Last Updated: 01-Feb-2025
Abuse Policy
Acriotech provides enterprise-grade technology infrastructure and software services. This Abuse Policy governs what constitutes unacceptable use of Acriotech's network, APIs, cloud infrastructure, software platforms, and any services provided to clients and end-users. We are committed to maintaining a safe, reliable, and law-abiding environment for all our clients, their end-users, and the broader internet community.
Zero Tolerance: Acriotech maintains a zero-tolerance policy for abuse. Violations will result in immediate service suspension, account termination, forfeiture of prepaid fees, and may be referred to law enforcement.
1. Scope of This Policy
This policy applies to:
- Direct clients of Acriotech who use our professional services or hosted software platforms.
- End-users of enterprise software systems built and operated by Acriotech on behalf of our clients.
- Third parties who interact with, or attempt to interact with, Acriotech infrastructure.
- Acriotech employees, contractors, and partners who access internal systems.
Regardless of where a user is located, use of Acriotech services constitutes acceptance of this Abuse Policy. Acriotech reserves the right to act on any abuse of our systems originating from any jurisdiction.
2. Prohibited Activities
2.1 Network & Infrastructure Abuse
- Denial of Service (DoS/DDoS) Attacks: Launching, facilitating, or directing distributed denial-of-service attacks against Acriotech's infrastructure, other Acriotech clients, or any third-party system.
- Network Intrusion: Unauthorized attempts to access, probe, scan, or compromise any Acriotech or third-party network, server, database, or system.
- Resource Hijacking: Using Acriotech's compute, storage, or network resources for purposes beyond the scope of your agreement — including unauthorized cryptocurrency mining, rendering workloads, or providing services to undisclosed third parties.
- IP Address Spoofing: Forging, spoofing, or otherwise misrepresenting the source IP address of traffic originating from Acriotech's network.
- Traffic Amplification: Using Acriotech systems as open proxies, relays, or reflectors to amplify traffic in attacks against third parties.
2.2 Malicious Code & Security Threats
- Hosting, distributing, or transmitting malware, ransomware, spyware, adware, trojans, rootkits, or any other malicious software.
- Operating command-and-control (C2) infrastructure for botnets or malware campaigns.
- Creating, deploying, or testing exploits against production systems (production security testing requires prior written authorization from Acriotech's Security team).
- Hosting phishing pages, credential harvesting sites, or fraudulent impersonations of legitimate organizations.
2.3 Illegal and Harmful Content
- Hosting, storing, distributing, or transmitting any content that is illegal under applicable international law, including child sexual abuse material (CSAM), content facilitating terrorism or extremist violence, or content facilitating human trafficking.
- Operating marketplaces for illegal goods or services, including unregulated weapons, narcotics, stolen financial data, or access credentials.
- Content that constitutes harassment, stalking, or targeted intimidation of an individual.
2.4 Data Integrity & Fraud
- Unauthorized access to, exfiltration of, or tampering with another user's or organization's data stored within Acriotech-managed systems.
- Circumventing authentication, authorization, billing controls, or API rate limits through technical means.
- Creating multiple accounts to evade a suspension or circumvent usage limits.
- Providing false or misleading information during account registration or contracting that materially affects the nature of the services provided.
2.5 Unauthorized Use of AI Features
- Using Acriotech AI infrastructure or APIs to generate child sexual abuse material, deepfakes of real individuals without their consent, or content designed to facilitate real-world violence.
- Attempting to extract training data, model weights, or system prompts from Acriotech AI systems through prompt injection, jailbreaking, or reverse engineering.
- Using AI systems to automate large-scale disinformation campaigns, impersonation attacks, or spam.
3. Consequences of Policy Violations
Upon detection or credible report of an abuse policy violation, Acriotech may take one or more of the following actions, depending on the severity, whether it is a first or repeat offense, and whether the violation was intentional:
Written warning, requirement to acknowledge policy, temporary throttling of API access.
Immediate suspension of the affected service or feature pending review. No refund for suspended period.
Immediate and permanent termination of all Acriotech accounts and services. Forfeiture of all prepaid fees. Referral to industry blocklists.
All of the above, plus referral to law enforcement and cooperation with criminal investigations. Preservation of evidence per legal hold procedures.
4. Monitoring and Detection
Acriotech actively monitors its network and infrastructure for abuse patterns using a combination of automated tools and human analysis. Our Security Operations Center (SOC) operates 24/7 and receives threat intelligence feeds from industry partners, ISACs, and government cybersecurity bodies to identify emerging threats.
By using Acriotech services, you consent to this monitoring for the purpose of enforcing this policy and maintaining the security and integrity of our infrastructure. All monitoring is conducted within the bounds of applicable law and our Privacy Policy.
5. Responsible Disclosure
If you are a security researcher who has discovered a potential vulnerability in Acriotech's systems, we strongly encourage responsible disclosure rather than exploitation. Please report your findings to our security team at security@acriotech.com before any public disclosure. We commit to:
- Acknowledging your report within 2 business days.
- Providing regular updates on the remediation status.
- Not pursuing legal action against researchers who act in good faith and within this responsible disclosure framework.
- Publicly acknowledging your contribution (with your permission) once the vulnerability is patched.
6. Reporting Abuse
If you believe Acriotech's infrastructure, network, or a client operating on Acriotech's platform is being used for abusive purposes, please report it immediately. Provide as much detail as possible, including:
- The nature of the abuse (e.g., DDoS source, phishing site, spam source).
- IP addresses, domain names, URLs, or any other identifiers involved.
- Timestamps and any relevant log excerpts or screenshots.
- Any harm already caused to you or your organization.
Abuse Reporting: abuse@acriotech.com
Security Issues: security@acriotech.com
All reports are treated confidentially. We target a first response within 24 business hours.