Acceptable use
Updated August 13, 2026
Summary
The Incognito VPS acceptable-use policy prohibits child sexual abuse material, malware command-and-control, phishing, bulk unsolicited email, attacks against third-party systems, and content criminal in the jurisdiction hosting the server. We do not ask who you are; we do enforce what the servers are used for.
The principle
We do not ask who you are. We do enforce what the servers are used for. Those two positions are compatible, and holding both is what makes this service usable rather than a liability.
The practical reason is address reputation. Our IPv4 ranges stay deliverable because we remove the customers who make them undeliverable. A provider that accepts everything ends up with address space that nothing accepts.
Absolutely prohibited — immediate suspension without notice
These are suspended the moment they are confirmed, with no notice period and no appeal before action:
- Child sexual abuse material, in any form, without exception.
- Malware command-and-control, ransomware panels, exploit kits and botnet infrastructure.
- Phishing sites, credential-harvesting pages and brand-impersonation infrastructure.
- Active attacks against third-party systems: DDoS, intrusion attempts, credential stuffing, mass vulnerability scanning.
- Distribution of material constituting a serious criminal offence in the jurisdiction hosting the server.
Prohibited — notice and a response window
These receive the full report text and at least 72 hours to respond before any action is taken. Most are resolved by the customer without further involvement from us.
- Bulk unsolicited email, open mail relays and open DNS resolvers.
- Distributing content you do not have the right to distribute.
- Running services that generate sustained abuse reports from third parties.
- Resource use that materially degrades service for other customers on shared hardware.
- Collecting personal data in breach of law applicable to you or to the data subjects.
Explicitly permitted
Stated because these are commonly refused elsewhere and people ask.
- Tor middle relays, bridges and onion services. Exit relays are permitted after a conversation, so we can place them appropriately.
- VPN and proxy endpoints of any protocol, including anti-censorship transports.
- Adult content that is legal in the hosting jurisdiction and involves only consenting adults.
- Cryptocurrency nodes, validators, mining pools and trading infrastructure.
- Security research, including operating honeypots and hosting proof-of-concept code.
- Political speech, journalism, whistleblowing platforms and material critical of any government.
- Public-web data collection conducted at a reasonable rate.
How we find out
Reactively, and only reactively. We do not inspect traffic, scan customer disks, or log connections. Enforcement is driven by third-party reports sent to our abuse address and by blocklist signals against our own address space.
There is no automated content scanning of customer workloads and no plan to introduce any. What runs on your server is not visible to us and we prefer it that way.
Reporting
Send reports to [email protected]. Include the address or hostname, the specific conduct, timestamps with a timezone, and any logs you can share. Reports are read by a person, usually within a few hours.
Automated volume filings citing US statute at non-US servers receive a reply identifying the applicable jurisdiction, because that is the accurate response rather than a dismissive one.
55-second deploy
Pick a jurisdiction. Pay in crypto. Be running in a minute.
No account to create, no email to confirm, no card to enter.