Last updated: 29 August 2026
This Acceptable Use & Abuse Policy (“AUP”) sets rules for use of Services supplied under the WEBDANGER brand by boxbank s.r.o.
Its purpose is to protect Customers, internet users, networks, domains, infrastructure, third parties, WEBDANGER and upstream providers from unlawful, abusive, malicious, deceptive or materially harmful use.
This AUP forms part of the applicable WEBDANGER contract where incorporated by the Terms of Service, an Order or service-specific terms.
Nothing in this AUP requires WEBDANGER to permit activity prohibited by applicable law, a binding authority order, registrar/registry policy, ICANN policy or mandatory upstream-provider requirement.
1. Service provider
WEBDANGER is operated by:
boxbank s.r.o. Jana Palacha 510/50 278 01 Kralupy nad Vltavou Czech Republic
IČO: 24048232
Registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, File No. 437675.
General contact:
contact@webdanger.com
Telephone / SMS:
+420 734 627 827
2. Scope
This Policy may apply to Services including:
- domain registration and management;
- DNS;
- hosting;
- cloud;
- virtual and dedicated servers;
- storage and backups;
- websites and applications;
- APIs;
- CRM/ERP systems;
- email-related Services;
- monitoring;
- security tools;
- vulnerability or website scanners;
- AI-enabled features;
- automation;
- and other WEBDANGER Services.
A service-specific policy may impose additional restrictions.
3. Customer responsibility
Customers are responsible for activity carried out through their accounts, credentials, domains, servers, applications and authorised users, except to the extent the activity results from WEBDANGER's own breach or another circumstance for which the Customer is not legally responsible.
Customers must take reasonable measures to prevent unauthorised use.
4. Law and upstream rules
Customers must comply with:
- applicable law;
- this AUP and the Terms;
- applicable registrar and registry rules;
- ICANN policies where applicable;
- upstream infrastructure restrictions incorporated into the relevant Service;
- binding court or authority orders;
- intellectual-property rights;
- and service-specific technical rules.
An upstream restriction applying only to a particular infrastructure product is not represented as a universal legal prohibition outside that product.
MALICIOUS AND UNAUTHORISED ACTIVITY
5. Unlawful use
Customers must not knowingly use WEBDANGER Services to organise, facilitate, conceal or carry out unlawful activity.
6. Malware
Customers must not use WEBDANGER Services to deploy, distribute, host, control or knowingly facilitate malicious software, including malicious:
- ransomware;
- trojans;
- spyware;
- credential stealers;
- worms;
- loaders;
- droppers;
- backdoors;
- destructive payloads;
- remote-access malware;
- or cryptominers deployed without authority.
Legitimate defensive malware analysis may be permitted only in an isolated, authorised environment expressly supporting that activity.
7. Botnets
Operating, controlling, coordinating or knowingly facilitating a botnet is prohibited.
Legitimate distributed computing using knowingly authorised devices is not a botnet merely because it is distributed.
8. Phishing
Phishing and credential theft are prohibited.
Customers must not host deceptive login pages, distribute phishing links, operate phishing kits, collect passwords without authority or redirect users to credential-stealing services.
9. Pharming and malicious redirects
Customers must not manipulate DNS, routing, redirects, hosts or similar infrastructure to redirect users deceptively to malicious destinations.
10. Credential attacks
Prohibited activity includes:
- credential stuffing against systems without authorisation;
- password spraying against third parties;
- session/token theft;
- MFA bypass;
- account takeover;
- or trading stolen credentials.
11. Unauthorised access
Customers must not access or attempt to access a system, network, account, database, API or device without lawful authorisation.
Public reachability is not by itself authorisation to perform intrusive testing.
12. Exploitation
Customers must not exploit vulnerabilities in third-party systems without authorisation, including unauthorised:
- remote-code execution;
- privilege escalation;
- persistence;
- data exfiltration;
- destructive testing;
- or exploit deployment.
SECURITY TESTING
13. Passive website audits
Low-impact analysis of publicly accessible information may be permitted, including:
- HTTP/TLS configuration;
- public DNS;
- security headers;
- certificate information;
- public technology metadata;
- ordinary public-page analysis;
- accessibility/performance analysis.
Passive review must not be used as a pretext for unauthorised exploitation.
14. Active security testing
Active testing can include port scanning, vulnerability probing, protocol enumeration, authenticated scanning, fuzzing or exploit validation.
WEBDANGER permits active testing only where:
- the Customer owns the target or has verifiable authorisation;
- scope is defined;
- testing is lawful;
- the WEBDANGER product expressly supports it;
- the infrastructure from which the test originates permits it;
- safety/rate limits are followed;
- unrelated systems are not targeted.
15. Upstream scanning restrictions
Where a WEBDANGER Service uses infrastructure whose provider prohibits scanning foreign networks or foreign IP addresses, Customers must comply with that restriction.
For Hetzner-backed infrastructure, Customers must comply with the system and product policies applicable to the ordered Service. Where those policies prohibit scanning foreign networks or foreign IP addresses, that restriction applies in full.
WEBDANGER may provide active security-testing functionality only through infrastructure whose rules expressly permit the relevant testing.
16. Proof of control
WEBDANGER may require proof of target control or testing authority, including:
- DNS TXT verification;
- HTML/file verification;
- administrative integration;
- domain-email verification;
- written authorisation;
- or another reasonable verification method.
For intrusive testing, a checkbox alone may be insufficient.
17. Scope containment
Authorised testing must remain within the verified target scope.
Customers must not intentionally pivot into other customers' systems, shared infrastructure outside scope, upstream management networks or unrelated IP space.
18. Password auditing
Password-strength testing may be performed only on systems/data the Customer is authorised to audit.
Cracking or attacking third-party credentials without authorisation is prohibited.
19. Load testing
Controlled load testing is permitted only where:
- the target is owned or authorised;
- the relevant infrastructure providers permit the test;
- safety limits are observed;
- unrelated systems are not reasonably endangered.
20. DDoS
Launching, purchasing, coordinating or facilitating unauthorised DoS/DDoS attacks is prohibited.
“Booter” or “stresser” services used to attack systems without authority are prohibited.
21. IP spoofing
Fake/spoofed source IP use is prohibited where the applicable Service/upstream provider prohibits it or where used for deception, abuse or unlawful activity.
EMAIL AND MESSAGING
22. Spam
Unsolicited bulk messaging and spam are prohibited.
Customers must not use WEBDANGER infrastructure for:
- unauthorised bulk commercial email;
- bulk unsolicited SMS;
- unlawful purchased-list campaigns;
- deceptive messaging;
- malicious-link campaigns;
- or messaging that violates applicable electronic-marketing law.
23. Lawful messaging
This does not prohibit:
- transactional messages;
- password resets;
- security notices;
- lawful opt-in marketing;
- lawful existing-customer communications;
- or other communications sent with an appropriate legal basis.
24. Sender identity
Customers must not deliberately falsify sender identity or conceal origin for fraud, abuse or evasion.
25. Open relays
Customers must not knowingly operate open mail relays, compromised spam systems or repeatedly abusive mail infrastructure.
WEBDANGER may restrict outbound mail where needed to control abuse and protect network/IP reputation.
DOMAINS AND DNS
26. DNS Abuse
For relevant domain Services, WEBDANGER treats the following as core DNS Abuse categories consistent with the current ICANN contractual definition:
- malware;
- botnets;
- phishing;
- pharming;
- spam when spam serves as a delivery mechanism for one of the preceding forms of DNS Abuse.
Ordinary unsolicited advertising may still violate this AUP even where it falls outside ICANN's narrower DNS Abuse definition.
27. Malicious domains
Customers must not register or use domains primarily to:
- phish;
- distribute malware;
- control botnets;
- pharm;
- deliver malicious payloads;
- impersonate persons/businesses fraudulently;
- facilitate unlawful fraud;
- or deliberately infringe third-party rights.
28. Registrar/registry action
A domain may be subject to action by WEBDANGER, an upstream provider, sponsoring registrar, registry, ICANN process, dispute provider, court or competent authority.
Depending on the basis and technical options, action may include:
- DNS hold;
- suspension;
- lock;
- sinkhole/redirect;
- transfer restriction;
- transfer;
- cancellation;
- or another mitigation measure.
WEBDANGER cannot guarantee continued domain operation where an upstream entity is entitled or required to act.
29. Openprovider-backed domains
Where domain Services are supplied through Openprovider, Customers must comply with the obligations WEBDANGER is required to pass through under Openprovider, registrar, registry and ICANN rules.
Customers must cooperate promptly with legitimate abuse investigations.
30. Registration data
Customers must provide accurate and current domain-registration information required by applicable policy.
False data, failure to complete required verification or abuse of privacy/proxy functions to facilitate misconduct may result in action.
31. Malicious subdomains
Customers must not knowingly permit their domains or delegated subdomains to be used for prohibited phishing, malware or comparable abuse.
32. Compromised legitimate websites
Where reasonably possible, WEBDANGER distinguishes deliberate abuse from a legitimate Customer site that has been compromised.
For compromised sites, proportionate measures may include quarantine, malicious-file removal, credential reset, patching, WAF restrictions or targeted suspension rather than immediate permanent termination.
ILLEGAL AND HARMFUL CONTENT
33. Illegal content
Customers must not knowingly use WEBDANGER hosting/server Services to store or disseminate illegal content.
WEBDANGER does not claim that every controversial, offensive or unpopular statement is illegal.
34. Child sexual abuse and exploitation
WEBDANGER has zero tolerance for child sexual abuse material (“CSAM”) and unlawful sexual exploitation of children.
Customers must not create, host, distribute, solicit, trade, knowingly facilitate access to or otherwise use WEBDANGER Services for such material or offences.
WEBDANGER may take immediate isolation, suspension, preservation and legally required reporting measures.
A reporter should not send suspected CSAM itself to an ordinary mailbox unless specifically instructed by an authorised reporting process. Reports should normally provide location/reference information without redistributing illegal material.
35. Terrorist content
WEBDANGER Services must not be used for unlawful terrorist content, recruitment for terrorism, unlawful operational support for terrorism or facilitation of terrorist offences.
This rule is applied with due regard to lawful journalism, research, historical documentation, counterspeech, education and other protected expression.
Discussion of terrorism is not itself terrorist content.
36. Terrorist-content removal orders
Where Regulation (EU) 2021/784 applies and WEBDANGER receives a valid removal order from a competent authority, WEBDANGER follows the statutory process.
That Regulation can require removal or disabling of identified terrorist content in all EU Member States as soon as possible and in any event within one hour of receipt of the valid removal order.
Where the Regulation requires preservation, terrorist content removed or disabled as a result of a removal order or applicable specific measure, together with related data required for the statutory purposes, is preserved for six months, subject to a longer specified preservation period where a competent authority or court validly requires it for ongoing proceedings.
Preserved terrorist content and related data are subject to appropriate technical and organisational safeguards and restricted to the legally permitted purposes.
Where required by Regulation (EU) 2021/784, WEBDANGER also makes information about the removal or disabling available to the affected content provider, subject to any lawful temporary non-disclosure direction issued for public-security reasons.
37. Threat to life or safety
Where WEBDANGER is a hosting service provider within the scope of Article 18 of the EU Digital Services Act and becomes aware of information giving rise to suspicion of a criminal offence involving a threat to the life or safety of one or more persons, WEBDANGER follows the applicable prompt-notification obligation.
38. Extremism and unlawful violence
Customers must not use WEBDANGER infrastructure for illegal extremist activity or unlawful incitement to violence.
Lawful political, academic, historical, journalistic or critical discussion is not prohibited merely because it discusses extremist ideology.
39. Threats, harassment and doxxing
Customers must not use WEBDANGER Services primarily to:
- make credible unlawful threats;
- conduct unlawful targeted harassment;
- unlawfully publish personal information to facilitate serious harm;
- extort;
- or intimidate unlawfully.
Lawful reporting, public-interest journalism and whistleblowing are not prohibited merely because they expose misconduct.
40. Private disputes
WEBDANGER is not a general court for private factual disputes.
For unclear defamation, ownership or similar disputes, WEBDANGER may require additional evidence, applicable legal basis or a competent authority/court decision before taking severe action.
CURRENT HOSTING MODEL RESTRICTIONS
41. Pornographic/obscene material
Unless a specific WEBDANGER Service expressly states otherwise following legal and upstream review, ordinary WEBDANGER hosting/server products do not permit pornographic or obscene hosted material where the applicable upstream infrastructure prohibits it.
This does not prohibit legitimate non-explicit health information, sexual education, science, art criticism or lawful discussion merely because it concerns sexuality.
42. Gambling
Unless a specific Service expressly permits it after legal/upstream review, WEBDANGER hosting/server Services must not be used to operate or materially host gambling services where the applicable upstream terms prohibit gambling.
General informational content about gambling is not automatically treated as operating a gambling service.
43. Illegal goods and services
Customers must not knowingly use WEBDANGER to operate a marketplace or service whose purpose is unlawful sale/distribution/procurement of regulated or prohibited goods or services.
Depending on applicable law, this may include illegal drugs, unlawfully supplied prescription medicines, illegal weapons, stolen goods, forged identity documents, counterfeit goods, illicit credentials or criminal services.
Lawful educational, compliance or journalistic discussion is not prohibited merely because it concerns regulated goods.
INTELLECTUAL PROPERTY
44. Copyright
Customers must not knowingly use WEBDANGER for systematic or deliberate copyright infringement, including piracy repositories or services primarily designed for unlawful distribution.
Good-faith ownership/licensing disputes are not automatically deliberate piracy.
45. Trademarks and impersonation
Customers must not use Services/domains for fraudulent trademark impersonation, counterfeit commerce or unlawful deception.
Lawful commentary, criticism, comparison or nominative use may be permitted.
46. Copyright complaints
Copyright complaints may be handled under the separate Copyright & DMCA Policy.
WEBDANGER is a Czech company; use of a DMCA workflow for relevant US matters does not make all global copyright disputes governed by US law.
PRIVACY AND SURVEILLANCE
47. Unlawful personal-data use
Customers must not knowingly use WEBDANGER for unlawful personal-data processing such as:
- identity theft;
- malicious credential databases;
- unlawful trafficking of personal data;
- stalking infrastructure;
- unlawful surveillance;
- or malicious publication of sensitive personal data.
48. Spyware/stalkerware
Customers must not deploy spyware, stalkerware or surveillance tooling against persons/devices without lawful authority.
Legitimate enterprise/device-management systems remain subject to applicable authority, transparency and privacy rules.
AUTOMATION, BOTS AND SCRAPING
49. Lawful automation
Automation is not prohibited merely because it is automated.
Lawful uses may include API integrations, monitoring, indexing, workflow automation, authorised crawling and testing.
50. Abusive bots
WEBDANGER may restrict:
- credential stuffing;
- botnet activity;
- DoS;
- unlawful access-control bypass;
- automated fraud;
- destructive scraping;
- or automation that materially impairs systems.
51. Scraping
Scraping is not categorically prohibited by this AUP but must comply with applicable law, access controls, privacy, intellectual-property/database rights, enforceable restrictions and reasonable technical limits.
Unlawfully bypassing authentication, CAPTCHA or explicit technical access restrictions is prohibited.
PROXIES, VPN AND FILE SHARING
52. Private VPN
A private VPN for lawful personal or organisational use may be permitted where the relevant upstream Service permits it.
53. Open proxies
WEBDANGER may prohibit or restrict open public proxies, anonymous relays, exit nodes or comparable infrastructure where they generate abuse, violate upstream rules or undermine safe operation.
54. Tor
Tor-related infrastructure is permitted only if the upstream provider permits the specific activity and the deployment complies with law and this AUP.
WEBDANGER does not guarantee that Tor exit operation is permitted by every upstream provider.
55. Legitimate file transfer
Private and lawful file storage/transfer is permitted within Service limits.
56. Piracy/seedboxes
Ordinary WEBDANGER hosting is not intended for infringement-focused torrent seedboxes, piracy repositories or similar services whose principal use violates copyright or upstream restrictions.
CRYPTOCURRENCY
57. Cryptocurrency mining
Cryptocurrency mining, farming or plotting is prohibited on WEBDANGER Services backed by infrastructure whose upstream provider prohibits it.
Hetzner currently prohibits applications used to mine cryptocurrencies on relevant Cloud and Dedicated Server products.
58. Other blockchain uses
A lawful blockchain website, API, software service or node is not automatically prohibited merely because it relates to cryptocurrency.
It remains subject to resource, legal, sanctions and upstream restrictions.
AI AND AUTOMATION
59. Lawful AI
AI may be used for lawful coding, support, analysis, content creation, automation and authorised defensive security work.
60. AI abuse
Customers must not use WEBDANGER AI features primarily to facilitate:
- phishing;
- credential theft;
- malicious-code deployment;
- fraud/impersonation scams;
- unlawful spam;
- child sexual exploitation;
- terrorist operational support;
- unlawful surveillance;
- or security-control evasion.
61. AI security work
AI-assisted defensive security is allowed only where the underlying testing activity is itself authorised under this AUP.
RESOURCE AND ACCOUNT ABUSE
62. Resource exhaustion
Customers must not deliberately consume excessive shared resources in a manner that materially harms other users or Service stability.
WEBDANGER may use rate limits, quotas, throttling, fair-use controls or temporary isolation.
63. Bypassing limits
Customers must not intentionally evade rate limits, billing meters, access controls, quotas or security restrictions.
64. Fraudulent accounts
Creating accounts with stolen payment instruments, compromised accounts, intentionally false identities or coordinated account farms for abuse is prohibited.
65. Resale
Resale is permitted only where the applicable product/agreement permits it.
Resellers must impose applicable downstream obligations and cooperate with abuse handling as required.
SANCTIONS
66. Sanctions/export controls
Services must not be used in a way that causes boxbank s.r.o. to violate applicable EU or Czech sanctions/export controls.
WEBDANGER may restrict or suspend transactions/Services where legally necessary.
67. Evasion
Using false identities, intermediaries or other arrangements to evade applicable sanctions/service restrictions is prohibited.
ABUSE REPORTING
68. Reporting abuse
Until a dedicated abuse contact is published, suspected abuse may be reported to:
contact@webdanger.com
WEBDANGER intends to maintain a dedicated electronic abuse-reporting mechanism when relevant domain/hosting Services are activated.
69. Useful report information
Where applicable, reports should include:
- exact URL/domain/IP/service identifier;
- description;
- why the reporter believes the activity is illegal or violates this AUP;
- applicable right/law if known;
- timestamps;
- evidence safe to transmit;
- urgency/safety information;
- reporter contact information where applicable.
Do not send passwords, private keys or illegal material unnecessarily.
EU DIGITAL SERVICES ACT
70. Article 16 hosting notices
Where WEBDANGER acts as a provider of hosting services within Article 16 of Regulation (EU) 2022/2065, it provides an electronic mechanism for notifying specific allegedly illegal information.
71. Article 16 notice elements
Where Article 16 applies, the mechanism requests:
- a sufficiently substantiated explanation of why the information is alleged to be illegal;
- the exact electronic location, such as URL(s), and additional identifying information where necessary;
- reporter name and email except where the statutory exception applies to information considered to involve offences referred to in Articles 3–7 of Directive 2011/93/EU;
- a statement confirming the reporter's good-faith belief that the information and allegations are accurate and complete.
72. Child-safety reporter identity exception
For notices concerning information considered to involve offences referred to in Articles 3–7 of Directive 2011/93/EU, the DSA Article 16 mechanism does not require reporter name/email in the same way as an ordinary notice.
WEBDANGER will not design its form to defeat that exception.
73. Acknowledgement
Where the reporter supplies electronic contact information and Article 16 applies, WEBDANGER sends confirmation of receipt without undue delay.
74. Decision
WEBDANGER processes applicable Article 16 notices in a timely, diligent, non-arbitrary and objective manner.
Where required, the reporter is notified without undue delay of the decision and available redress.
75. Automated means
If automated means are used to process or decide an applicable Article 16 notice, their use is disclosed in the decision notification where legally required.
76. Actual knowledge
A sufficiently precise and substantiated Article 16 notice may give rise to actual knowledge/awareness regarding the specific information where it enables a diligent hosting provider to identify illegality without detailed legal examination.
ENFORCEMENT
77. Available measures
Depending on severity, law, contract and upstream requirements, WEBDANGER may:
- request information/remediation;
- warn;
- remove/disable specific content;
- quarantine files;
- disable malicious scripts;
- restrict email/ports/APIs;
- throttle;
- isolate/suspend a server;
- suspend DNS;
- apply domain restrictions;
- terminate a Service/account;
- preserve evidence;
- notify an upstream provider;
- comply with a lawful authority order.
78. Proportionality
Where circumstances permit, WEBDANGER considers:
- nature/severity;
- immediacy of harm;
- intent;
- recurrence;
- Customer cooperation;
- compromise vs deliberate abuse;
- collateral damage;
- technical alternatives;
- legal/upstream obligations.
79. Warning and cure
For ordinary remediable violations without urgent safety/legal/security risk, WEBDANGER may provide notice and a reasonable remediation period.
The period depends on the risk and any upstream deadline.
80. Immediate action
WEBDANGER may act immediately without advance notice where reasonably necessary for:
- active phishing;
- malware/botnets;
- active attacks/DDoS;
- CSAM;
- credible life/safety threats;
- valid urgent legal orders;
- valid terrorist-content removal orders;
- sanctions;
- material fraud;
- severe network instability;
- or urgent mandatory upstream action.
81. Quarantine
Where feasible, WEBDANGER may quarantine rather than immediately destroy content while investigating, containing malware, preserving evidence or awaiting remediation.
82. Evidence preservation
WEBDANGER may preserve relevant logs, files, communications and account records where reasonably necessary for abuse investigation, legal compliance, valid preservation obligations, security or legal claims, subject to applicable privacy/data-protection rules.
83. Upstream action
WEBDANGER may be required to act because of Hetzner, Openprovider, Cloudflare, another infrastructure provider, sponsoring registrar, registry, ICANN, court or competent authority.
Where WEBDANGER has no ability to prevent a valid upstream action, continued availability cannot be guaranteed.
84. Payment is not permission for abuse
Payment does not authorise prohibited use.
Refund/cancellation consequences are governed by the Terms, mandatory law and circumstances.
DSA STATEMENT OF REASONS AND REVIEW
85. Statement of reasons
Where Article 17 DSA applies to a restriction imposed because Customer-provided information is considered illegal or incompatible with WEBDANGER terms, WEBDANGER provides the affected recipient with a clear and specific statement of reasons required by law.
This obligation is applied subject to the exceptions in Article 17 itself, including where Article 17 does not apply to a restriction concerning deceptive high-volume commercial content or to an order governed by Article 9 DSA.
86. Statement contents
Where required, the statement may describe:
- restriction;
- affected information;
- geographic scope;
- duration;
- facts/circumstances;
- whether based on notice or own initiative;
- legal or contractual basis;
- automated means where applicable;
- redress possibilities.
Information may be withheld where law permits or requires it, including protection of investigations.
87. Requesting review
A Customer may request review of an abuse action at:
contact@webdanger.com
or through a dedicated mechanism when available.
The request should identify the decision and provide relevant supporting information.
88. Review does not suspend urgent action
A review request does not automatically restore a Service or suspend a binding legal/upstream deadline.
89. Additional redress
Where law grants additional judicial, administrative, out-of-court or other redress, this AUP does not remove those rights.
AUTHORITIES
90. Valid requests
WEBDANGER responds to legally valid court/authority orders, preservation obligations and other binding processes.
WEBDANGER may verify authenticity, jurisdiction, scope and legal basis before disclosure or action.
91. Informal requests
An email claiming to be from law enforcement does not automatically authorise unrestricted data disclosure.
Where appropriate, WEBDANGER may request official credentials, proper legal process, authority details, jurisdiction and case/reference information.
92. DSA Article 18
Where Article 18 applies and WEBDANGER becomes aware of information giving rise to suspicion of a criminal offence involving a threat to life/safety, WEBDANGER follows the applicable prompt-notification rules.
FAIR MODERATION
93. No promise of universal monitoring
WEBDANGER does not promise to proactively review every Customer file, domain, website or communication.
It may nevertheless use proportionate security, malware, abuse and fraud systems and investigate specific reports.
94. False reports
Knowingly submitting materially false reports, forged evidence or impersonating authorities is prohibited.
A good-faith reporter is not penalised merely because a report is rejected.
95. Retaliation
Customers must not unlawfully retaliate against a person merely for making a good-faith abuse report or exercising a lawful right.
CHANGES AND CONTACT
96. Changes
WEBDANGER may update this AUP for legal, ICANN/registry, upstream, security, abuse-pattern or product changes.
Material contractual changes are handled under the Terms and mandatory law.
97. Contact
General and current abuse contact:
contact@webdanger.com
A dedicated abuse address/form may replace or supplement this contact when activated.
APPENDIX A — ABUSE CATEGORIES
- Malware
- Botnet
- Phishing
- Pharming
- Spam
- Compromised website
- Domain/DNS abuse
- DDoS/network attack
- Unauthorised scanning
- Credential theft
- Fraud/impersonation
- Child safety/CSAM
- Terrorist content
- Threat to life/safety
- Illegal goods/services
- Copyright
- Trademark/counterfeit
- Privacy/doxxing
- Threats/harassment
- Sanctions
- Resource abuse
- Other illegal content
- Other AUP violation
APPENDIX B — ABUSE REPORT TEMPLATE
Affected URL/domain/IP/service: ________________________________
Category: ________________________________
Explanation: ________________________________
Why is this alleged to be illegal or contrary to the AUP? ________________________________
Applicable law/right, if known: ________________________________
Exact electronic location: ________________________________
Evidence safe to transmit: ________________________________
Date/time observed: ________________________________
Urgent threat to life or safety? Yes / No
Reporter name: ________________________________
Reporter email: ________________________________
Good-faith statement: I believe in good faith that the information and allegations provided are accurate and complete.
For the statutory Article 16 DSA child-sexual-abuse offence exception, the production form must not require name/email where the law says those fields need not be requested.
APPENDIX C — RESPONSE SEVERITY MODEL
Critical
Examples: active phishing/malware/botnet, CSAM, credible imminent safety threat, valid terrorist-content order, active DDoS, applicable sanctions prohibition.
Possible action: immediate containment/suspension + investigation/escalation + required reporting/upstream action.
High
Examples: compromised site distributing malware, serious spam, credential attacks, serious fraud, active unauthorised scanning.
Possible action: rapid restriction + short remediation period where safe.
Medium
Examples: open relay, recurring risky configuration, credible IP complaint, resource abuse.
Possible action: notice + deadline + targeted restriction if unresolved.
Unclear/low
Examples: incomplete report, private factual dispute, unclear ownership dispute.
Possible action: request information; avoid unnecessary emergency restriction.
APPENDIX D — SECURITY TESTING MODEL
Passive public website audit: allowed where lawful.
Verified active test: only where target authorisation, defined scope and compatible scan infrastructure exist.
Foreign-IP/network scan from ordinary Hetzner Cloud/Dedicated: prohibited under the current upstream terms reviewed for this Policy.
DDoS/stress testing: only controlled/authorised and only where both target and network providers permit it.
Credential auditing: authorised systems only.
Exploit validation: isolated/controlled environment expressly supporting it.
Effective / review date: 29 August 2026