Acceptable Use Policy
This Acceptable Use Policy establishes the activities and workloads that are prohibited or restricted when using Velocity cloud development environments, compute resources, networking, APIs and related Services.
This policy does not grant permission to perform activities that would otherwise require authorization from a system owner, network operator, rights holder or other third party.
1. Scope
This Acceptable Use Policy ("AUP") applies to all users of Velocity, including users of free trials, paid subscriptions, prepaid compute balances, APIs, development environments, sandboxes, GPUs, networking features, webhooks and integrations.
The AUP forms part of Velocity's Terms of Service.
A violation of this AUP may result in warnings, resource restrictions, suspension, termination, deletion of affected resources, reporting to appropriate authorities, or other actions described below.
2. General Requirements
You must use Velocity only for legitimate purposes and in a manner that does not:
- Violate applicable law or regulation.
- Infringe intellectual-property, privacy, publicity or other rights.
- Interfere with the operation or security of Velocity.
- Interfere with another user's resources.
- Create unreasonable risk to infrastructure or other users.
- Circumvent technical, security, billing or resource restrictions.
- Facilitate fraud, abuse, unauthorized access or malicious activity.
3. Malware and Malicious Software
You must not use Velocity to create, deploy, distribute, host or operate malicious software or infrastructure intended to harm, compromise, surveil or gain unauthorized access to systems.
- Ransomware or file-encrypting malware.
- Credential stealers and password stealers.
- Keyloggers intended for unauthorized surveillance.
- Remote-access trojans used without authorization.
- Botnet agents or command-and-control infrastructure.
- Worms designed to propagate without authorization.
- Destructive malware or wipers.
- Malicious browser extensions.
- Payloads designed to evade security controls.
- Malware distribution infrastructure.
Security research, malware analysis and defensive testing may be permitted when conducted in an isolated environment and with appropriate authorization, provided the activity does not compromise third-party systems or violate another provision of this AUP.
4. Unauthorized Network Activity
You may not use Velocity to conduct network activity against systems that you do not own or have explicit authorization to test.
- Unauthorized port scanning.
- Unauthorized vulnerability scanning.
- Network enumeration against third-party infrastructure.
- Credential attacks against external systems.
- Brute-force authentication attempts.
- Unauthorized exploitation of vulnerabilities.
- Traffic interception or man-in-the-middle attacks.
- ARP spoofing or similar network attacks.
- Unauthorized packet capture.
- Network flooding.
Authorized penetration testing against systems that you own or have explicit permission to test may be permitted, provided that the testing does not threaten Velocity infrastructure, violate applicable law or materially affect other users.
5. Security Research
Velocity supports legitimate software development and defensive security research.
Security testing is acceptable when you have authorization from the owner of the system being tested and conduct the testing in a controlled manner.
You remain responsible for ensuring that your testing does not:
- Attack Velocity infrastructure without authorization.
- Attack other Velocity customers.
- Cause denial of service.
- Attempt sandbox escape.
- Access data belonging to other users.
- Create persistent malicious infrastructure.
- Exfiltrate credentials or secrets.
- Cause material disruption to third-party systems.
6. Sandbox Escape and Infrastructure Attacks
You must not attempt to bypass or compromise the isolation boundaries of a Velocity sandbox.
- Attempting container or sandbox escape.
- Accessing the underlying host operating system.
- Accessing another customer's sandbox.
- Attempting to obtain infrastructure-provider credentials.
- Attempting to access internal control-plane APIs without authorization.
- Modifying infrastructure outside your assigned environment.
- Exploiting virtualization or container-runtime vulnerabilities against Velocity.
- Scanning internal infrastructure for unauthorized access.
If you discover a security vulnerability affecting Velocity, report it responsibly through support@fairarena.raiseaticket.com rather than exploiting it beyond what is reasonably necessary to demonstrate the issue.
7. Cryptocurrency Mining and Resource Abuse
Cryptocurrency mining and other workloads whose primary purpose is to consume disproportionate compute resources for financial gain are prohibited unless Velocity has expressly authorized them in writing.
- Cryptocurrency mining.
- Mining pools operated from Velocity infrastructure.
- Proof-of-work mining.
- Hidden background mining.
- Browser or container-based cryptojacking.
- Using compromised accounts or resources to obtain additional compute.
You must not attempt to circumvent CPU, memory, GPU, runtime, concurrency, network or spending limits.
8. Resource Abuse
Velocity provides shared infrastructure. You must not use your resources in a way that intentionally or negligently causes material degradation of the Service or other users' workloads.
- Intentionally exhausting shared infrastructure.
- Launching excessive numbers of sandboxes to consume available capacity.
- Creating resource-allocation loops.
- Abusing autoscaling or provisioning systems.
- Generating unnecessary infrastructure traffic.
- Attempting to monopolize scarce GPU capacity.
- Circumventing concurrency limits.
- Creating workloads designed to trigger excessive infrastructure costs.
Velocity may impose temporary or permanent resource limits when necessary to maintain platform stability.
9. Proxy, VPN and Network Relay Abuse
Velocity environments may have network connectivity. You may not use that connectivity to operate abusive proxy or relay infrastructure.
- Open proxies accessible to unauthenticated third parties.
- Residential proxy or IP rotation networks without authorization.
- Traffic laundering or origin obfuscation for malicious activity.
- Proxying attacks against third parties.
- Operating anonymous relay infrastructure for illegal activity.
- Using Velocity as a network-bypass service to circumvent third-party access controls.
Legitimate development proxies, application reverse proxies, tunnels and similar tools may be used when they are operated within the limits of this AUP and applicable law.
10. Spam and Abuse
You must not use Velocity to send unsolicited or abusive communications.
- Bulk unsolicited email.
- Phishing campaigns.
- Credential-harvesting campaigns.
- Malicious SMS or messaging campaigns.
- Unsolicited automated communications.
- Spam infrastructure.
- Email address harvesting for unsolicited marketing.
- Abuse of third-party messaging or email APIs.
Legitimate transactional email, development testing and authorized marketing infrastructure may be used in compliance with applicable laws and the policies of the relevant email or messaging provider.
11. Credential Theft and Account Abuse
You may not use Velocity to obtain, steal, collect, purchase, trade or distribute credentials belonging to other people or organizations without authorization.
- Password theft.
- Session-token theft.
- Cookie theft.
- API-key harvesting.
- OAuth-token theft.
- Phishing for authentication credentials.
- Credential stuffing.
- Password spraying against unauthorized accounts.
- Selling or distributing stolen credentials.
You are also responsible for protecting your own Velocity credentials, API keys, OAuth tokens and secrets.
12. Payment and Financial Abuse
You must not use Velocity to facilitate financial fraud or payment abuse.
- Using stolen payment credentials.
- Creating accounts to abuse promotional credits.
- Manipulating billing or usage metering.
- Attempting to obtain unauthorized wallet credits.
- Refund fraud.
- Chargeback abuse.
- Payment-method testing using unauthorized cards.
- Creating multiple accounts to bypass account-level limits.
13. Data Theft and Privacy Violations
You may not use Velocity to collect, expose, distribute or process personal information in violation of applicable law or without appropriate authorization.
- Unauthorized scraping of personal information.
- Doxxing.
- Credential databases containing unlawfully obtained information.
- Unauthorized surveillance.
- Distribution of private or confidential information.
- Unauthorized collection of authentication data.
- Processing personal data in violation of applicable law.
You are responsible for determining whether your own workloads comply with applicable privacy and data-protection requirements.
14. Illegal Content and Activities
You must not use Velocity to create, store, distribute or facilitate content or activities that are unlawful under applicable law.
- Fraud and scams.
- Identity theft.
- Extortion.
- Unauthorized surveillance.
- Illegal trafficking or distribution.
- Sexual exploitation or abuse of minors.
- Terrorist or violent-extremist activity.
- Malicious interference with public or private infrastructure.
- Other criminal activity.
Velocity may cooperate with valid legal requests from competent authorities where required by applicable law.
15. Intellectual Property
You must not use Velocity to knowingly infringe another party's intellectual-property rights.
- Unauthorized distribution of copyrighted software.
- Hosting or distributing pirated content.
- Unauthorized distribution of commercial source code.
- Circumventing software licensing or DRM restrictions.
- Distributing stolen repositories or proprietary materials.
- Using Velocity to facilitate intellectual-property infringement.
Open-source software may be used in accordance with the applicable open-source license.
16. Monitoring and Abuse Detection
To protect the platform and its users, Velocity may monitor service-level and security-related information associated with resource usage.
This may include:
- Resource consumption.
- Network traffic metadata.
- Authentication events.
- API usage.
- Provisioning activity.
- Security events.
- Abuse reports.
- Billing anomalies.
- Infrastructure health signals.
Monitoring does not mean that Velocity routinely reviews the contents of every user's source code or files. However, we may investigate specific resources when reasonably necessary to respond to abuse, security incidents, legal obligations or credible reports.
17. Reporting Abuse
If you believe a Velocity resource is being used for malicious or unlawful activity, report it to:
Abuse & Security
Reports should include enough information for us to identify the affected resource, such as a sandbox ID, URL, IP address, timestamp, domain or other relevant technical evidence.
Do not include unnecessary personal information or sensitive credentials in an abuse report.
18. Enforcement
If we reasonably believe that an account or resource violates this AUP, we may take action proportionate to the situation.
Warning
Request that you stop or modify the prohibited activity.
Rate Limiting
Restrict network, API, compute or other resource usage.
Resource Suspension
Stop affected sandboxes or other resources.
Account Suspension
Temporarily restrict access to Velocity.
Termination
Permanently terminate an account or affected resources.
Legal Action
Take or support appropriate legal or regulatory action where necessary.
19. Immediate Suspension
Velocity may suspend a resource or account without prior notice where reasonably necessary to prevent:
- An active security incident.
- Ongoing attacks against third-party systems.
- Compromise of Velocity infrastructure.
- Material harm to other customers.
- Significant resource abuse.
- Fraud or payment abuse.
- Illegal activity creating immediate risk.
- Continued abuse after a warning.
Where reasonably practicable and legally permitted, we may notify the account holder and provide an opportunity to resolve the issue.
20. Data Preservation and Deletion
When resources are suspended or terminated for an AUP violation, Velocity may preserve relevant logs and account information for security, investigation, dispute resolution and legal compliance.
Suspended resources may subsequently be deleted according to Velocity's retention and lifecycle policies.
Users should maintain independent backups of important data. Velocity does not guarantee recovery of resources terminated for policy violations.
21. Legal Requests and Cooperation
Velocity may disclose information when required by applicable law, valid legal process or a lawful request from a competent authority.
Where applicable, Velocity may preserve relevant information necessary to comply with legal obligations or respond to security incidents.
CERT-In's cybersecurity directions establish cybersecurity information and incident-related requirements applicable to certain categories of entities, including cloud service providers.
Velocity will comply with applicable legal and regulatory requirements based on the services and infrastructure it operates.
22. False Reports and Abuse of Enforcement
You must not knowingly submit false abuse reports, fabricate evidence, impersonate another person or organization, or attempt to use the abuse process to harass another user.
We may disregard or take action against repeated malicious reports or attempts to manipulate enforcement systems.
23. Third-Party Systems
This AUP applies to your use of Velocity even when your workload interacts with external systems.
You are responsible for obtaining appropriate authorization before interacting with third-party infrastructure.
The fact that a third-party system is publicly accessible does not mean that you are authorized to scan, exploit, scrape, access or disrupt it.
24. Policy Interpretation
This AUP cannot list every possible form of abusive behavior. Conduct that is substantially similar to the prohibited activities described above may also be restricted where it creates material security, legal, operational or financial risk.
We will interpret and enforce this policy reasonably and proportionately, taking into account the nature, severity, intent and impact of the activity.
25. Changes to This Policy
We may update this AUP when our infrastructure, Services, security requirements or legal obligations change.
The latest version will be published on this page with an updated revision date.
26. Abuse & Security Contact
Report abuse, security incidents or policy violations
For abuse or security reports, contact:
Saksham Goel
Abuse: support@fairarena.raiseaticket.com
Security: support@fairarena.raiseaticket.com
Support: support@fairarena.raiseaticket.com
Address: New Delhi, India