Version v1; this document is the contractual basis for enforcement actions
and is incorporated into the Terms of Service. Published
versions are archived and never edited in place.
The short version: don't attack anyone, don't spam, don't host what's
illegal under US law, and respond when we contact you. AGIdock is
deliberately permissive — full root, your own firewall, no platform
filtering beyond anti-spoof and a blocked outbound :25 — because the target
customer is a professional running competent agents.
That permissiveness survives only if abuse is rare and dealt with fast.
Prohibited
Attacks: DoS/DDoS in any direction, unauthorized access attempts,
vulnerability scanning of third parties without documented authorization,
malware command-and-control, credential stuffing, IP/MAC spoofing
(technically prevented, contractually prohibited).
Spam and sender fraud: unsolicited bulk email, purchased lists,
snowshoe patterns, From-domain forgery. The relay's tier and scoring
system is the technical wall; this clause is the contractual one. The
email relay is for mail your recipients asked for.
Illegal content under California or US federal law, including CSAM
(reported to authorities without notice), non-consensual intimate imagery,
and content infringing others' rights after valid notice (see
DMCA).
Fraud against us: stolen payment instruments, signup-code farming,
ban evasion via new accounts.
Resource abuse: workloads whose product is CPU time itself, mining
above all. vCPUs are derived from the RAM you buy and billed at zero, and
hosts are packed on the assumption of ordinary duty cycles, so a machine
held at full load indefinitely is taking capacity from its neighbours
rather than capacity it paid for. Bursts are fine — builds, batch jobs,
inference, whatever your work actually needs. Also prohibited: anything
that degrades other tenants' service beyond your VM's own resources.
Your obligations
Keep services you expose reasonably secured; a compromised VM used for
attacks is your problem within 48 hours of notice, then ours.
Keep the account email responsive. Abuse notices go there; silence
escalates enforcement.
If you run agents autonomously (expected!), you remain responsible for
everything they do with your credentials.
Enforcement ladder
Proportional and mostly automated at the low end; humans decide anything
destructive:
1. Signals (spam rejects, traffic anomalies, external reports)
accumulate into a per-account score that decays over time (half-life
~72 h) — one-off mistakes age out.
2. Automatic, reversible: sustained spam rejects freeze email sending
for the account. High-confidence attack traffic blocks the offending
flow. Both lift on review.
3. Human-decided: account suspension, resource termination, and
anything irreversible always require a human on our side; you get
notice and, where lawful, a chance to respond and export data.
4. Immediate action without prior notice is reserved for ongoing harm
(active attacks, CSAM, court order).
Enforcement actions are recorded and, except where legally barred, visible
to you (GET /v1/compliance/cases). Disputes: reply to the case, or email
abuse@agidock.cloud.
Reporting abuse
Report abuse by an AGIdock customer to abuse@agidock.cloud with logs
(timestamps + IPs). We answer within 2 business days;
DMCA notices go to the designated agent.