Acceptable Use Policy
Effective Date: September 30, 2026 · Last Updated: September 30, 2026
This Acceptable Use Policy ("AUP") governs use of services provided by Covariant Systems LLC d/b/a HelixNodes ("HelixNodes," "we," "us," or "our").
This AUP is incorporated into the HelixNodes Terms of Service.
It applies to all HelixNodes Services and to all activity conducted through them, including activity performed by customers, employees, contractors, users, applications, scripts, downstream customers, and compromised systems.
You are responsible for ensuring that anyone using Services under your account complies with this AUP.
This AUP is intended to protect HelixNodes customers, networks, upstream providers, Internet users, and the integrity and reputation of HelixNodes infrastructure.
The examples below are illustrative and are not an exhaustive list of prohibited conduct.
1. General Principle
You may use HelixNodes Services for lawful purposes that do not:
- harm others;
- interfere with networks or systems;
- create unreasonable security or operational risks;
- violate third-party rights;
- damage HelixNodes' network or IP reputation; or
- expose HelixNodes or its suppliers to unreasonable legal, technical, or financial risk.
2. Illegal Activity
You may not use the Services to engage in, promote, facilitate, or materially assist activity that violates applicable law.
This includes use of the Services for unlawful:
- fraud;
- theft;
- trafficking;
- extortion;
- unauthorized access;
- identity theft;
- distribution of controlled substances;
- financial schemes;
- infringement;
- exploitation; or
- other criminal activity.
A mere allegation that content is unlawful does not necessarily require us to remove it. We may consider the circumstances, applicable law, credible legal demands, court orders, and other relevant evidence.
3. Child Sexual Abuse Material and Exploitation
The Services may not be used to create, possess, host, distribute, solicit, advertise, facilitate access to, or otherwise support:
- child sexual abuse material ("CSAM");
- sexual exploitation of minors;
- grooming of minors for sexual activity;
- trafficking or exploitation of minors; or
- synthetic or computer-generated material that is unlawful under applicable child-exploitation laws.
Suspected CSAM or child exploitation may be reported to relevant authorities or organizations as required by law.
We may immediately preserve evidence, disable access, suspend Services, or terminate an account in connection with suspected child exploitation.
4. Non-Consensual Sexual Content
You may not use the Services to knowingly host or distribute unlawful intimate imagery, including intimate material distributed without the depicted person's consent where prohibited by applicable law.
5. Malware and Malicious Software
You may not knowingly use the Services to develop, deploy, distribute, host, control, or facilitate malware or malicious infrastructure intended to compromise systems or harm others.
Prohibited uses include malicious:
- ransomware;
- botnets;
- credential stealers;
- infostealers;
- spyware;
- worms;
- trojans;
- malicious loaders;
- command-and-control infrastructure; or
- exploit infrastructure.
Legitimate malware analysis, threat research, honeypots, reverse engineering, and controlled security research may be permitted where conducted safely and lawfully and where the activity does not attack or compromise third-party systems.
Contact us before deploying unusual security-research infrastructure if it may generate abuse complaints or resemble malicious activity.
6. Unauthorized Access and Hacking
You may not access or attempt to access systems, accounts, data, or networks without authorization.
This includes:
- credential stuffing;
- password spraying against third parties;
- brute-force attacks;
- exploitation of vulnerabilities without authorization;
- bypassing authentication;
- stealing credentials;
- unauthorized privilege escalation; or
- accessing data without permission.
Possession of a publicly accessible IP address or Internet-facing service does not by itself constitute authorization to attack or exploit that system.
7. Port Scanning and Vulnerability Scanning
Unauthorized scanning of third-party networks is prohibited where the scanning is abusive, disruptive, excessively broad, intended to identify targets for exploitation, or conducted without appropriate authorization.
Legitimate security testing of systems you own or are authorized to test is allowed.
Research scanning may be permitted where it:
- has a legitimate research purpose;
- is appropriately rate-limited;
- does not attempt exploitation;
- identifies its source where reasonably appropriate;
- honors reasonable opt-out requests; and
- does not materially disrupt remote systems.
HelixNodes may require evidence of authorization or additional information regarding large-scale scanning activity.
8. Denial-of-Service Attacks
You may not use the Services to originate, coordinate, amplify, participate in, facilitate, or control:
- denial-of-service attacks;
- distributed denial-of-service attacks;
- packet floods;
- SYN floods;
- reflection or amplification attacks;
- application-layer exhaustion attacks; or
- other intentional attempts to impair availability of a third-party service.
Testing against systems you own or are expressly authorized to test may be permitted, but high-volume testing capable of materially affecting HelixNodes infrastructure requires prior written approval.
9. Retaliatory or Attack-Attracting Activity
You may not knowingly use the Services in a manner primarily intended to provoke attacks against HelixNodes infrastructure.
This includes deliberately announcing attack challenges, operating infrastructure designed principally to attract hostile traffic, or repeatedly provoking third parties into attacking addresses on the HelixNodes network.
Receiving an unsolicited DDoS attack does not itself violate this policy.
10. IP Spoofing and Packet Manipulation
You may not transmit traffic with falsified source information where doing so is deceptive, unauthorized, or intended to facilitate abuse.
Prohibited activities include unauthorized IP-source spoofing and deceptive packet-header forgery.
Legitimate laboratory testing within isolated environments is permitted.
11. Phishing and Credential Theft
Phishing is strictly prohibited.
You may not use the Services to:
- impersonate legitimate services for credential theft;
- operate fake authentication pages;
- harvest passwords, private keys, authentication tokens, or payment credentials;
- redirect victims to phishing infrastructure; or
- host content materially supporting phishing campaigns.
Confirmed phishing infrastructure may be disabled immediately.
12. Spam and Unsolicited Messaging
You may not use the Services to send or facilitate unsolicited bulk messages.
This includes unsolicited:
- commercial email;
- bulk promotional email;
- SMS;
- messaging-platform messages; or
- substantially similar electronic communications.
Bulk or commercial email must comply with applicable laws and recognized opt-in practices.
You must maintain evidence of consent for recipients where consent is required.
You may not:
- purchase or scrape address lists for unsolicited mailing;
- use harvested email addresses;
- use deceptive sender identities;
- conceal message origin;
- evade spam filters;
- continue mailing recipients who have opted out; or
- operate infrastructure whose primary purpose is unsolicited messaging.
13. Email Reputation
You are responsible for mail originating from your Services.
You must take reasonable measures to prevent compromised accounts, open relays, vulnerable web applications, or unauthorized users from sending spam.
You may not knowingly use the Services in a way that causes HelixNodes address space to be repeatedly or materially listed by widely recognized blocklists such as Spamhaus.
We may restrict outbound SMTP, block port 25, rate-limit mail, or suspend mail functionality where reasonably necessary to protect network reputation.
We may require additional verification before enabling unrestricted outbound email.
14. Email Lists
If you operate mailing lists or send bulk commercial email, you must:
- send only to recipients with an appropriate basis to receive the messages;
- maintain evidence supporting that basis;
- accurately identify the sender;
- provide a practical unsubscribe mechanism;
- honor opt-out requests promptly;
- maintain appropriate bounce handling; and
- comply with applicable anti-spam law.
"Opt-out" purchased, rented, scraped, or harvested mailing lists are not acceptable merely because recipients are offered an unsubscribe link.
15. Open Relays and Insecure Services
You may not knowingly operate an insecure service that is being actively abused.
We may require remediation of:
- open mail relays;
- open recursive DNS resolvers;
- publicly writable proxies;
- exposed databases;
- compromised CMS installations; or
- other insecure configurations being used to attack third parties.
Operating a legitimate VPN, private proxy, DNS server, or similar application is not inherently prohibited, provided it is appropriately secured and otherwise complies with this AUP.
16. Proxies and VPNs
VPNs and proxy services are permitted unless otherwise stated for a particular plan, provided they are not used primarily to facilitate abuse.
Public or commercial proxy services must take reasonable measures to address abuse.
We may require an operator to disable abusive users or traffic sources.
17. Tor
Operating Tor infrastructure is subject to the following conditions:
- Tor clients are generally permitted.
- Tor relays that do not permit exit traffic are generally permitted.
- Tor exit nodes require prior written approval from HelixNodes.
We may deny or withdraw approval where a Tor exit node generates disproportionate abuse complaints or operational risk.
18. Copyright and Intellectual Property
You may not knowingly use the Services to infringe copyright, trademark, trade-secret, or other intellectual-property rights.
Examples include unauthorized distribution of:
- copyrighted movies;
- television programming;
- commercial software;
- games;
- music;
- books; or
- other protected works.
This provision does not prohibit activity permitted by license, fair use, public-domain status, or other applicable legal authority.
HelixNodes may process properly submitted copyright complaints and may terminate repeat infringers in appropriate circumstances.
19. BitTorrent and Peer-to-Peer Traffic
BitTorrent and other peer-to-peer technologies are not inherently prohibited on VPS Services unless a plan states otherwise.
You are responsible for ensuring that the material transferred is lawful and that your activity does not:
- infringe copyrights;
- create excessive abuse complaints;
- exceed resource allocations;
- harm network performance; or
- violate other provisions of this AUP.
Shared web-hosting accounts may not be used as high-volume torrent seedboxes or general-purpose file-distribution infrastructure unless expressly permitted by the applicable plan.
20. Adult Content
Lawful adult content involving consenting adults is not categorically prohibited unless otherwise specified for a product.
However, content is prohibited if it:
- involves minors;
- is non-consensual;
- violates applicable law;
- depicts unlawful exploitation;
- is used for trafficking or coercion; or
- otherwise violates this AUP.
You are responsible for applicable age-verification, recordkeeping, and other legal requirements.
21. Harassment, Threats, and Doxxing
You may not use the Services to make credible unlawful threats, facilitate targeted unlawful harassment, or unlawfully publish highly sensitive personal information for the purpose of enabling physical harm or criminal activity.
Legitimate journalism, criticism, public-record publication, security research, or discussion of publicly available information is not prohibited merely because another person finds it objectionable.
22. Fraud and Deception
You may not use the Services for fraudulent schemes, including:
- impersonation intended to defraud;
- fake storefronts designed to steal payment data;
- investment scams;
- advance-fee fraud;
- Ponzi or pyramid schemes where unlawful;
- fraudulent support operations;
- payment-card fraud;
- fake escrow services; or
- intentionally deceptive schemes designed to steal money or credentials.
23. Cryptocurrency
Operating ordinary cryptocurrency software, wallets, nodes, or blockchain applications is generally permitted on VPS products if otherwise lawful.
Cryptocurrency mining is prohibited on shared hosting.
On VPS products, mining or similar sustained computation may be restricted where it creates excessive CPU, power, storage, or I/O consumption inconsistent with the purchased Service.
Cryptocurrency theft, cryptojacking, fraudulent investment schemes, and malicious mining are prohibited.
24. Resource Abuse
You may not consume shared resources in a manner that materially and repeatedly degrades service for other customers.
Examples may include excessive:
- CPU usage;
- disk I/O;
- process counts;
- database load;
- memory pressure;
- storage operations;
- network packet rates; or
- mail volume.
Resource enforcement will take into account the type of Service purchased.
A workload considered inappropriate for shared web hosting may be entirely acceptable on a properly sized VPS.
Where practical, we will generally provide an opportunity to optimize, reduce usage, or upgrade before suspending a legitimate workload.
Immediate intervention may occur where continued usage threatens system stability.
25. Shared Web Hosting Restrictions
Shared web-hosting accounts are intended primarily to operate websites, web applications, databases, and associated email.
Unless expressly included with a plan, shared hosting may not be used primarily as:
- an offsite backup repository;
- general-purpose cloud storage;
- a video-streaming origin;
- a public file mirror;
- a high-volume download server;
- a cryptocurrency miner;
- a compute worker;
- a game server;
- a VPN or proxy server; or
- a persistent background-compute environment.
These restrictions do not ordinarily apply to VPS Services unless specifically stated.
26. Circumvention of Service Limits
You may not intentionally bypass Service limits or enforcement mechanisms.
This includes:
- creating multiple accounts to avoid restrictions;
- manipulating usage reporting;
- circumventing bandwidth limits;
- evading mail restrictions;
- evading abuse suspensions;
- repeatedly replacing suspended Services to continue prohibited activity; or
- falsifying information to obtain additional resources.
27. IP Reputation
HelixNodes has a legitimate interest in maintaining the reputation and routability of its address space.
You may not engage in conduct that causes repeated or substantial:
- spam listings;
- malware listings;
- fraud listings;
- abuse-provider complaints;
- network blocks;
- routing sanctions; or
- similar reputation damage.
The existence of one inaccurate or isolated blocklist entry does not automatically constitute a violation.
We evaluate the nature, source, frequency, and credibility of reports.
28. Abuse of Third-Party Services
Using HelixNodes infrastructure to intentionally circumvent technical restrictions imposed by third parties may violate this AUP where the activity is deceptive, unauthorized, abusive, or materially harmful.
Customers conducting scraping, crawling, automated testing, or high-volume API access are responsible for ensuring their activity is authorized and appropriately rate-limited.
29. Scraping and Crawling
Automated crawling and scraping are permitted where lawful and responsibly conducted.
You may not use the Services for crawling or scraping that:
- causes material disruption;
- evades access controls without authorization;
- performs credential attacks;
- ignores reasonable technical rate limits in an abusive manner; or
- is otherwise unlawful.
30. Security Research
HelixNodes supports legitimate security research.
Security-research workloads are generally permitted where you:
- have authorization to test the target;
- use reasonable safeguards;
- avoid harming unrelated systems;
- do not use stolen credentials or data;
- do not deploy malicious payloads against unauthorized targets; and
- comply with applicable law.
If your research is likely to appear malicious from ordinary network-abuse telemetry, you should notify HelixNodes in advance.
31. Network Monitoring
You may monitor traffic and systems you own or are authorized to monitor.
Intercepting private communications or network traffic without appropriate authorization is prohibited.
32. Resellers and Downstream Users
If you resell HelixNodes Services or provide services to downstream customers, you remain responsible for activity originating from resources assigned to your account.
You must maintain:
- valid contact information;
- a reasonable abuse-reporting process; and
- the ability to promptly address abuse by downstream customers.
Repeated failure to manage downstream abuse may result in restriction or termination.
33. Abuse Complaints
Abuse reports should be sent to:
support@helixnodes.com
A useful report should include, where available:
- source IP address;
- destination IP address;
- timestamp and timezone;
- relevant logs;
- URLs;
- email headers;
- packet captures;
- screenshots; and
- a description of the incident.
We may request additional information before acting.
34. Abuse Notices to Customers
Where appropriate, we will generally attempt to notify the affected customer of an AUP issue.
The notice may specify a remediation deadline based on severity.
For routine issues, we may allow a reasonable period for investigation and correction.
For severe or active abuse, we may act before contacting you.
Examples include:
- active phishing;
- ongoing DDoS attacks;
- active malware distribution;
- botnet command-and-control;
- large-scale brute force;
- active spam outbreaks;
- child exploitation;
- immediate threats to network stability; or
- circumstances requiring immediate action by law.
35. Protective Measures
We may take technically reasonable measures to stop or mitigate abuse, including:
- packet filtering;
- firewall rules;
- blocking ports;
- rate limiting;
- removing network connectivity;
- null-routing addresses;
- disabling a website;
- isolating a virtual server;
- suspending a Service; or
- terminating an account.
Where possible, we will choose measures proportionate to the problem.
36. Compromised Systems
You are responsible for securing compromised Services.
A compromised system is not automatically treated as intentional abuse.
However, once notified, you must take reasonable steps to remediate it.
Repeated compromises, failure to respond, or failure to secure a Service may result in suspension or termination.
37. Repeat Violations
Repeated AUP violations may result in escalating enforcement.
We may consider:
- severity;
- frequency;
- whether violations were intentional;
- cooperation;
- remediation efforts;
- previous warnings; and
- risk to other users or the network.
Repeated severe abuse may result in account-wide termination.
38. Evasion Following Suspension
You may not create or use new accounts or Services for the purpose of circumventing an abuse-related suspension or termination.
39. Staff and Support Abuse
Threats of violence, unlawful harassment, or sustained abusive conduct directed toward HelixNodes employees or contractors are prohibited.
We understand that customers may be frustrated and may strongly criticize the company or its decisions. Mere criticism, complaints, profanity, or disagreement will not by itself constitute an AUP violation.
We may restrict communications or terminate the relationship where conduct becomes threatening, harassing, or materially interferes with our ability to provide support.
40. No Duty to Monitor
HelixNodes does not undertake a general obligation to monitor Customer Content or actively police all customer activity.
Our ability to investigate or act upon abuse does not create a duty to monitor all Services.
41. Enforcement Discretion
Not every technical violation requires the same response.
We may consider context, severity, intent, harm, history, technical necessity, and customer cooperation.
Nothing in this AUP requires HelixNodes to allow continued activity merely because substantially similar activity was previously permitted.
42. Changes to this Policy
We may update this AUP to address:
- new abuse patterns;
- legal requirements;
- security threats;
- network changes; or
- operational experience.
Material changes will be communicated in accordance with the HelixNodes Terms of Service.
43. Questions
Questions about whether a planned workload is permitted may be directed to:
support@helixnodes.com
Customers with unusual high-volume, security-research, scanning, mail, proxy, or network-testing workloads are encouraged to contact us before deployment.