acceptable use policy
lawful, secure and responsible use of hosted services, accounts, networks, software and APIs.
amber.systems acceptable use policy
Version 2026-08-18 - last updated 18 August 2026
1. Scope
1.1 This Acceptable Use Policy (AUP) applies where a Contract incorporates it and governs use of amber.systems hosting, infrastructure, networks, storage, communications, software, SaaS, APIs, accounts and related services (Services).
1.2 The Customer is responsible for its Authorised Users, integrations and workloads, and for people who access a Service through the Customer’s products or credentials.
1.3 This AUP is intended to prevent harm, not to prohibit legitimate research, interoperability, defensive security, malware analysis, reverse engineering or testing performed with proper authority and proportionate safeguards.
2. General standard
You must not use a Service:
- unlawfully or to facilitate unlawful conduct;
- to infringe another person’s rights;
- in a way intended or reasonably likely to cause material harm to people, systems or networks;
- to mislead people about identity, authority, source or affiliation in a materially harmful way; or
- in breach of a restriction in the applicable Order Form or Service Schedule.
3. Security testing, scanning and research
3.1 You may scan, test, fuzz, reverse engineer, analyse malware, assess security controls and perform similar work where:
- you own or control the target; or
- the person with authority over the target has expressly authorised the activity;
- the activity remains within the authorised scope;
- you use reasonable safeguards to protect third-party data and service availability; and
- the activity complies with applicable law.
3.2 You must not use a Service to access, intercept, scan, exploit, disrupt or test a third party’s system, account, communications or data without sufficient authority.
3.3 Legitimate testing is not prohibited merely because it attempts to bypass authentication, authorisation, rate limits, isolation or another technical control. The relevant boundary is authority, scope, impact and third-party rights.
3.4 Malware, exploit code and offensive tooling may be stored or executed for legitimate research, analysis, testing, education or defensive work where the environment is appropriately isolated and the activity does not affect an unauthorised target.
3.5 You must not operate a botnet, command-and-control system or malware distribution service that controls or harms systems without their owners’ informed permission.
4. Accounts, credentials and access
You must not:
- use credentials, sessions, tokens, keys or accounts that you are not authorised to use;
- attempt to access another customer’s tenant, resources or data without permission;
- sell, publish or distribute stolen credentials or authentication material;
- deliberately circumvent an access restriction imposed specifically on you to prevent material harm or abuse; or
- conceal the source of activity to impersonate another person or evade accountability for harmful conduct.
Using multiple accounts that you control for testing, isolation, development or legitimate business purposes is permitted unless the Order Form states a genuine per-account licensing limit.
5. Network and service integrity
You must not:
- conduct denial-of-service activity or generate traffic intended to materially degrade availability;
- interfere with routing, addressing, name resolution or another person’s network communications without authority;
- operate an open relay, open proxy or publicly accessible recursive resolver where this creates a material abuse risk;
- spoof source information for fraud, evasion or harm;
- evade an agreed resource limit, billing meter or technical restriction in order to obtain unpaid capacity; or
- consume resources at a level that materially affects other customers and is inconsistent with the purchased Service.
Reasonable load testing is permitted against systems you own or have permission to test where the Service and capacity have been agreed for that purpose.
6. Communications and messaging
You must not use a Service to:
- send spam or unsolicited bulk messages contrary to applicable law;
- conduct phishing, credential theft, impersonation, harassment or threats;
- falsify caller identity, sender information or routing data for fraud or harmful deception;
- repeatedly contact a person after a clear and lawful request to stop; or
- operate a messaging campaign without the consents, notices, suppression controls and records required by law.
Transactional, service, security, research and individually relevant business communications are not prohibited merely because the recipient did not initiate the first contact, provided the communication is lawful and not abusive.
7. Content and material
You must not knowingly use a Service to store, process or distribute:
- child sexual abuse material or material whose possession or distribution is unlawful;
- material that unlawfully infringes intellectual property, privacy, confidentiality or data-protection rights;
- fraudulent content or instructions intended to obtain money, credentials or access by deception;
- unlawful threats or targeted harassment; or
- content whose processing is prohibited by a binding court order or competent authority.
We do not make subjective offensiveness a standalone breach. Content is assessed by reference to law, rights, safety and material operational harm.
8. Data protection and surveillance
You must:
- have a lawful basis and required notices for personal-data processing performed through the Services;
- apply appropriate access, retention and security controls;
- obtain required consent or authority before recording, monitoring or intercepting communications; and
- not use the Services for indiscriminate or unlawful surveillance.
High-risk, special-category or criminal-offence data may be used only where the Service is suitable, the Contract permits it and appropriate safeguards are in place.
9. Intellectual property and licensing
You must have rights or permission to use Customer Content and software deployed through the Services.
Open-source use, interoperability, compatibility work, reverse engineering, quotation, research, archiving and other acts permitted by law or licence are not prohibited.
We may ask for reasonable information about authority or licensing where we receive a credible rights complaint, but we do not adjudicate complex ownership disputes without appropriate evidence.
10. Upstream providers
A Service may depend on an infrastructure, telecommunications, payment, model or software provider with mandatory acceptable-use restrictions. You must comply with an upstream restriction that we identify as applicable and reasonably make available, but only to the extent it is relevant to the Service and not inconsistent with mandatory law.
An upstream provider may take independent action. We will use reasonable efforts to communicate the basis and restore service where the issue can be resolved.
11. Investigation and cooperation
11.1 We may investigate a credible report of misuse using proportionate means, including reviewing relevant metadata, logs, configuration, reports and account records.
11.2 We do not undertake a general obligation to monitor Customer Content. We may inspect content where reasonably necessary to respond to an incident, support request, legal obligation or credible abuse report, subject to the Contract and applicable law.
11.3 You must provide reasonable cooperation, preserve relevant evidence and take proportionate corrective action.
11.4 We may share information with an affected provider, rights holder, regulator or authority only where lawful and reasonably necessary. Our privacy notice and DPA govern personal-data handling.
12. Action we may take
Where we reasonably believe a breach has occurred or creates an immediate risk, we may:
- ask you to stop, explain or modify the activity;
- apply a rate limit, network block or temporary restriction;
- quarantine material or isolate an affected workload;
- suspend the affected Service;
- remove or disable access to unlawful material;
- preserve relevant records;
- notify an upstream provider or competent authority where required or reasonably necessary; or
- terminate the affected Contract for a material or repeated breach.
We will, where reasonably possible:
- give notice and an opportunity to respond;
- limit action to the affected Service or material;
- consider legitimate research, public-interest and interoperability context;
- avoid unnecessary access to Customer Content; and
- restore access when the risk is resolved.
Immediate action may be taken for an urgent security risk, ongoing harm, legal requirement or serious abuse.
13. Reports and appeals
Send abuse reports to abuse@amber.systems. Send vulnerabilities in amber.systems systems to security@amber.systems.
A report should identify the affected Service, relevant times, source and destination information, the nature of the concern, and supporting evidence. Do not send unnecessary personal data or sensitive content.
A Customer may ask us to review enforcement action by replying to the notice or contacting abuse@amber.systems. We will consider relevant authority, context, remediation and proportionality.
14. Changes
We may update this AUP under the change mechanism in the General Terms. A change will not retrospectively make previously authorised conduct a breach.