Home / Legal
Acceptable Use Policy
Draft — not yet effective; requires legal review before publication. Last updated: [EFFECTIVE DATE]
This Acceptable Use Policy (the "AUP") is part of our terms of service with you. In it, "agent-next", "we", and "us" mean [LEGAL ENTITY NAME], and "Service" and "Sandbox" have the meanings given in the Terms. The AUP applies to everyone who uses the Service, and to everything done with an account's API Keys — including by AI agents, scripts, and other automated tools you configure.
The short version: use the Service for legitimate development, testing, and automation. Do not use it to break the law, attack anyone, abuse shared resources, or undermine the Service itself. You are responsible for what your agents and tools do. If you violate this AUP, the enforcement ladder in Section 13 applies.
1. Illegal content and activity
Do not use the Service to create, host, store, or distribute content that is illegal under applicable law, including:
- child sexual abuse material (CSAM) — we report incidents of CSAM to the National Center for Missing & Exploited Children (NCMEC) and to law enforcement as required by U.S. law;
- content that plans, promotes, or carries out violence, terrorism, or other serious crime;
- marketplaces or tools for illegal drugs, stolen data or credentials, or forged documents;
- catalogs or dumps of stolen personal data, credentials, or payment cards, however obtained; and
- fraud, scams, or deception that would be unlawful where committed.
You are responsible for knowing the laws that apply to what you do from a Sandbox, wherever you are.
2. Malware, attacks, and unauthorized access
Do not use the Service to:
- create, host, or distribute malware, ransomware, exploit kits, or other harmful code;
- publish poisoned software supply-chain artifacts — malicious packages, typosquatted names, or backdoored builds — to public registries from the Service;
- operate botnets, command-and-control servers, or similar attack infrastructure;
- launch, participate in, or facilitate distributed denial-of-service (DDoS) or other traffic attacks;
- scan, probe, or exploit systems or networks you do not own or are not explicitly authorized to test;
- conduct credential stuffing, brute-force attacks, or unauthorized authentication attempts;
- harvest credentials, session tokens, API keys, or other secrets from systems you are not authorized to access; or
- phish or social-engineer people into giving up credentials, access, or personal information.
Authorized security testing is fine — but only against systems you own or have written permission to test. Keep that permission on hand; we may ask to see it.
3. Spam and unsolicited messaging
Outbound email (SMTP, ports 25, 465, and 587) is blocked at the network level, and attempting to circumvent that block violates this AUP. Regardless of channel, do not use the Service to send spam or bulk unsolicited messages of any kind — email, chat, SMS, web forms, contact pages, in-app messages, or messages sent through any third-party API. This includes sending through throwaway or third-party accounts you do not control, and it includes transactional messaging to people who never asked for it.
4. Resource abuse
The Service's compute and network capacity is shared. Do not:
- mine cryptocurrency or run sustained CPU workloads characteristic of cryptomining — we detect sustained CPU abuse and act on it;
- evade, or attempt to evade, rate limits, quotas, network blocks, or other usage controls;
- run workloads whose evident purpose is to consume capacity rather than to develop or automate something — for example public file-hosting or media-streaming mirrors;
- create multiple accounts to farm the free grant — the grant is one per person or organization; or
- share your API Keys with untrusted parties or services in a way that effectively transfers your account to them.
We may adjust limits, blocks, and other technical controls (including rate limits and the SMTP block) at any time to protect the Service.
5. Proxy and network services
Do not run open proxies or public VPN exits, and do not resell proxy, VPN, or tunneling services through the Service. This includes Tor exit relays. Using a Sandbox as your own outbound network hop for your own work is fine; making the Service a public relay is not.
6. Attacking the Service itself
Do not attempt to:
- escape a Sandbox or otherwise break sandbox isolation;
- attack, overload, or probe our infrastructure, or that of our hosting providers;
- access, scan, or interfere with other tenants' Sandboxes or data;
- bypass or attempt to bypass authentication, tenancy separation, metering, or other account controls; or
- hammer our own API in ways that knowingly degrade it for other users.
7. Security research
Testing, probing, or scanning our infrastructure — the API gateway, the control plane, the sandbox runtime, or any other part of the Service — requires our prior written authorization, obtained before you begin. That authorization will identify the targets, the methods, and the duration of the research. Testing without it violates Section 6, whatever the intent.
If you believe you have found a security vulnerability in the Service, report it to [SECURITY EMAIL] with enough detail for us to reproduce and assess it. Do not access other tenants' Sandboxes or data, do not test third-party systems, and give us time to investigate and fix before any public disclosure. Research conducted within a written authorization from us, and vulnerability reports sent to that address, are not violations of this AUP, and we will not pursue claims against research that stays within its authorization. Authorization from us never extends to other tenants or to third-party systems. [SAFE-HARBOR AND DISCLOSURE TERMS]
8. Intellectual property and harassment
- Do not distribute or host content you know infringes someone's copyright, trademark, trade secret, or other intellectual property rights, and do not circumvent technical protection measures or licence enforcement.
- Do not use the Service to harass, threaten, or defame anyone, or to publish someone's private identifying information without their consent (doxxing).
- Do not impersonate agent-next, our staff, or our infrastructure partners, including via lookalike domains or misleading From: headers.
9. Copyright complaints (DMCA)
We respond to copyright complaints under the U.S. Digital Millennium Copyright Act and similar laws. If you believe content available through the Service infringes your copyright, send written notice to our designated agent: [DMCA DESIGNATED AGENT]. A notice that works must: identify the copyrighted work; identify the material you want removed clearly enough for us to find it; give your name, address, telephone number, and email; state your good-faith belief that the use is not authorized by the copyright owner, its agent, or the law; state, under penalty of perjury, that the information is accurate and that you are the owner or authorized to act for the owner; and be signed (physically or electronically).
When we receive a valid notice, we may remove or disable access to the material and take reasonable steps to tell the affected customer promptly.
A customer who believes their material was removed or disabled by mistake or misidentification may send a written counter-notice to that agent. To be effective, a counter-notice must include: a physical or electronic signature; identification of the material that was removed or to which access was disabled, and the location at which it appeared before it was removed or disabled; the customer's name, address, and telephone number, and a statement that the customer consents to the jurisdiction of the U.S. federal district court for the judicial district of their address — or, if their address is outside the United States, of any judicial district in which we may be found — and that they will accept service of process from the person who sent the original notice or that person's agent; and a statement, under penalty of perjury, that the customer has a good-faith belief that the material was removed or disabled as a result of mistake or misidentification.
When we receive a valid counter-notice, we promptly send a copy to the person who sent the original notice and inform them that we will restore the material. Unless our designated agent first receives notice from that person that they have filed a court action seeking to restrain the customer from engaging in infringing activity relating to the material, we replace the removed material and cease disabling access to it not less than 10, nor more than 14, business days after receiving the counter-notice. [DMCA COUNTER-NOTICE AND RESTORATION PROCESS]
We terminate the accounts of customers who repeatedly infringe copyright under our repeat-infringer policy: [REPEAT INFRINGER POLICY]. Knowingly making a false claim or counter-claim in this process may violate this policy and the law.
10. Scraping
Scraping public data through a Sandbox is not banned outright. Scraping that violates the target site's terms of service or applicable law is. If a target prohibits automated access or requires a licence you do not have, do not automate against it from the Service.
11. Sanctions and export controls
Do not use the Service if you are located in, ordinarily resident in, or organized under the laws of a country or region subject to comprehensive sanctions, or if you are identified on an applicable sanctions or export-control list. Do not use the Service to provide services to such persons or regions, or in violation of applicable export-control laws.
12. Other harmful conduct
This policy names the abuses we see most often; it is not an exhaustive list of everything prohibited. Conduct that is materially similar to what is listed, or that harms or risks harm to us, our users, our infrastructure providers, or third parties, may violate this AUP even if it is not spelled out above. If you are unsure whether a planned use fits, ask us at [ABUSE EMAIL] before you build it.
13. Enforcement
We enforce this AUP to protect the Service, our users, our infrastructure providers, and ourselves. Enforcement generally escalates with severity, but nothing obliges us to warn first:
- Warning. We tell you what we saw and ask you to stop or fix it.
- Technical limits. Throttling, reduced quotas, blocked network access, or API Key revocation.
- Suspension. Your account is suspended: you can no longer create, resume, or connect Sandboxes or reach your Sandboxes' network endpoints, and running Sandboxes may be paused. Your API Key keeps working for the remaining operations, such as listing, pausing, or deleting your Sandboxes and reading your usage.
- Termination. Your account is closed and your remaining Sandboxes deleted.
We may act immediately, without prior notice, when the situation warrants it — for example CSAM, an ongoing attack, active exploitation, or an abuse report from our hosting provider. We cooperate with abuse reports from our hosting providers and with lawful requests and legal process, and we may report conduct to law enforcement or, for CSAM, to NCMEC where the law requires it.
Some enforcement is automated. Rate limits, the hour-budget control that pauses running Sandboxes when an account's hours are exhausted or its API Key is revoked, and automated abuse detection that throttles or suspends accounts all act without a person in the loop. If you believe an enforcement action or an automated restriction affecting your account is mistaken, contact [ABUSE EMAIL] with your account details and the context you think matters. [CONFIRMED ENFORCEMENT REVIEW PROCESS]
14. Reporting abuse
If you see abuse coming from the Service, email [ABUSE EMAIL] with what you know: sandbox or account identifiers if visible, timestamps, relevant logs or URLs, and why you believe it violates this policy. We may ask follow-up questions. Reports from third parties are treated in confidence to the extent the law allows.
15. Changes
We may update this AUP as the Service and abuse trends evolve. We will announce material changes as described in the terms of service. An updated AUP takes effect for you after the notice period described there, except urgent legal or safety changes, which may take effect immediately with prompt notice.