Acceptable use
What is not allowed on axnet's platform, and what axnet does about it.
Version 0.2Updated Adopted by axnet on
1. Scope
1.1 This policy is part of the terms and conditions (article 10). It applies to every customer, every user and every resource, and to anyone with access through the customer.
1.2 The customer is responsible for everything that runs on its machines or comes from its addresses, also after a break-in.
1.3 Unsure about a use case? Ask first through info@axnet.nl.
2. Illegal content
2.1 Not allowed: content and activities that breach Dutch or European law, including:
- child sexual abuse material (CSAM), in any form;
- terrorist content;
- infringement of copyright, trademarks or other intellectual property;
- scams, fraud and trade in illegal goods or services;
- threats, defamation, incitement to hatred and spreading other people’s private data;
- unlawful processing of personal data.
2.2 For child sexual abuse material, axnet acts at once and reports it to the police.
3. Malware and phishing
3.1 Not allowed:
- spreading or offering malware, ransomware and exploits;
- botnets and command-and-control servers;
- phishing: sites and messages that pose as someone else to obtain data or money.
4. Spam and mail
4.1 No spam: unsolicited electronic messages (art. 11.7 of the Dutch Telecommunications Act), also not through third parties or bought address lists.
4.2 No open relays, open proxies or other services that let third parties send mail or traffic through the customer.
4.3 Outbound mail (port 25) is closed for new accounts. axnet opens it on request and may close it again after spam or an open relay.
4.4 Anyone sending newsletters or other bulk mail has the recipients’ consent and processes unsubscribes at once.
5. Network
5.1 Not allowed:
- DDoS attacks, including “stress tests” of systems the customer does not own;
- scanning other people’s systems for ports or vulnerabilities without their permission;
- breaking in or trying to, such as brute-forcing passwords;
- IP spoofing: traffic with a source address not assigned to the machine;
- open resolvers and other services that lend themselves to amplification attacks, such as open DNS, NTP or memcached;
- disrupting axnet’s network or other customers.
5.2 axnet also filters spoofed traffic itself, on every machine: Protected by axnet.
6. Resale
6.1 Reselling or renting out machines, access or IP addresses to third parties requires axnet’s written permission.
6.2 Even then, the customer remains responsible for what those third parties do.
7. Crypto mining
7.1 Crypto mining: not allowed.
8. Enforcement
8.1 axnet investigates notices through Report abuse and its own observations.
8.2 axnet chooses the lightest measure that works (terms, article 11.4):
- asking the customer to stop the abuse, with a deadline;
- restricting port 25 or other traffic;
- taking a machine or address off the network, or stopping the machine;
- suspending the account or terminating the agreement.
8.3 In acute danger, axnet acts at once, without a deadline: for child sexual abuse material, an ongoing attack, or malware or phishing that causes harm. axnet then tells the customer why as soon as possible.
8.4 With every measure, the customer receives a statement of reasons (DSA art. 17). It objects by e-mail to misbruik@axnet.nl (terms, article 11.6).
8.5 In case of serious or repeated abuse, axnet may terminate the agreement at once (terms, article 8.4).
8.6 The customer indemnifies axnet against third-party claims arising from abuse (terms, article 14.5).
8.7 axnet cooperates with competent authorities where the law requires it.
9. Reporting
9.1 Abuse: Report abuse or misbruik@axnet.nl.
9.2 A vulnerability in axnet: Responsible disclosure.