Acceptable Use Policy
What is and is not allowed on XDP.NETWORK's DDoS-protection Services: prohibited content and network behavior, abuse reporting, and enforcement.
On this page
This Acceptable Use Policy ("AUP") defines what is and is not allowed when using the Services of XDP.NETWORK ("we", "us"), [[PLACEHOLDER: company legal name]], a PingLess Studios product: the OpenShield-XDP firewall Agent (Game and Game Pro editions), PingLess WAF and WAF Pro, the Console, and our APIs. It applies to every Customer ("you") and to all Protected Infrastructure — your servers, game servers, sites, and APIs enrolled in the Services. This AUP is incorporated into the Terms of Service; breaching it breaches the Terms.
1. Purpose & scope
We exist to stop denial-of-service attacks, not to carry them. This policy protects our network, our other Customers, and third parties. It applies to all Services, to all Protected Infrastructure, to any traffic that passes through or is filtered by the Services, and to anything done with an account, API key, or license issued to you. You are responsible for all activity under your account — including activity by your team members, your end users, and anyone you grant access to your servers or the Console.
2. Prohibited content & activity
You may not use the Services to host, transmit, link to, or distribute:
- Content that is illegal in [[PLACEHOLDER: operating jurisdiction]] or in any jurisdiction where your Protected Infrastructure operates.
- Malware, exploit kits, or command-and-control (C2) infrastructure — whether the Services front it, filter for it, or merely resolve to it.
- Phishing pages, credential-harvesting forms, or impersonation content.
- Child sexual abuse material (CSAM). Zero tolerance: immediate termination and a report to the competent authorities, with evidence preserved.
- Spam. You may not originate, relay, or promote bulk unsolicited messages through or behind the Services.
- Material that infringes copyright or other intellectual-property rights. Rights holders should use our DMCA / Abuse process.
3. Prohibited network behavior
You may not use the Services, your account, or your Protected Infrastructure to:
- Launch, amplify, broker, or test denial-of-service attacks against anyone. That includes "test" attacks against targets you do not own or lack explicit written authorization to test.
- Spoof source IP addresses in traffic that transits our network.
- Scan, probe, or enumerate third-party networks or hosts without authorization.
- Knowingly operate open resolvers or reflectors that can be abused for amplification — including open DNS resolvers, internet-exposed memcached instances, and NTP servers answering
monlistqueries. If we tell you one of yours is open, fix it promptly. - Operate, resell, white-label, or promote DDoS-for-hire, "booter", or "stresser" services. This is an absolute prohibition and is enforced with immediate termination.
4. No interference with the Services
- No benchmarking, load-testing, or stress-testing our infrastructure without our prior written consent. Test your own defenses; ours are shared with every other Customer.
- No bypassing or attempting to bypass plan limits or technical controls — for example running more Agent instances than your license allows, or evading WAF Pro plan boundaries.
- No interfering with mitigation delivered to other Customers, such as flooding shared WAF capacity with junk traffic or deliberately tripping shared rate limits.
- No probing or reverse-engineering the Services themselves beyond what is needed to operate them as documented.
5. API & Console abuse
- No scraping, crawling, or enumerating other tenants' data, configurations, or traffic through the Console or API.
- No sharing account credentials or API keys (
osk_…) outside your organization. Keys are per-server secrets; treat them that way. - No circumventing rate limits, access controls, or authentication on the API or Console.
- Automated access must stay within published limits: [[PLACEHOLDER: API rate limits or link to API documentation]].
6. Game servers
Hosting game and voice servers is welcome — that is exactly what the Game and Game Pro editions of OpenShield-XDP are built for. Per-player rate limiting and query/RCON shielding exist so your community can keep playing through an attack. What is not welcome behind our protection:
- Hosting or distributing cheats, aimbots, cracked clients, or account-stealing tools.
- Server emulators or private-server software that infringes the game publisher's intellectual property.
- Attack tools dressed up as game utilities — "server testers", packet flooders, and similar.
7. Reporting abuse
Report abuse to [[PLACEHOLDER: abuse contact email]]. To help us act quickly, include:
- The source and destination IP addresses involved.
- Timestamps, with the time zone.
- Relevant logs, packet captures, message headers, or URLs.
- A short description of what you observed and why you believe it violates this policy.
We acknowledge reports [[PLACEHOLDER: e.g. within 24 hours]] and investigate every one. Because of privacy obligations, we may not be able to tell you the outcome of an investigation into someone else's account.
8. Enforcement
We enforce this AUP on a ladder, matched to the severity of the violation:
- Warning. For first-time, minor, or accidental violations, with a reasonable deadline to fix the problem.
- Suspension. For repeated violations, or failure to fix the problem after a warning. Service is restored once the issue is resolved.
- Termination. For serious or persistent violations.
Severe cases skip the ladder: CSAM, active attack traffic originating from your account or Protected Infrastructure, and operating a booter or stresser service all mean immediate suspension or termination without warning. Where traffic to or from your Protected Infrastructure threatens other Customers or our network, we may rate-limit or null-route the offending destination to protect them — and we will tell you when we do. Accounts terminated for AUP violations are not eligible for refunds; see the Refund, Cancellation & Chargeback Policy.
9. Cooperation with law enforcement
Where the law requires, we report illegal activity to the competent authorities, preserve relevant evidence, and respond to valid legal process. How we handle such requests, and the data involved, is described in the Privacy Policy.
Version history
| Date | Change |
|---|---|
| Initial publication. |