Devpipe

Draft document

Acceptable use

Drafted 7 August 2026 · Effective: not yet
Part of the terms of service once both are in force

Every box runs on a machine Devpipe rents from DigitalOcean under one account. An abuse report about your box arrives at that account, not yours. One machine mining coins or scanning ports can get the whole account flagged, and that takes every other customer's box down with it. That is the reason for every rule below — not a moral position, a shared blast radius.

  1. 01 · No mining
  2. 02 · No spam
  3. 03 · Nothing pointed at strangers
  4. 04 · Nothing illegal
  5. 05 · No anonymising services
  6. 06 · No resale
  7. 07 · Respect the agent vendors
  8. 08 · Leave the platform alone
  9. 09 · What happens on a report
  10. 10 · Reporting abuse

01 No mining, and nothing else that turns compute into money for its own sake

No cryptocurrency mining, no proof-of-work of any kind, no bandwidth resale or "passive income" clients, no ad-viewing or captcha-solving farms.

This is the single most common reason a hosting account gets flagged, and the arithmetic never works anyway: on a machine this size the electricity costs more than the coin. If a box is doing it, we will see it in the provider's usage graphs before anyone reports it.

02 No spam

No bulk unsolicited email, no address harvesting, no open mail relays, no sending on behalf of someone who did not ask you to.

Outbound port 25 is blocked at the provider by default and we are not going to ask for it to be opened. Send transactional mail through a provider with an API and a reputation to protect.

03 Nothing pointed at somebody else's machine

  • No port scanning, vulnerability scanning, brute forcing, or credential stuffing against systems you do not own.
  • No denial of service, traffic floods, or amplification.
  • No command and control, botnet nodes, malware hosting, phishing pages, or fake sign-in pages.

Security research

Fine against your own systems, or against a target where you hold written authorisation. The authorisation is yours to produce when a report lands, and it needs to exist before the scan does, not after.

An agent doing it unprompted is still your box doing it. If you point an autonomous process at the internet, scope it.

04 Nothing illegal

  • Nothing unlawful where you are or where the box is. You pick the region, so you pick the second one.
  • Child sexual abuse material ends the account immediately, with no warning and no appeal, and is reported to the authorities.
  • No distributing content you do not have the rights to. A box is not a warez host or a torrent seedbox.
  • Nothing that exists to defraud people: fake shops, fake support desks, cloned sign-in pages.

05 No anonymising services for other people

No open proxies, no public VPN endpoints, no Tor exit relays. Use one for your own traffic if you like; running one for the public generates abuse reports in a volume we cannot answer, and every one of them lands on the provider account that all the other boxes depend on.

06 No resale

A box is for you and the people you work with directly. Do not resell it, sublet it, rent out shells on it, or run other people's CI on it as a service. Do not share an account so that several people can buy access to one box.

If you want boxes for a team, that is a thing we want to sell you — team accounts are not built yet; say what to do in the meantime.

07 Respect the agent vendors' terms

The agent CLIs are yours, signed in with your own account. Using a box to share one subscription across many people, to evade rate limits, or to automate something the vendor forbids is between you and them until it is not — a vendor that decides Devpipe's address range is the problem takes every user's agent down with it.

08 Leave the platform alone

  • No attempts to escape the virtual machine, reach the hypervisor, or reach our control plane.
  • No probing or attacking other customers' boxes.
  • No tampering with the daemon, its token, or the certificate on your hostname. Breaking them mostly breaks your own box, but the token is what lets your box talk to us.

If you find a way through, report it to security@devpipe.com — mailbox to be created. We will not pursue anyone who reports in good faith, stops at proof, and does not take data. Decide whether to publish a formal safe-harbour statement.

09 What happens when we get a report

We read it, and we start with box metadata — size, region, the tools it was built with, when it was created, what the provider's network graphs show. Most reports resolve there without anyone looking at your disk. Where they do not, we may have to look at the box itself; the terms and the privacy policy say plainly what that means.

  • First An email describing what we have been told and what needs to stop, with time to fix it.
  • Then Suspension, if the reply does not come or the behaviour does not stop. Your sessions end, you cannot sign in, and your boxes are marked for destruction. There is no powered-off state we can park a box in, so this is not a pause — it is the step before the disk goes.
  • Straight away The same, without notice, where a third party is being actively harmed or the provider account is at risk. We explain afterwards, and we do explain.
  • Last Destruction of the box and closure of the account for deliberate or repeated abuse. The disk goes with it.

Appeals go to abuse@devpipe.com — mailbox to be created and a person reads them. Because suspension takes the box down rather than pausing it, an account suspended in error is refunded for the rest of the period it had paid for; a box that is already gone cannot be handed back. Decide the billing treatment for a suspension that turns out to be justified.

10 Reporting abuse to us

If a Devpipe box is bothering you, write to abuse@devpipe.com — mailbox to be created with the IP address or hostname, timestamps including the timezone, and enough log to show what happened. Reports with those three things get acted on the same day; reports without them mostly cannot be traced to a box at all.