Acceptable Use Policy
Draft pending legal review. Placeholders in [brackets] will be completed before this document takes effect.
Last updated 30 September 2026
This AUP applies to every account on Forge, operated by [BEESWORX LEGAL NAME] (Reg. No. [BEESWORX REGISTRATION NO.]). It is incorporated into the Terms of Service.
1. Prohibited activity
You may not use the Service to:
- Send unsolicited bulk e-mail ("spam"), phish, or impersonate a brand. The Anti-Spam Policy sets out the rules for e-mail sent through the Service. Direct outbound mail from your applications to third-party mail servers on port 25 is blocked at the network layer [OWNER TO CONFIRM THE PORT BLOCK IS ENABLED ON FORGESERVER.APP]: send application mail through the platform's managed e-mail or your own configured provider instead. A platform subdomain (
<name>.<platform domain>) that impersonates a bank, telco, retailer, or generic account or security term (e.g.login,secure,admin,absa,fnb,capitec) is refused at creation time by the platform's reserved and phishing name list. This check applies to the platform subdomain only, not to a custom domain you bring and verify yourself, or to a hostname discovered from your own compose file. Using either to impersonate a brand is still an AUP violation, just not one blocked automatically. - Mine cryptocurrency, or run any workload whose primary purpose is sustained, near-100% CPU utilisation for value extraction rather than serving your application. Where automated mining detection is enabled [OWNER TO CONFIRM ENABLED ON FORGESERVER.APP], a container with a CPU limit that stays at 90% or more of that limit for over 30 continuous minutes is automatically stopped, the stop is audit-logged, and the operator is alerted. You may restart the app; a repeat offence is treated as a suspension-worthy AUP breach. Mining is prohibited whether or not the automated check catches it.
- Attack, scan, or abuse third-party systems from the platform: port-scanning, DDoS, brute-forcing credentials, or exploiting vulnerabilities in systems you do not own or have permission to test.
- Attempt to bypass platform isolation: the org-scoped access controls on the platform's own control-plane data, the network egress boundary (which blocks traffic leaving the host from every tenant container to cloud metadata endpoints and private network ranges), or the sandboxed container runtime (gVisor) that tenant workloads run in.
- Store or process content that is unlawful in South Africa, including child sexual abuse material, content that infringes third-party intellectual property (see the Intellectual Property Guidelines), malware distributed for harm, or content that violates the rights of others under POPIA or any other law.
- Resell or sub-license the Service without a separate written agreement.
- Circumvent quota, billing, or rate limits through automation, multiple accounts, or technical means.
2. Reporting abuse
Anyone (a tenant, a third party, or a member of the public) may report suspected abuse:
- E-mail: [ABUSE CONTACT E-MAIL, e.g. abuse@forgeserver.app].
- In-app: a "Report abuse" link is shown in the dashboard sidebar, on the signup page, and on any suspended-site takedown page once the operator has configured the abuse contact [OWNER TO CONFIRM CONFIGURED ON FORGESERVER.APP].
Reports of intellectual property infringement follow the take-down process in the Intellectual Property Guidelines.
3. Response targets
| Category | Target first response |
|---|---|
| Active phishing, malware distribution, or an imminent security threat | 1 hour, business hours |
| Everything else (spam, ToS/AUP violations, IP complaints, general abuse) | 24 hours |
Business hours are [BUSINESS HOURS / TIMEZONE, e.g. 08:00 to 17:00 SAST, Mon to Fri]. Outside business hours, active phishing or malware is handled on a best-effort basis until the next business-hours window opens.
4. The suspension ladder
Enforcement is graduated and, wherever possible, reversible:
- Warn. For a first, non-critical violation, we notify the org's owners and admins by e-mail and describe the required remediation and deadline.
Suspend. If unresolved, or immediately for severe or active-harm cases (phishing, malware, mining, active attack), the org is suspended by a platform administrator, or automatically for non-payment (see below). This:
- Puts a 503 "This site has been suspended" takedown page in front of every hostname of every web application in the org (not a 451: suspension is ordinarily temporary and reversible, and 451 asserts a legal demand). The takedown page carries a "Report abuse" link when an abuse contact is configured. Identity, feature-flag, and mail-relay hostnames bound to the org are not covered by this takedown and may continue serving.
- Stops the org's application containers, dedicated Redis instances and managed MariaDB databases, and revokes the org's access to the platform's managed e-mail. Shared PostgreSQL databases, directly exposed ports, SFTP, and object storage remain reachable with valid credentials during a suspension: suspension takes web applications offline, it does not firewall all of the org's provisioned data services.
- Refuses new deploys, app starts, and PR previews for the org, and blocks the org's members from its dashboard and API until it is reactivated. (Where the suspension is for non-payment, owners and admins can still reach the billing page to pay.)
- Leaves all data, secrets, and configuration intact, but members cannot access or export it themselves while suspended. A platform administrator can export data or temporarily lift the suspension for remediation on request.
- Non-payment specifically: where the platform's billing integration is configured, suspension for non-payment is automatic, by default 14 days after we first see the account go past due (see the Terms of Service); the org's owners are notified when the past-due period begins and again at suspension. Where billing is not integrated, an operator carries out the same suspension by hand on the same schedule.
- Reactivate. Once the issue is resolved (content removed, payment received, remediation confirmed), the operator reactivates the org: the takedown pages are lifted, apps that were running before suspension are restarted, and member access is restored.
- Delete. Deletion is not automatic by default, including for non-payment: an operator must act, and only where automatic deletion has been separately enabled does automatic deletion follow a further period after suspension (the automated warning before it goes to Beesworx; see the Terms of Service). Deletion tears down every provisioned resource (apps and their volumes, databases, object storage, secrets, and backups, including off-host copies) in sequence and cannot be undone. Content that cannot lawfully be retained (e.g. CSAM) is escalated and removed immediately, ahead of this schedule. Some data may outlive deletion: see the Data Processing Agreement for known gaps (build caches, centrally collected logs, some registry images).
5. Content and account removal
For content-specific complaints (e.g. a single infringing app, not the whole org), the operator may act on a narrower control first (stopping a single app, removing a custom domain, or revoking an exposed port) before suspending the entire org, at their discretion given severity. These narrower actions are reversible by the tenant itself (a member with deploy permission can restart a stopped app; a removed domain can be re-added, though it must be re-verified), so we use them only while the tenant is cooperating and escalate to a full org suspension where they are not.
6. Changes
This AUP may be updated from time to time; see the Terms of Service for how changes are communicated.