Legal
Acceptable Use Policy
What may and may not be run on infrastructure operated by bolt.sh, including dedicated servers, network capacity and address space we announce.
This policy applies to any infrastructure operated or provided by bolt.sh (a practice of GeekyAnts Inc) — dedicated servers, hosting, network capacity, edge capacity and IP address space we announce on your behalf.
It exists for a practical reason: we announce our own address space and hold our own peering and transit relationships. Abuse originating from our prefixes affects every customer behind them.
Prohibited
Network abuse. Denial-of-service traffic, amplification or reflection attacks, port scanning or vulnerability scanning of systems you do not own or have written authorisation to test, and any attempt to intercept traffic not destined for you.
Routing abuse. Announcing address space you do not control, falsifying BGP origin or path attributes, and route leaks caused by deliberately permissive export policy.
Unsolicited messaging. Bulk unsolicited email, SMS or messaging, and operating infrastructure that supports it — list hosting, address harvesting, or relay services for such traffic.
Malware and intrusion infrastructure. Hosting, distributing or controlling malware, ransomware, botnet command-and-control, phishing sites, or credential-harvesting pages.
Unlawful content. Material that is unlawful in the jurisdiction where it is hosted or served, including content that infringes intellectual property rights, and child sexual abuse material — reported immediately to the relevant authorities with no notice period.
Resource abuse. Deliberately circumventing quotas, rate limits or fair-use provisions, or using shared capacity in a way that materially degrades service for others.
Security testing
Authorised security testing of your own systems is permitted and encouraged. Testing that generates significant traffic volume must be scheduled with us in advance so it is not mistaken for an attack. Testing against third-party systems requires written authorisation from the system owner, which you must be able to produce on request.
Your responsibilities
You are responsible for everything that happens on infrastructure assigned to you, including activity by your users, customers and anyone who compromises your systems.
Keep systems patched, secure your credentials, publish a working abuse contact, and respond to abuse reports we forward. A compromised server generating attack traffic is treated the same as a deliberate one — we will act on it either way.
How we respond
Where possible we contact you first and give you a reasonable window to resolve the issue. Where traffic is actively harming the network or other customers, or where the content is unlawful, we may null-route, suspend or disconnect immediately and notify you afterwards.
Repeated or severe violations result in termination. We cooperate with lawful requests from law enforcement and with other network operators investigating abuse originating from our prefixes.
Reporting abuse
Email [email protected] with timestamps including timezone, source and destination addresses, and relevant log excerpts. Reports with evidence get acted on faster than reports without.
Changes
This policy may be updated as network conditions and legal obligations change. Material changes are communicated to active customers before they take effect.