites violence.
- Circumventing sanctions, export controls, or supplying services to sanctioned parties.
3. Restricted without written permission
- Penetration testing or scanning of third party infrastructure.
- Reselling access to the network to your own customers.
- Sustained traffic above 500 Mbps or sustained concurrency above 10,000 sessions.
- Automated account creation on third party platforms.
Ask first: . Written permission means an email from us, not silence.
4. Typical permitted use
- Price and market intelligence gathering from publicly accessible pages.
- Brand protection, counterfeit detection and affiliate compliance monitoring.
- Ad verification and localised SEO or SERP checking.
- Geo specific QA of your own applications.
- Public web data collection that respects robots directives and rate limits.
Being technically permitted here is not legal advice. Scraping law varies by country and by the target's terms; that assessment is yours to make.
5. How to behave on the network
- Respect
robots.txtand any published rate limits on the sites you visit. - Identify your traffic honestly where a site asks you to.
- Back off when you receive 429 or 5xx responses. Do not hammer through them.
- Do not attempt to identify, contact or interfere with the residential peers whose connections carry your traffic.
- Do not attempt to bypass our own rate limits, signing or challenge mechanisms.
6. Data you collect
You are the controller of anything you gather through the network. Complying with data protection law, including lawful basis, minimisation and subject rights, is your responsibility, not ours.
7. How we enforce this
We act on abuse reports from network partners, from destination operators, and from our own monitoring. Depending on severity we may:
- contact you and ask you to stop;
- rate limit or suspend a specific service;
- suspend the account pending explanation;
- terminate without refund and preserve logs for law enforcement.
For anything in section 2 we skip straight to step 4. We do not owe a warning for material that is criminal on its face.
8. Reporting abuse
If traffic from this network is harming your systems, email with timestamps in UTC, the source IPs, and a sample of the requests. We investigate every report and will confirm receipt.
See also the Terms of Service and Privacy Policy.