Acceptable Use Policy
Rules for acceptable use of the Nubesti platform so security testing stays authorized, lawful, and safe.
Last updated: September 21, 2026
This Acceptable Use Policy (“AUP”) applies to everyone who uses Nubesti websites, accounts, APIs, or security-testing services. It is part of the Terms of Service.
Nubesti is a professional security-testing platform. Use it only for lawful, authorized defensive testing.
1. Authorized targets only
You may test only assets you own or for which you have documented authorization. You must be able to produce that authorization if we ask.
You must not point scans, exploits, credentials, or social-engineering modules at third-party systems, shared infrastructure, or people who have not consented, unless they are explicitly in an approved scope.
2. Prohibited activities
You must not use Nubesti to:
- Conduct unauthorized access, attacks, or surveillance
- Target systems without permission, including customers, partners, or random internet hosts
- Distribute malware, ransomware, or exploit kits except as strictly necessary inside an authorized test and contained environment
- Attack Nubesti infrastructure, other tenants, or our subprocessors
- Interfere with measurements, billing, or abuse-prevention controls
- Mine cryptocurrency, send spam, or operate botnets
- Violate export controls, sanctions, or local computer-crime laws
- Upload unlawful, infringing, or highly regulated data unless a written agreement allows it
- Resell the service or share access except as permitted by your plan
- Reverse engineer the platform except to the limited extent allowed by law
3. Safe testing practices
You agree to:
- Prefer staging or non-production environments when destructive tests are possible
- Set rate limits and exclusion lists that protect availability
- Stop a test if it causes unexpected production impact
- Keep findings confidential except as needed inside your organization or as required by law
- Follow the Rules of Engagement for scoped assessments
4. Credentials and secrets
Do not submit production secrets you are not authorized to share. Rotate any credentials used during a test. Do not use the platform to store payment card data, government ID dumps, or special-category data unless we have agreed in writing.
5. Enforcement
We may investigate suspected AUP violations, preserve logs, suspend accounts, notify affected parties, and cooperate with law enforcement. We may refuse or terminate service where we reasonably believe continued use creates legal or safety risk.
If you discover unauthorized use of your account, email [email protected] immediately.
6. Reporting abuse
Report suspected abuse of Nubesti services to [email protected] or through our Ethics & Reporting channel.
7. Changes
We may update this AUP as threats and product capabilities change. Continued use after the update date means you accept the revised rules.