Acceptable use policy
Root access on our hardware, on a network shared with other customers. This page is the short list of things that get a server switched off.
Last updated 17 September 2026
You get full root or administrator access to your instance, which means you can run almost anything on it. This policy is about the small set of things you cannot, either because they are illegal or because they damage the network and the people sharing it with you. It is part of the terms of service.
1. Who this applies to
This policy applies to you, to anyone you give access to your instance, and to anyone using a service you run on it. If you resell capacity, host other people's sites or operate a community, their conduct is your responsibility to us: we act on the instance and the account, not on your users, so you need your own terms and your own means of enforcing them.
It applies to every region equally. Activity that is legal where you are may still be prohibited here, and content hosted in one region remains subject to the law applying to that region and its facility.
2. The general standard
Do not use the service to break the law, to harm other people, or to interfere with anybody else's use of the network. The sections below are concrete examples rather than an exhaustive list, and something is not permitted merely because it is not named here.
Two more points of the same kind:
- Do not misrepresent who you are in order to obtain or keep service, including false registration details, stolen payment methods, or a new account opened to evade a suspension.
- Do not use the service in a way that damages the reputation of our address space, our network, or the facilities that host it. Address blocks are shared infrastructure and getting them listed as a source of abuse affects every customer in them.
3. Email, spam and bulk messaging
You must not use the service to send or facilitate:
- Unsolicited bulk email, of any volume. The test is consent, not quantity: mail sent to addresses that did not ask for it is spam whether it goes to ten recipients or a million.
- Mail to purchased, scraped, harvested or otherwise non-consenting address lists, including lists you acquired from a third party who claimed they were opted in.
- Mail with forged headers, a forged envelope sender, a misleading subject line, or a reply path designed to hide its origin.
- Mail with no functioning unsubscribe mechanism where the recipient is entitled to one, or continued mail to a recipient who has unsubscribed.
- Any part of a spam operation run elsewhere: list management, address verification, bounce processing, redirector or tracking domains, landing pages, or payment pages for a campaign sent from another network. Hosting the machinery counts.
- Unsolicited bulk messaging through other channels, including SMS gateways, messaging platforms, forum, comment and wiki spam, and automated account creation on third-party services.
If you send legitimate bulk mail, such as your own product or transactional mail, configure it properly: authenticate it, publish the records that let receivers verify it, honour unsubscribes promptly, and handle your own bounces and complaints. Your sending reputation is yours to manage, and the effect of your mail on our address space is what we act on.
4. Network abuse
You must not, from your instance or through it:
- Launch, participate in, or knowingly contribute to a denial of service or distributed denial of service attack, at any layer and by any method, including volumetric floods, application-layer floods and slow-connection attacks.
- Operate, rent, advertise or sell an attack service. A stresser or booter is an attack service regardless of the disclaimer on its landing page, and so is a control panel for one hosted here while the traffic leaves from somewhere else.
- Take part in a reflection or amplification attack, whether as the source of the spoofed requests or by running a service that reflects and amplifies them. Section 10 covers the services most often used this way.
- Scan ports, addresses, or services on networks you do not own and have no written permission to test. Occasional stray traffic from a misconfigured tool is not what this targets; sweeping ranges is, and it generates complaints that reach us.
- Spoof source addresses, forge packet headers, or otherwise send traffic that misrepresents where it came from. Spoofed traffic from our address space is treated as a serious breach because it makes our network a weapon against others.
- Interfere with the routing or addressing of the network, including hijacking or announcing address space you do not control, ARP or neighbour-discovery poisoning on the local segment, DHCP interference, and unauthorised tunnelling designed to bypass platform controls.
- Attempt to reach the management network, another customer's instance, the virtualisation layer, or any part of our infrastructure that is not allocated to you, including by sniffing traffic that is not yours.
- Use addresses other than those assigned to you, or continue using an address after it has been reassigned.
5. Intrusion and unauthorised access
You must not use the service to:
- Attempt to gain access to any system, account, network or data without authorisation, including by exploiting a vulnerability, by social engineering, or by bypassing an authentication or licensing control.
- Run credential stuffing, password spraying or brute force attacks against authentication endpoints anywhere, including SSH, RDP, mail, admin panels and APIs.
- Distribute, trade in or process stolen credentials, breach data, card numbers, personal data obtained unlawfully, or the tooling built to check and monetise them.
- Operate a service that harvests credentials from unwitting users, or that proxies a login flow in order to capture what passes through it.
- Circumvent a rate limit, access control, ban or block imposed by a third-party service in order to extract data or abuse it.
6. Malware, phishing and attack infrastructure
You must not host, store, distribute, link to or operate:
- Malware of any kind, including viruses, worms, trojans, droppers, loaders, ransomware, keyloggers, stealers, rootkits and cryptographic mining payloads installed on machines without their owner's knowledge.
- Command and control infrastructure for a botnet or malware family, including panels, tasking servers, exfiltration endpoints, payload staging, dead-drop resolvers, and proxy or fast-flux layers that front any of them.
- Phishing pages, fake login portals, brand impersonation sites, fraudulent stores, or the kits and templates used to build them.
- Fraud infrastructure more generally: advance fee and romance fraud operations, fake support services, fraudulent cryptocurrency or investment schemes, carding shops, and services that exist to launder the proceeds of any of them.
- Exploit kits, drive-by download infrastructure, or malicious redirect and traffic distribution systems.
Malware samples held for legitimate defensive research are treated under section 11 and require containment and, if in doubt, a word with us first.
7. Child sexual abuse material
There is zero tolerance for child sexual abuse material on this platform. Storing, hosting, distributing, producing, advertising, linking to or facilitating access to material that sexually exploits or abuses a child is absolutely prohibited, in every region, with no exception and no warning step.
On a credible report or discovery, the instance is suspended immediately and the account is terminated. We preserve the evidence, we report to law enforcement and the relevant reporting bodies, and we cooperate fully with their investigation. There is no notice period, no opportunity to remediate, and no appeal on the substance of this section.
This also covers the surrounding activity: solicitation or grooming of children, trafficking, and services built to index or distribute such material. Report anything of this kind to abuse@roguewavehosting.com and mark it urgent in the subject line.
8. Other illegal and infringing content
You must not use the service to host, distribute or facilitate:
- Material that infringes copyright, trademark or other intellectual property rights, including unlicensed film, television, music, books, software, games and fonts, and including indexes, trackers, link sites and stream relays whose purpose is to make infringing material available.
- Circumvention of technical protection measures, licence servers, cracks, keygens and pirated licence distribution.
- Content that is illegal in the region where it is hosted, or whose distribution from that region is illegal.
- Threats, harassment campaigns, doxxing, stalkerware, non-consensual intimate imagery, and material that incites violence or terrorism.
- Trade in controlled substances, weapons, or other goods whose sale requires a licence you do not hold.
- Impersonation of a person or organisation in order to deceive, including counterfeit goods and forged documents.
Rights holders and their agents can send infringement notices to abuse@roguewavehosting.com. Identify the work, the URL or address where it appears, and the basis of your claim, and we will forward it to the account holder and act under section 14 where required.
9. Resource abuse and shared capacity
Your vCPU is dedicated and is never oversubscribed, so a busy process of yours does not take CPU time from anybody else. Disk and network capacity are shared, and that is where one customer can degrade another. You must not:
- Generate sustained disk input and output at a level that degrades storage performance for other instances on the same host, including pathological small-random-write patterns, tight write loops, and unthrottled synthetic disk benchmarks left running.
- Saturate network capacity or the packet-per-second capability of a host in a way that affects other customers, including sustained floods of very small packets and unthrottled transfer loops.
- Open connections or sockets at a rate that exhausts shared network state, including large-scale connection churn and mass outbound connection attempts.
- Run anything designed to consume as much shared capacity as it can obtain, or to probe for the limits of the platform's isolation.
The standard is effect, not category. Any workload is acceptable while it stays inside the resources you bought and does not degrade the instances around you. If your workload is outgrowing its plan, upgrade it: memory and disk are expandable, upgrades are prorated and no rebuild is required.
Cryptocurrency mining and similar workloads
Mining, hashing, proof-of-work and comparable compute-saturating workloads are not prohibited as a category, and your dedicated vCPU is yours to use. They are, however, fully subject to this section: the moment such a workload degrades shared disk or network capacity for other customers, it is resource abuse and we will treat it as such. Two conditions always apply. The mining must be on your own hardware allocation and for your own account, and any mining conducted on machines without their owner's consent, or using a stolen or fraudulent payment method to obtain the instance, falls under sections 6 and 2 instead and is prohibited outright.
10. Open resolvers, relays and proxies
A service that will act for anyone who asks becomes somebody else's attack tool, usually within days of being exposed. You must not run, and must configure to prevent:
- Open DNS resolvers. A recursive resolver answering queries from arbitrary addresses. Restrict recursion to your own networks, or to authenticated clients, and serve authoritative zones without recursion.
- Open mail relays. An SMTP service that relays mail for unauthenticated senders. Require authentication for submission and accept mail for your own domains only.
- Open proxies. An HTTP, SOCKS or similar proxy usable by anyone. A proxy or VPN service with real authentication and your own accounting is acceptable; an unauthenticated one is not, and you remain responsible for traffic your users send through it.
- Other amplifiable services left open. NTP with monitoring commands enabled, unauthenticated memcached or Redis reachable from the internet, SNMP with a default community string, and similar services exposed without access control.
You open your own ports through the firewall on your VPS, so exposing one of these is a configuration decision on your side. We may notify you that a service on your instance is reachable and amplifiable and ask you to close or restrict it, and we may restrict traffic to it while it is being abused.
11. Security testing and research
Defensive research, malware analysis and penetration testing are legitimate uses of a VPS, within limits:
- Test only systems you own or have written authorisation to test, and keep that authorisation available in case a complaint reaches us.
- Keep samples contained. Malware held for analysis must not be reachable from the internet, must not be able to call out, and must not be distributed from the instance.
- Do not use the instance as the origin of exploitation traffic against third parties, with or without an engagement letter from someone else.
- If you are planning something that could look like an attack from the outside, tell us at support@roguewavehosting.com beforehand. It is much easier to check a note on file than to leave a suspicious traffic pattern running while we try to reach you.
Found a vulnerability in our platform? Report it to support@roguewavehosting.com with "security" in the subject line and enough detail to reproduce it, and do not use it beyond what is needed to demonstrate the issue.
12. If your server is compromised
You hold root access, you install the software, and you decide which ports to open, so securing the instance is yours. Servers still get compromised, and a compromised server attacking other people is treated the same way as a deliberate attack, because the effect on the network is identical. What differs is how we handle you.
If we see attack, scan or spam traffic leaving your instance we will contact you and, where the traffic is causing ongoing harm, restrict or suspend the instance first and explain afterwards. To get it back:
- Find and close the way in rather than only killing the process you can see.
- Rotate every credential and key on the instance, and anything reused elsewhere.
- Patch the operating system and the application that was exploited, or reinstall. An instance you cannot account for is better rebuilt than cleaned, and a reinstall destroys the data on the disk.
- Tell us what you found and what you changed, in the ticket. The question we have to answer is whether the traffic will start again.
Note that no backup or snapshot service is provided, so rebuilding after a compromise depends entirely on copies you keep yourself.
13. Reporting abuse
Send reports about activity originating from our network to abuse@roguewavehosting.com. Reports are read by people, and a report with evidence in it gets acted on faster than one without.
Include:
- The address involved, which is the IPv4 address on our network that you saw the activity from or the address of the content you are reporting.
- Timestamps with the time zone stated. A time without a zone or offset costs us a round trip and can make a log search inconclusive.
- Unedited log excerpts showing the activity, with enough surrounding context to be meaningful. For network abuse, include the ports and protocol and the direction of the traffic.
- For spam, the full message headers. The body alone rarely identifies the source; the headers usually do.
- For content reports, the full URL and a description of what is wrong with it, rather than a screenshot alone.
- A contact address in case we need to ask a question.
We may pass your report, including its technical detail, to the account holder so they can fix the problem, since most abuse is a compromise rather than a choice. Tell us in the report if you need your identity withheld and we will forward the technical detail without it. Reports about child sexual abuse material are handled under section 7 and are never forwarded to the account holder.
Please do not send abuse reports to the support address; it slows them down. Send infringement notices and content complaints to the abuse address too.
14. Enforcement
We would rather fix a problem than lose a customer, so enforcement escalates. How far up the ladder we start depends on the severity of what is happening and whether it is ongoing:
- Notice. We contact the account holder, describe the activity and the evidence, and ask for it to be stopped or the vulnerability closed within a stated period. Most cases end here.
- Technical restriction. Where the activity continues or the harm is ongoing, we may limit the instance rather than switch it off: restricting traffic to or from a specific port or protocol, rate limiting outbound traffic, or blocking a destination. This keeps the rest of your service running while the abuse stops.
- Suspension. The instance is taken offline. We suspend without prior notice where activity is causing ongoing harm, where an instance is actively attacking others, or where the law requires it, and we notify you afterwards. Suspension does not stop charges accruing.
- Termination. For unresolved suspensions, repeat breaches, and serious single breaches. Termination ends the agreement and releases the storage, and the data on it cannot be recovered afterwards.
Section 7 has no ladder: child sexual abuse material means immediate suspension and termination.
We may also, where it is necessary and proportionate, preserve evidence of the activity, report it to law enforcement or the relevant authority, and comply with a lawful order requiring us to act.
Responding to an enforcement action
Reply to the notice we sent, or write to support@roguewavehosting.com with the reference from it. Tell us what the activity actually was, what you have changed, and why it will not recur. A reinstated instance that resumes the same activity goes straight to termination.
If you believe a report was mistaken, say so and explain why, with your own logs. Abuse reports are sometimes wrong, and we would rather be shown that than defend a bad decision. Opening a new account to get around a suspension, by contrast, is itself a breach under section 2 and ends both accounts.
15. Changes to this policy
Abuse changes, so this policy does too. The date at the top of the page shows when the current version took effect, and we will notify account holders by email of a change that materially affects what is permitted. Changes needed to address an active abuse or security problem may take effect immediately.
16. Contact
- Abuse reports, infringement notices and content complaints: abuse@roguewavehosting.com
- Enforcement questions, appeals and everything else: support@roguewavehosting.com
- Privacy and data protection requests: privacy@roguewavehosting.com
Related pages: terms of service, service level and privacy policy.