Effective Date: August 6, 2025
Last Updated: July 17, 2026
This Acceptable Use Policy (“AUP”) is issued by Cañaveral Group (CGC), a corporation duly organized and existing under the laws of the Republic of the Philippines, acting through its NuCDN division (“NuCDN,” the “Company,” “we,” “us,” or “our”).
This AUP governs the use of all websites, networks, infrastructure, systems, platforms, software, hosting, content delivery, DNS, security, DDoS mitigation, monitoring, storage, APIs, control panels, and other services provided or made available by NuCDN (collectively, the “Services”).
This AUP applies to every Subscriber, Account holder, Authorized User, reseller, customer, end user, visitor, contractor, administrator, and other person who accesses or uses the Services directly or indirectly.
IMPORTANT — PLEASE READ CAREFULLY
THIS AUP FORMS AN INTEGRAL AND BINDING PART OF NUCDN’S TERMS AND CONDITIONS.
BY CREATING AN ACCOUNT, PURCHASING, ACCESSING, CONFIGURING, OR USING THE SERVICES, YOU:
- ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS AUP;
- AGREE TO COMPLY WITH THIS AUP;
- AGREE TO ENSURE THAT YOUR AUTHORIZED USERS AND END USERS COMPLY WITH THIS AUP; AND
- ACCEPT RESPONSIBILITY FOR ACTIVITY CONDUCTED THROUGH YOUR ACCOUNT, SERVICES, SYSTEMS, APPLICATIONS, AND CUSTOMER CONTENT.
VIOLATION OF THIS AUP CONSTITUTES A MATERIAL BREACH OF THE NUCDN TERMS AND CONDITIONS AND MAY RESULT IN IMMEDIATE FILTERING, RESTRICTION, SUSPENSION, CONTENT DISABLING, TERMINATION, OR OTHER ENFORCEMENT ACTION.
NuCDN may take immediate action without advance notice where reasonably necessary to protect the Services, infrastructure, customers, providers, third parties, or the public.
TABLE OF CONTENTS
- Definitions
- Purpose and Scope
- Incorporated Policies
- Subscriber Responsibility
- General Use Requirements
- Unlawful Activities
- Cybersecurity Abuse
- Malware and Malicious Code
- Unauthorized Access and Security Testing
- Denial-of-Service and Traffic Attacks
- Phishing and Deceptive Activity
- Spam and Unsolicited Communications
- Network Abuse
- Proxy, VPN, and Anonymization Services
- Illegal and Restricted Content
- Child Exploitation and Abuse
- Sexual and Adult Content
- Violent, Extremist, and Terrorist Content
- Intellectual Property Infringement
- Fraud and Financial Abuse
- Regulated Goods and Services
- Gambling and Betting
- Cryptocurrency and Blockchain Activity
- Artificial Intelligence and Automated Use
- Privacy and Personal Data
- Resource Usage and Fair Use
- Bandwidth and Unmetered Services
- Storage and Backup Restrictions
- Free, Trial, and Promotional Services
- Resellers and Downstream Users
- Security and Account Management
- Abuse Notices and Cooperation
- Investigations
- Enforcement Actions
- Content and Traffic Restrictions
- Emergency Action
- Repeat Violations
- Reporting Abuse
- Counter-Notices and Appeals
- Costs and Remediation
- No General Monitoring Obligation
- Law Enforcement and Legal Requests
- Service Level Exclusions
- Modifications
- Governing Terms
- Contact Information
- Acceptance
1. DEFINITIONS
For purposes of this AUP:
- Abuse means any activity, content, configuration, transmission, omission, or use of the Services that violates this AUP, Applicable Law, third-party rights, or reasonable network and security standards.
- Abuse Report means a complaint, notice, allegation, security report, legal demand, intellectual-property complaint, or other communication alleging misuse of the Services.
- Account means the Subscriber’s customer account, portal, control panel, credentials, API keys, subscriptions, resources, and associated records.
- Applicable Law means all laws, regulations, court orders, administrative issuances, regulatory requirements, and legally binding governmental directives applicable to the relevant activity, content, person, jurisdiction, or Service.
- Authorized User means an employee, contractor, administrator, representative, customer, end user, or other person authorized by the Subscriber to access or use the Account or Services.
- Customer Content means all websites, applications, files, software, scripts, databases, messages, DNS records, media, traffic, requests, personal data, and other content submitted to, stored on, transmitted through, cached by, routed through, or processed using the Services.
- Malicious Activity means activity intended or reasonably likely to compromise, damage, disrupt, deceive, exploit, interfere with, or obtain unauthorized access to a person, device, Account, network, application, system, or data.
- Resource means CPU, memory, storage, bandwidth, network connections, requests, processes, database usage, mail volume, IP addresses, mitigation capacity, or another technical allocation associated with a Service.
- Subscriber or Customer means the individual or legal entity that purchases, administers, accesses, or uses the Services.
- Third-Party Rights means intellectual-property, privacy, publicity, confidentiality, contractual, consumer, property, security, or other legally recognized rights belonging to another person.
2. PURPOSE AND SCOPE
The purposes of this AUP are to:
- protect NuCDN’s infrastructure, networks, systems, Autonomous Systems, IP resources, facilities, providers, and reputation;
- protect Subscribers, Authorized Users, end users, third parties, and the public;
- prevent unlawful, malicious, fraudulent, abusive, or disruptive use;
- maintain fair, secure, reliable, and stable operation of the Services;
- ensure reasonable sharing of network and computing Resources;
- support compliance with Applicable Law and lawful governmental requirements; and
- establish procedures for investigating and responding to suspected violations.
This AUP applies to:
- Content Delivery Network and edge Services;
- DNS and DNS-security Services;
- DDoS detection, filtering, mitigation, and traffic-scrubbing Services;
- web application firewall and website-security Services;
- shared, free, managed, virtual, and dedicated hosting;
- virtual machines and dedicated servers;
- storage, backup, and file Services;
- email, messaging, and notification functions;
- APIs, dashboards, control panels, and integrations;
- monitoring, logging, analytics, and security systems;
- IP addresses, network routes, ports, and connectivity;
- free, trial, beta, preview, and promotional Services; and
- all related infrastructure and technical resources.
This AUP applies regardless of whether prohibited activity is initiated intentionally, negligently, unknowingly, automatically, through compromised systems, or by an Authorized User or downstream customer.
3. INCORPORATED POLICIES
This AUP forms part of NuCDN’s legal framework and should be read together with:
- Terms and Conditions: https://www.nucdn.co/legal/terms-and-conditions/
- Privacy Policy: https://www.nucdn.co/legal/privacy-policy/
- Service Level Agreement: https://www.nucdn.co/legal/sla/
- Trust, Abuse, and Intellectual Property Policy: https://www.nucdn.co/legal/dmca/
- any applicable Order, product-specific terms, security requirements, or supplemental policy.
If this AUP conflicts with the Terms and Conditions, the Terms and Conditions shall control unless a higher-priority written agreement expressly states otherwise.
If a mandatory requirement of Applicable Law conflicts with this AUP, the mandatory legal requirement shall prevail only to the minimum extent of the conflict.
4. SUBSCRIBER RESPONSIBILITY
The Subscriber is responsible for all activity conducted through or connected with its:
- Account;
- Services;
- IP addresses;
- domains and DNS zones;
- servers and virtual machines;
- applications and websites;
- API keys and access tokens;
- Authorized Users;
- resellers and downstream customers;
- Customer Content; and
- devices, systems, and credentials.
The Subscriber remains responsible even where prohibited activity:
- was performed without the Subscriber’s direct knowledge;
- was performed by an Authorized User;
- was performed by a reseller or downstream customer;
- resulted from compromised credentials;
- resulted from malware or an exploited vulnerability;
- was performed through an automated script or application;
- was caused by incorrect configuration; or
- was performed by another person using Subscriber-controlled infrastructure.
The Subscriber must take reasonable measures to prevent, detect, stop, investigate, and remediate prohibited activity.
5. GENERAL USE REQUIREMENTS
The Subscriber shall:
- use the Services only for lawful purposes;
- comply with this AUP and Applicable Law;
- maintain accurate Account and contact information;
- secure credentials and systems;
- maintain supported and patched software;
- monitor Service activity and Resource usage;
- configure applications, DNS, firewalls, and security controls correctly;
- maintain valid administrative and abuse contacts;
- respond promptly to NuCDN notices;
- cooperate reasonably with security and abuse investigations;
- take corrective action when requested;
- prevent unauthorized access and misuse;
- maintain appropriate permissions for Customer Content;
- respect Third-Party Rights; and
- ensure that Authorized Users comply with this AUP.
The Subscriber shall not use the Services in a manner that NuCDN reasonably determines:
- is unlawful, harmful, fraudulent, deceptive, abusive, or disruptive;
- creates an unreasonable security or operational risk;
- degrades the Services for other customers;
- causes NuCDN or a provider to receive complaints, blacklisting, sanctions, or legal demands;
- threatens NuCDN’s IP reputation or network relationships;
- circumvents Service limits or controls;
- interferes with an investigation; or
- exposes NuCDN, its providers, customers, or third parties to liability or harm.
6. UNLAWFUL ACTIVITIES
The Services must not be used to commit, promote, facilitate, conceal, fund, assist, or encourage activity that violates Applicable Law.
Prohibited unlawful activity includes, without limitation:
- cybercrime;
- computer-related fraud or forgery;
- identity theft;
- unauthorized interception or access;
- illegal access to computer systems;
- illegal data or system interference;
- misuse of devices or credentials;
- extortion or blackmail;
- money laundering;
- terrorist financing;
- distribution of illegal goods or services;
- human trafficking or exploitation;
- illegal gambling;
- intellectual-property infringement;
- privacy or data-protection violations;
- fraudulent investment or financial schemes;
- illegal surveillance;
- harassment, threats, or stalking;
- distribution of unlawful intimate material;
- obstruction of justice;
- sanctions evasion; and
- activity prohibited by a valid court or governmental order.
NuCDN is not required to determine criminal or civil liability conclusively before taking reasonable protective or contractual action.
7. CYBERSECURITY ABUSE
The Services must not be used to compromise, attack, disrupt, probe, intercept, damage, exploit, or obtain unauthorized access to any system, Account, network, application, device, or data.
Prohibited activity includes:
- exploiting vulnerabilities without authorization;
- unauthorized penetration testing;
- credential attacks;
- password cracking;
- brute-force attacks;
- credential stuffing;
- session hijacking;
- privilege escalation;
- remote-code execution against third-party systems;
- unauthorized data extraction;
- interception of communications;
- man-in-the-middle attacks;
- DNS poisoning or spoofing;
- routing attacks;
- packet injection;
- system or data interference;
- circumvention of authentication or access controls;
- deployment or control of botnets;
- command-and-control infrastructure;
- attack staging;
- credential marketplaces;
- exploit kit distribution; and
- sale or distribution of unauthorized access.
Security research and testing are permitted only where:
- the Subscriber owns the target system or has verifiable written authorization from the owner;
- the activity complies with Applicable Law;
- the activity does not affect unrelated systems or users;
- the activity remains within reasonable Resource limits;
- the activity does not involve destructive payloads or unauthorized data access;
- NuCDN has provided prior written approval where required; and
- the Subscriber complies with any conditions imposed by NuCDN.
8. MALWARE AND MALICIOUS CODE
The Services must not be used to create, host, distribute, transmit, execute, manage, sell, or facilitate:
- malware;
- ransomware;
- spyware;
- trojans;
- worms;
- viruses;
- rootkits;
- keyloggers;
- credential stealers;
- cryptojacking software;
- remote-access malware;
- botnet agents;
- command-and-control systems;
- malicious browser extensions;
- malicious mobile applications;
- drive-by downloads;
- exploit kits;
- web shells;
- payload droppers;
- malicious scripts;
- data-wiping tools used without authorization; or
- software designed primarily to evade security detection.
Legitimate malware research may be permitted only with NuCDN’s prior written approval and appropriate isolation, access controls, lawful authorization, and safety measures.
NuCDN may immediately disable, isolate, delete, quarantine, or block malicious files, domains, processes, Accounts, IP addresses, or traffic.
9. UNAUTHORIZED ACCESS AND SECURITY TESTING
Subscriber shall not perform or permit:
- unauthorized port scanning;
- vulnerability scanning;
- penetration testing;
- password testing;
- service enumeration;
- network mapping;
- automated exploit testing;
- wireless intrusion;
- credential testing;
- unauthorized scraping of protected systems;
- security-control bypass testing;
- load or stress testing against third-party systems; or
- any similar activity without lawful authorization.
Testing NuCDN-controlled infrastructure is prohibited unless NuCDN provides express written authorization.
A Subscriber requesting authorization must provide:
- the identity of the person conducting the test;
- the target systems and IP addresses;
- proof of authorization from the system owner;
- the testing dates and times;
- the testing methods;
- expected traffic volume;
- source IP addresses;
- an emergency contact; and
- other information reasonably required by NuCDN.
NuCDN may approve, deny, limit, pause, or revoke testing authorization at any time.
10. DENIAL-OF-SERVICE AND TRAFFIC ATTACKS
The Services must not be used to launch, coordinate, facilitate, amplify, relay, advertise, sell, test, or participate in:
- denial-of-service attacks;
- distributed denial-of-service attacks;
- application-layer flooding;
- protocol attacks;
- reflection or amplification attacks;
- packet floods;
- connection exhaustion attacks;
- request floods;
- resource-exhaustion attacks;
- stress-testing services directed at unauthorized targets;
- booter or stresser services;
- attack-for-hire services;
- traffic laundering;
- malicious proxying; or
- any activity intended to degrade or deny access to another service.
Subscribers must not intentionally attract attacks that materially endanger NuCDN infrastructure or other customers.
NuCDN may null-route, filter, challenge, rate-limit, isolate, reroute, suspend, or terminate traffic or Services affected by attacks.
Protective action taken during an attack does not constitute a violation of the SLA where excluded under the SLA.
11. PHISHING AND DECEPTIVE ACTIVITY
The Services must not be used for:
- phishing;
- credential harvesting;
- impersonation;
- spoofed login pages;
- fake payment or banking pages;
- fraudulent customer-support pages;
- business-email compromise;
- social-engineering campaigns;
- deceptive redirects;
- misleading domain names;
- lookalike websites intended to deceive;
- fraudulent account-verification messages;
- fake giveaways or promotions;
- romance or advance-fee scams;
- investment or recovery scams;
- fraudulent technical-support services; or
- any activity intended to obtain money, credentials, data, or access through deception.
NuCDN may immediately suspend suspected phishing infrastructure while investigating.
Subscriber must not use NuCDN branding, trademarks, logos, or communications in a manner that falsely suggests authorization, sponsorship, or affiliation.
12. SPAM AND UNSOLICITED COMMUNICATIONS
The Services must not be used to send, facilitate, relay, host, advertise, or support unsolicited or abusive communications.
Prohibited activity includes:
- unsolicited bulk email;
- unsolicited commercial messages;
- mass messaging without valid permission;
- purchased, scraped, rented, or harvested contact lists;
- email-address harvesting;
- snowshoe spam;
- spam through messaging platforms, APIs, forms, or comments;
- automated account registration;
- contact-form abuse;
- fake unsubscribe links;
- header forgery;
- sender-identity concealment;
- open mail relays;
- spamvertised websites;
- mail-bombing;
- high-volume messages causing blacklisting; and
- communications violating applicable marketing, privacy, or consumer laws.
Commercial communications must:
- be sent only to recipients for whom the sender has a lawful basis;
- accurately identify the sender;
- use truthful subject lines and content;
- include a working unsubscribe mechanism where required;
- honor opt-out requests promptly;
- comply with applicable privacy and electronic-commerce requirements; and
- not generate excessive complaints, bounces, or blacklisting.
NuCDN may restrict outbound mail, block ports, impose rate limits, require additional verification, or suspend messaging capabilities.
13. NETWORK ABUSE
Subscriber shall not engage in activity that interferes with or degrades NuCDN or third-party networks.
Prohibited network activity includes:
- IP spoofing;
- MAC spoofing used for unauthorized purposes;
- ARP poisoning;
- route hijacking;
- BGP manipulation without authorization;
- unauthorized route announcements;
- DNS amplification;
- source-address forgery;
- packet fragmentation attacks;
- broadcast or multicast abuse;
- excessive connection creation;
- network scanning;
- persistent connection abuse;
- traffic intended to exhaust ports, sessions, or state tables;
- circumvention of bandwidth controls;
- abuse of peering, transit, tunneling, or routing;
- unauthorized use of IP addresses;
- use of invalid, misleading, or forged WHOIS or network information;
- activities causing blacklisting or reputation damage; and
- interference with monitoring, logging, or security systems.
NuCDN may require remediation, traffic controls, source validation, port restrictions, route filtering, or additional security measures.
14. PROXY, VPN, AND ANONYMIZATION SERVICES
The following may not be operated without NuCDN’s prior written authorization:
- public proxy services;
- open HTTP or SOCKS proxies;
- open DNS resolvers;
- open mail relays;
- commercial VPN services;
- anonymization exit nodes;
- Tor exit nodes;
- traffic-relay services;
- residential proxy networks;
- peer-to-peer proxy networks;
- traffic-brokering systems;
- credential-sharing gateways;
- geo-restriction bypass services;
- public tunneling platforms; and
- services designed to conceal abusive or unlawful activity.
Private VPNs or proxies used solely for lawful internal access may be permitted provided that they:
- are secured against unauthorized access;
- are not open to the public;
- do not generate abuse complaints;
- do not violate Applicable Law;
- do not conceal malicious activity; and
- remain within purchased Resource limits.
NuCDN may require additional verification, abuse controls, logging, traffic restrictions, or security configuration for approved services.
15. ILLEGAL AND RESTRICTED CONTENT
Customer Content must not violate Applicable Law or Third-Party Rights.
Prohibited content includes:
- content declared unlawful by a competent court or authority;
- content facilitating criminal activity;
- fraudulent or deceptive content;
- stolen data or credentials;
- malware or exploit content used maliciously;
- counterfeit documents;
- illegal marketplaces;
- unlawfully obtained personal information;
- non-consensual intimate content;
- content promoting or facilitating human trafficking;
- content facilitating illegal drug transactions;
- content facilitating illegal weapons transactions;
- pirated or infringing content;
- content violating privacy or confidentiality obligations;
- content prohibited by applicable sanctions; and
- content subject to a valid removal or blocking order.
NuCDN may restrict Customer Content that presents a substantial legal, security, operational, or reputational risk even before a court has issued a final determination, where reasonable under the circumstances.
16. CHILD EXPLOITATION AND ABUSE
NuCDN strictly prohibits use of the Services for any form of child sexual abuse, exploitation, grooming, trafficking, or endangerment.
Prohibited activity includes:
- child sexual abuse material;
- sexualized images or videos of minors;
- grooming or solicitation of minors;
- sexual extortion involving minors;
- trafficking or exploitation of children;
- instructions for locating or distributing abusive material;
- links, archives, indexes, or search tools intended to facilitate access to abusive material;
- synthetic or computer-generated content depicting sexual abuse of minors;
- content sexualizing identifiable minors;
- advertising or facilitating sexual services involving minors; and
- attempts to evade detection or reporting requirements.
NuCDN may immediately preserve evidence, disable access, suspend Accounts, and report suspected activity to competent authorities or authorized child-protection organizations where appropriate or legally required.
No advance notice or opportunity to cure is required for suspected child exploitation or abuse.
17. SEXUAL AND ADULT CONTENT
Unless NuCDN expressly approves otherwise in writing, the following are prohibited:
- pornographic websites;
- sexually explicit videos, images, or live streams;
- adult-content distribution platforms;
- escort or prostitution-related services;
- sexual-services advertising;
- non-consensual sexual content;
- revenge pornography;
- sexual deepfakes involving identifiable persons without consent;
- content involving coercion, exploitation, or trafficking;
- content depicting sexual violence;
- content involving minors or persons presented as minors; and
- services primarily intended to distribute adult material.
Where adult content is expressly approved, the Subscriber must:
- comply with Applicable Law;
- verify the age and consent of all depicted persons;
- maintain legally required records;
- implement appropriate age restrictions;
- provide lawful notice and consent procedures;
- respond promptly to removal requests involving unauthorized content;
- prevent access by minors where required; and
- comply with any additional conditions imposed by NuCDN.
NuCDN may decline to provide Services for adult content even where the content is lawful.
18. VIOLENT, EXTREMIST, AND TERRORIST CONTENT
The Services must not be used to support, promote, glorify, recruit for, fund, coordinate, or materially assist terrorism, violent extremism, or organizations prohibited by Applicable Law.
Prohibited content and activity include:
- terrorist propaganda;
- recruitment materials;
- operational instructions for attacks;
- fundraising for prohibited organizations;
- communications coordinating violent activity;
- manifestos intended to encourage imminent violence;
- graphic content distributed primarily to glorify or promote terrorism;
- instructions for manufacturing explosives for unlawful use;
- targeting information intended to facilitate violence;
- hosting official infrastructure for a legally prohibited terrorist organization; and
- sanctions evasion for prohibited organizations or persons.
News reporting, academic research, historical documentation, counterspeech, and human-rights documentation may be permitted where lawful and not used to facilitate prohibited activity.
NuCDN may consider context, purpose, public interest, legal obligations, and risk when evaluating such content.
19. INTELLECTUAL PROPERTY INFRINGEMENT
The Services must not be used to infringe or facilitate infringement of copyrights, trademarks, patents, trade secrets, database rights, or other intellectual-property rights.
Prohibited activity includes:
- pirated software, films, music, books, games, or media;
- unauthorized streaming or download services;
- software cracks, license bypasses, or activation-key distribution;
- counterfeit goods;
- unauthorized trademark impersonation;
- distribution of stolen source code;
- circumvention of digital-rights management primarily for infringement;
- torrent indexes primarily dedicated to infringing material;
- cyberlocker services knowingly supporting repeated infringement;
- unauthorized IPTV services;
- sale of stolen digital accounts; and
- repeated infringement after notice.
Intellectual-property complaints are handled under the NuCDN Trust, Abuse, and Intellectual Property Policy.
NuCDN may disable content, proxying, caching, DNS resolution, or Account access where reasonably necessary to address a supported complaint or lawful request.
20. FRAUD AND FINANCIAL ABUSE
The Services must not be used for:
- payment fraud;
- credit-card testing;
- carding;
- stolen payment-data marketplaces;
- banking fraud;
- invoice fraud;
- business-email compromise;
- money laundering;
- investment scams;
- Ponzi or pyramid schemes;
- advance-fee fraud;
- fraudulent fundraising;
- fake charities;
- identity theft;
- account takeover;
- counterfeit payment pages;
- unauthorized financial services;
- sanctions evasion;
- fraudulent chargeback schemes;
- transaction laundering; or
- concealment of proceeds from unlawful activity.
NuCDN may require identity, business, payment, beneficial-ownership, or source-of-funds verification where reasonably necessary.
NuCDN may suspend Services during a fraud or payment-risk review.
21. REGULATED GOODS AND SERVICES
The Services must not be used to advertise, sell, distribute, facilitate, or support regulated goods or services without all legally required licenses, approvals, safeguards, and authorization.
Restricted categories include:
- controlled substances;
- prescription medicines;
- unapproved medical products;
- weapons and ammunition;
- explosives;
- hazardous materials;
- counterfeit products;
- stolen goods;
- human organs or biological materials;
- protected wildlife;
- regulated financial services;
- money transmission;
- securities or investment products;
- telecommunications services requiring authorization;
- government-issued documents;
- surveillance tools restricted by law; and
- any product or service requiring regulatory approval.
NuCDN may require proof of licensing and may decline to support a regulated activity even where lawful.
22. GAMBLING AND BETTING
Gambling, betting, lottery, casino, sweepstakes, prize, or wagering services are prohibited unless:
- the activity is lawful in every relevant jurisdiction;
- the Subscriber holds all required licenses;
- the Subscriber provides verifiable licensing information;
- the Service is not offered to prohibited locations or persons;
- appropriate age and identity verification is used;
- anti-money-laundering and responsible-gambling controls are maintained;
- NuCDN has provided prior written approval; and
- the Subscriber complies with additional conditions imposed by NuCDN.
Prohibited activity includes:
- unlicensed online casinos;
- unlicensed sports betting;
- illegal lotteries;
- unauthorized gambling payment processing;
- skin gambling;
- rigged or deceptive games;
- gambling services directed at minors;
- unauthorized gambling affiliate systems; and
- services designed to evade gambling restrictions.
NuCDN may decline all gambling-related use at its reasonable discretion.
23. CRYPTOCURRENCY AND BLOCKCHAIN ACTIVITY
The following are prohibited unless expressly authorized in writing:
- cryptocurrency mining;
- resource-intensive blockchain validation;
- unauthorized mining pools;
- cryptojacking;
- fraudulent token offerings;
- investment scams involving digital assets;
- unlicensed exchange or money-transmission services;
- mixers or tumblers used to conceal unlawful proceeds;
- stolen-wallet or seed-phrase collection;
- phishing for cryptocurrency credentials;
- malicious smart-contract distribution;
- unlawful sanctions evasion; and
- blockchain activity that creates excessive Resource usage or abuse complaints.
Lawful blockchain nodes, wallets, analytics, or related applications may be allowed on suitable paid Services where:
- Resource usage remains within plan limits;
- the activity complies with Applicable Law;
- the activity does not involve prohibited financial services;
- the Service is appropriately secured;
- the activity does not generate abuse or security risks; and
- NuCDN has not imposed a product-specific restriction.
24. ARTIFICIAL INTELLIGENCE AND AUTOMATED USE
Artificial intelligence, machine learning, automated agents, crawlers, bots, or high-volume automation must not be used to:
- generate or distribute unlawful content;
- impersonate persons fraudulently;
- create phishing, malware, spam, or deceptive materials;
- conduct unauthorized scanning or attacks;
- scrape data in violation of law, contract, access controls, or Third-Party Rights;
- circumvent rate limits or usage limits;
- generate abusive or excessive traffic;
- create non-consensual intimate content;
- facilitate child exploitation;
- automate fraud or financial abuse;
- manipulate engagement or advertising fraudulently;
- operate fake-account networks;
- generate harmful deepfakes for deception or abuse; or
- interfere with NuCDN systems or other customers.
Automated use must:
- remain within plan limits;
- comply with robots, authentication, and access controls where applicable;
- identify itself where required by law or industry practice;
- respect opt-out and deletion requests;
- maintain appropriate human oversight;
- avoid excessive or destabilizing Resource consumption; and
- comply with privacy, intellectual-property, and consumer-protection requirements.
NuCDN may rate-limit or block automated traffic that creates security, stability, cost, or abuse concerns.
25. PRIVACY AND PERSONAL DATA
Subscriber must not collect, process, disclose, sell, transfer, monitor, or use Personal Data through the Services in violation of Applicable Law or the NuCDN Privacy Policy.
Prohibited activity includes:
- unauthorized collection of Personal Data;
- credential harvesting;
- unlawful tracking or profiling;
- sale of unlawfully obtained Personal Data;
- doxxing;
- distribution of stolen databases;
- non-consensual disclosure of sensitive information;
- illegal surveillance;
- unauthorized interception of communications;
- processing children’s data without required safeguards;
- failure to honor applicable Data Subject rights;
- processing without a lawful basis;
- failure to provide required privacy notices;
- unlawful cross-border transfer; and
- failure to implement appropriate security safeguards.
Subscriber is responsible for:
- determining the lawful basis for its processing;
- providing required privacy notices;
- obtaining required consent or authorization;
- responding to Data Subject requests;
- maintaining appropriate data-processing agreements;
- configuring security and retention controls;
- reporting Personal Data breaches where required; and
- ensuring that NuCDN’s processing instructions are lawful.
NuCDN may restrict processing that creates an unreasonable privacy, security, compliance, or legal risk.
26. RESOURCE USAGE AND FAIR USE
Subscriber must use Resources in a commercially reasonable manner consistent with the selected Service plan.
Prohibited or restricted Resource use includes:
- sustained CPU usage that materially affects shared infrastructure;
- excessive memory use;
- excessive disk input and output;
- excessive process or connection counts;
- excessive database queries;
- excessive file or inode counts;
- storage of disproportionately large files on shared hosting;
- high-volume automated requests;
- continuous background processes not supported by the plan;
- resource-intensive transcoding or rendering;
- high-volume crawling;
- cryptocurrency mining;
- public file distribution inconsistent with the plan;
- use intended to avoid purchasing a suitable plan;
- circumvention of quotas or metering;
- creating multiple Accounts to evade limits; and
- activity that degrades other customers’ Services.
NuCDN may:
- notify the Subscriber;
- request optimization;
- apply temporary throttling;
- limit processes or connections;
- restrict features;
- require migration to another plan;
- charge applicable overages;
- isolate the affected Service;
- suspend the Service; or
- terminate repeated or harmful usage.
“Unlimited” or “unmetered” descriptions do not permit unreasonable, abusive, unlawful, or infrastructure-disrupting use.
27. BANDWIDTH AND UNMETERED SERVICES
Bandwidth and traffic are subject to the technical capabilities, port speed, network conditions, plan specifications, and fair-use requirements of the selected Service.
Unmetered bandwidth means that ordinary traffic is not billed per unit under the applicable plan. It does not mean:
- unlimited physical capacity;
- guaranteed constant line-rate usage;
- permission to disrupt shared infrastructure;
- permission to generate artificial traffic;
- permission to operate attack or amplification services;
- permission to evade traffic controls;
- permission to resell bandwidth without authorization; or
- permission to use Resources in a manner inconsistent with the plan.
NuCDN may apply reasonable traffic-management measures to:
- protect network stability;
- mitigate attacks;
- manage congestion;
- enforce plan limits;
- prevent abuse;
- protect upstream relationships;
- comply with legal requirements; or
- maintain fair access for customers.
Subscribers requiring sustained high-bandwidth workloads must disclose those requirements and purchase an appropriate Service.
28. STORAGE AND BACKUP RESTRICTIONS
Unless the selected Service is expressly designed for storage or backup, the Services must not be used primarily as:
- a bulk file repository;
- a personal cloud drive;
- a backup archive;
- a public file-sharing platform;
- a media mirror;
- a software mirror;
- a download portal;
- a torrent seedbox;
- a video-streaming origin;
- an archival cold-storage service;
- a data-lake platform;
- a permanent log archive; or
- a repository for unrelated third-party files.
Subscriber must not store:
- illegal or infringing files;
- malware;
- stolen data;
- unencrypted credentials;
- unencrypted private keys;
- unlawfully obtained Personal Data;
- content violating this AUP; or
- data for which the Subscriber lacks sufficient rights or authorization.
Subscriber remains responsible for independent backups. NuCDN does not guarantee recovery unless expressly stated in a separate backup agreement.
29. FREE, TRIAL, AND PROMOTIONAL SERVICES
Free, trial, beta, preview, and promotional Services are subject to stricter Resource and fair-use limitations.
The following are prohibited on free Services unless expressly permitted:
- commercial file hosting;
- backup storage;
- mirror hosting;
- video or audio streaming;
- high-traffic download services;
- bulk email or messaging;
- automation platforms;
- public APIs generating substantial usage;
- continuous background workers;
- proxies or VPNs;
- cryptocurrency or blockchain workloads;
- resource-intensive scripts;
- resale or subleasing;
- business-critical production workloads;
- high-risk or regulated content;
- content generating repeated abuse complaints; and
- any activity NuCDN determines unsuitable for a free Service.
NuCDN may impose:
- storage limits;
- bandwidth limits;
- request limits;
- CPU and memory limits;
- file-size limits;
- database limits;
- inactivity limits;
- feature restrictions;
- advertising or branding requirements;
- automatic suspension; and
- automatic deletion after inactivity.
Free Services may be modified, restricted, suspended, or discontinued at any time without a Service Credit or uptime guarantee.
30. RESELLERS AND DOWNSTREAM USERS
A Subscriber that resells, sublicenses, manages, or provides Services to downstream users must:
- obtain NuCDN’s authorization where required;
- maintain enforceable customer terms consistent with this AUP;
- provide an abuse-reporting process;
- maintain accurate downstream-customer records;
- respond promptly to NuCDN notices;
- investigate downstream abuse;
- suspend or terminate violating users where reasonably required;
- prevent repeat abuse;
- comply with privacy and consumer laws;
- maintain appropriate verification and billing controls;
- not misrepresent its relationship with NuCDN; and
- remain responsible for all downstream activity.
NuCDN may contact a downstream user directly where reasonably necessary to address an urgent security, abuse, legal, or safety issue.
Failure by a reseller to control downstream abuse may result in restriction or termination of the reseller’s Account.
31. SECURITY AND ACCOUNT MANAGEMENT
Subscriber must implement reasonable security measures, including:
- strong and unique passwords;
- multi-factor authentication where available;
- restricted administrator access;
- timely removal of former users;
- secure storage of API keys and tokens;
- software updates and security patches;
- firewalls and access controls;
- malware protection;
- monitoring and logging;
- secure backups;
- encryption where appropriate;
- incident-response procedures;
- regular review of Authorized Users; and
- appropriate security for origin servers and applications.
Subscriber must notify NuCDN promptly after discovering:
- unauthorized Account access;
- credential compromise;
- malware infection;
- system exploitation;
- data loss or exposure;
- abusive activity;
- unexpected traffic;
- unauthorized configuration changes; or
- another incident that may affect NuCDN or third parties.
NuCDN may reset credentials, revoke tokens, restrict access, or require additional security controls where an Account is suspected of compromise.
32. ABUSE NOTICES AND COOPERATION
Subscriber must maintain valid administrative, technical, and abuse contacts and regularly monitor communications sent to those contacts.
After receiving an Abuse Report or NuCDN notice, the Subscriber must:
- acknowledge the notice within the stated period;
- investigate promptly;
- stop or contain prohibited activity;
- preserve relevant evidence where appropriate;
- provide a substantive response;
- describe corrective action;
- remove or secure compromised systems;
- prevent recurrence;
- provide requested logs or technical information where lawful;
- cooperate with NuCDN’s investigation; and
- comply with any reasonable remediation deadline.
Response periods may vary according to severity.
NuCDN may require immediate action for:
- phishing;
- malware;
- child exploitation;
- active attacks;
- fraud;
- credential theft;
- large-scale spam;
- imminent safety risks;
- legal orders; or
- activity threatening infrastructure.
Failure to respond may result in immediate enforcement.
33. INVESTIGATIONS
NuCDN may investigate suspected violations using information reasonably available to it, including:
- Account records;
- network and security logs;
- traffic metadata;
- DNS records;
- system events;
- support communications;
- payment and verification information;
- publicly available information;
- third-party complaints;
- threat-intelligence sources;
- provider reports;
- law-enforcement communications;
- Subscriber responses; and
- technical testing or analysis.
NuCDN may:
- request information from the Subscriber;
- require identity or business verification;
- preserve relevant records;
- inspect files or processes where reasonably necessary and lawful;
- temporarily isolate a Resource;
- scan suspected malicious content;
- share necessary information with providers or authorities;
- require security remediation;
- retain evidence; and
- take protective action before completing an investigation.
NuCDN is not required to disclose confidential security methods, complainant identities, provider information, legal requests, internal detection rules, or information that could compromise an investigation.
34. ENFORCEMENT ACTIONS
Where NuCDN reasonably believes that this AUP has been violated or that action is necessary to prevent harm, NuCDN may:
- issue a warning;
- request information;
- require remediation;
- require verification;
- limit Resources;
- rate-limit traffic;
- block ports or protocols;
- block domains, hostnames, URLs, files, or IP addresses;
- disable caching or proxying;
- disable DNS resolution;
- quarantine Customer Content;
- remove or disable access to content;
- revoke API keys or credentials;
- restrict Account access;
- isolate a server or virtual machine;
- null-route traffic;
- suspend an Affected Service;
- suspend the entire Account;
- terminate Services;
- decline future Orders;
- require migration to another Service;
- charge remediation or administrative costs where permitted;
- notify affected providers or third parties;
- report unlawful activity to competent authorities; or
- take another reasonable action permitted by the Terms and Conditions.
NuCDN may select an enforcement action based on:
- severity;
- urgency;
- risk of harm;
- legal obligations;
- Subscriber cooperation;
- history of violations;
- intent or negligence;
- effect on other customers;
- provider requirements;
- reputation or blacklisting risk;
- technical feasibility; and
- likelihood of recurrence.
NuCDN is not required to apply enforcement measures in a particular order.
35. CONTENT AND TRAFFIC RESTRICTIONS
NuCDN may restrict, filter, challenge, reroute, block, cache, remove, quarantine, or disable access to content or traffic where reasonably necessary to:
- enforce this AUP;
- protect security and stability;
- respond to attacks;
- prevent fraud or abuse;
- comply with Applicable Law;
- comply with a lawful court or governmental order;
- comply with a provider requirement;
- protect Third-Party Rights;
- prevent blacklisting;
- protect individuals from harm;
- investigate a suspected violation; or
- maintain the Services.
Technical enforcement may affect legitimate traffic or content during an emergency or investigation. NuCDN will use commercially reasonable efforts to limit unnecessary disruption but does not guarantee that all protective measures will be error-free.
36. EMERGENCY ACTION
NuCDN may act immediately and without prior notice where it reasonably believes that:
- an active attack is occurring;
- malware or phishing is active;
- credentials or Personal Data are being stolen;
- a system is compromised;
- child exploitation material is involved;
- there is an imminent threat to life or safety;
- continued operation threatens infrastructure;
- a provider requires urgent action;
- a legal order requires immediate compliance;
- continued use may cause substantial liability or harm; or
- delay would materially increase risk.
Emergency action may include immediate suspension, null-routing, content disabling, isolation, credential revocation, traffic blocking, evidence preservation, or notification to authorities.
NuCDN will provide notice after emergency action where reasonably practicable and legally permitted.
37. REPEAT VIOLATIONS
NuCDN may impose stronger enforcement for repeated, related, or unresolved violations.
Factors indicating repeated abuse may include:
- multiple Abuse Reports;
- repeated compromise caused by inadequate security;
- failure to remediate vulnerabilities;
- repeated spam or phishing;
- multiple infringing websites;
- repeated creation of replacement Accounts;
- migration of prohibited content between Services;
- attempts to evade previous enforcement;
- continued abuse by downstream customers;
- false or misleading responses;
- failure to maintain valid contact details; and
- activity linked to previously terminated persons or organizations.
Repeat violations may result in permanent termination, refusal of future Services, blocking of related Accounts, or notification to providers or authorities.
38. REPORTING ABUSE
To report suspected abuse involving NuCDN Services, submit an abuse ticket through:
https://my.nucdn.co/submitticket.php?step=2&deptid=7
Abuse reports may also be sent to:
Email: legal@nucdn.co / abuse@nucdn.co
A clear subject line should be used, such as:
- Abuse Report — Phishing Website
- Abuse Report — Malware Distribution
- Abuse Report — Spam Activity
- Abuse Report — Network Attack
- Abuse Report — Copyright Infringement
- Abuse Report — Child Safety Concern
An Abuse Report should include:
- the complainant’s name and contact information;
- the type of alleged abuse;
- the affected domain, URL, hostname, IP address, Account, or Service;
- the date and time of the activity, including time zone;
- a description of the activity;
- relevant logs, email headers, screenshots, or technical evidence;
- the specific content or traffic involved;
- the legal right or interest affected, where applicable;
- a statement that the report is submitted in good faith; and
- any other information reasonably necessary to investigate.
Reports lacking sufficient information may be delayed or closed without action.
Knowingly false, fraudulent, abusive, or misleading reports are prohibited.
39. COUNTER-NOTICES AND APPEALS
A Subscriber affected by an enforcement action may submit a written appeal unless:
- the action was required by Applicable Law;
- the action was required by a binding court or governmental order;
- an appeal would compromise security or an investigation;
- the Account was terminated for fraud or identity misrepresentation;
- the matter involves imminent safety concerns;
- the matter involves child exploitation; or
- NuCDN reasonably determines that review is unavailable.
An appeal should include:
- the Account and Service identifier;
- the enforcement notice or ticket number;
- a clear explanation of why the action should be reconsidered;
- supporting evidence;
- details of remediation completed;
- measures implemented to prevent recurrence; and
- confirmation that the Subscriber will comply with this AUP.
Submission of an appeal does not automatically restore a Service or pause enforcement.
NuCDN may uphold, modify, reverse, or impose conditions on an enforcement decision.
NuCDN’s decision following reasonable internal review is final under NuCDN’s contractual processes, without limiting any non-waivable legal right.
40. COSTS AND REMEDIATION
To the extent permitted by the Terms and Conditions and Applicable Law, the Subscriber may be responsible for reasonable costs caused by its violation, including:
- investigation costs;
- security-response costs;
- malware-remediation costs;
- network mitigation costs;
- provider or data-center charges;
- IP delisting or reputation-recovery costs;
- replacement IP-resource costs;
- administrative costs;
- legal and regulatory-response costs;
- restoration or reactivation fees;
- equipment replacement costs;
- excess bandwidth or Resource charges;
- third-party claims or penalties; and
- reasonable professional fees.
Payment of costs does not require NuCDN to restore a terminated or suspended Service.
NuCDN may require a security deposit, advance payment, additional verification, or a remediation plan before restoring Services.
41. NO GENERAL MONITORING OBLIGATION
NuCDN does not undertake a general obligation to monitor all Customer Content, communications, or activities conducted through the Services.
However, NuCDN may monitor, inspect, analyze, scan, filter, log, or investigate activity where reasonably necessary to:
- provide and secure the Services;
- detect threats or abuse;
- enforce this AUP;
- respond to an Abuse Report;
- investigate a security incident;
- comply with Applicable Law;
- protect legal rights;
- maintain network stability;
- prevent fraud; or
- protect customers and third parties.
NuCDN’s failure to detect or act on a violation does not constitute approval, waiver, negligence, or an assumption of responsibility for Customer Content.
42. LAW ENFORCEMENT AND LEGAL REQUESTS
NuCDN may preserve or disclose information where reasonably and lawfully necessary to:
- comply with a warrant, subpoena, court order, or lawful governmental request;
- respond to an emergency involving danger to life or safety;
- investigate cybercrime, fraud, abuse, or unauthorized access;
- protect NuCDN’s legal rights and infrastructure;
- enforce the Terms and Conditions;
- support a lawful regulatory inquiry; or
- respond to valid Subscriber authorization.
Where legally permitted and appropriate, NuCDN may:
- request clarification;
- verify authority;
- challenge an invalid or overbroad request;
- limit disclosure to relevant information;
- notify the affected Subscriber; and
- seek confidential treatment.
NuCDN may be prohibited from notifying a Subscriber of certain legal requests.
Subscriber must not obstruct, conceal evidence, retaliate against a complainant, or interfere with a lawful investigation.
43. SERVICE LEVEL EXCLUSIONS
Any restriction, filtering, suspension, interruption, degradation, or termination resulting from:
- a violation of this AUP;
- an abuse investigation;
- security mitigation;
- fraud review;
- Account compromise;
- Subscriber misconfiguration;
- Resource abuse;
- a legal or regulatory request;
- a provider requirement;
- emergency action;
- malicious traffic;
- content disabling; or
- another enforcement measure permitted by this AUP
is excluded from availability calculations and does not qualify for a Service Credit under the NuCDN Service Level Agreement.
44. MODIFICATIONS
NuCDN may update this AUP to reflect changes in:
- Applicable Law;
- security threats;
- abuse patterns;
- technology;
- network operations;
- Services;
- provider requirements;
- industry practices;
- regulatory guidance; or
- business operations.
The current version will be published at:
https://www.nucdn.co/legal/aup/
NuCDN will revise the “Last Updated” date when changes are published.
Where a change materially affects Subscriber obligations, NuCDN will provide reasonable notice where practicable, unless immediate effectiveness is reasonably required for security, legal, fraud-prevention, provider, or emergency reasons.
Continued use of the Services after the applicable effective date constitutes acceptance of the revised AUP.
An update does not prevent NuCDN from acting against activity that was already prohibited under Applicable Law, the Terms and Conditions, or a previous version of this AUP.
45. GOVERNING TERMS
This AUP is governed by and construed in accordance with the NuCDN Terms and Conditions.
The following provisions of the Terms and Conditions remain fully applicable:
- Subscriber responsibilities;
- suspension and emergency action;
- Customer Content;
- privacy and data processing;
- fees and payment;
- termination;
- warranty disclaimer;
- limitation of liability;
- indemnification;
- governing law;
- dispute resolution;
- jurisdiction and venue;
- electronic communications;
- force majeure;
- assignment;
- waiver;
- severability; and
- entire agreement.
This AUP does not replace the Terms and Conditions and must be interpreted consistently with them.
46. CONTACT INFORMATION
For abuse reports, security concerns, suspected violations, or AUP-related inquiries, contact:
Cañaveral Group (CGC), acting through NuCDN
Abuse Ticket: https://my.nucdn.co/submitticket.php?step=2&deptid=7
Legal and Abuse Email: legal@nucdn.co / abuse@nucdn.co
Telephone: +63 961 904 8179
Business Address: Unit E-0054, 5th Floor, CBC Asia Technozone, Aguinaldo Highway, Talaba I, Bacoor City, Cavite 4102, Philippines
Emergency security concerns should be clearly identified in the ticket subject and should include sufficient technical information to allow prompt investigation.
47. ACCEPTANCE
BY CREATING AN ACCOUNT, PURCHASING, ACCESSING, CONFIGURING, OR USING THE SERVICES, THE SUBSCRIBER ACKNOWLEDGES THAT IT HAS READ, UNDERSTOOD, AND AGREED TO THIS AUP, THE TERMS AND CONDITIONS, AND ALL APPLICABLE INCORPORATED POLICIES.
THE SUBSCRIBER IS RESPONSIBLE FOR ENSURING THAT ITS AUTHORIZED USERS, RESELLERS, DOWNSTREAM CUSTOMERS, AND END USERS COMPLY WITH THIS AUP.
IF THE SUBSCRIBER DOES NOT AGREE TO THIS AUP, THE SUBSCRIBER MUST NOT ACCESS, PURCHASE, CONFIGURE, OR USE THE SERVICES.