1. Scope
This policy applies to colocation, dedicated servers and virtual private servers, and to anyone you allow to use them. You are responsible for what your users and your customers do with your service.
2. Content you may not host
- Anything unlawful where the service is located — Hong Kong, Singapore, Japan, Germany or the United States, as applicable.
- Child sexual abuse material. We report this to the authorities and terminate immediately, without refund.
- Material that infringes someone else’s copyright, trademark or other intellectual property.
- Malware, exploit kits, phishing pages, or infrastructure that exists to command and control compromised machines.
3. Network abuse
You may not use our network to attack anyone, ours included. Specifically:
- No denial-of-service traffic of any kind, and no packet flooding, whether aimed at a third party or generated as a test.
- No port scanning, vulnerability scanning or intrusion attempts against systems you do not own and have not been authorised to test in writing.
- No IP or route hijacking, no forged source addresses, and no announcing address space that is not yours.
- No open resolvers, open relays or open proxies that can be used as amplification.
Packet flooding is the single fastest way to damage the hardware you are renting. Where it damages a machine, you pay for the replacement.
4. Email and messaging
- No unsolicited bulk email, and no sending on behalf of anyone who does.
- No harvesting addresses, and no purchased or scraped recipient lists.
- No forged headers or misleading sender information.
5. Cryptocurrency mining
Sustained mining loads are not permitted without our prior written agreement. Mining runs hardware at full load continuously, which shortens its life, and on colocation it draws power you may not have contracted for.
Where mining damages a dedicated server, the replacement is billed to you rather than covered by our 24-hour replacement commitment.
6. Resource use
Virtual private servers run on shared hosts with no overcommit — every vCPU you buy is a real thread. In return, you may not run workloads that deliberately degrade neighbouring instances, and you may not resell your allocation as if it were separate capacity.
Colocation power draw must stay inside what you have contracted. Where a rack repeatedly exceeds it, we will ask you to add a circuit or reduce load.
7. Your own security
Keeping your operating system patched, your credentials secret and your services configured safely is your job, not ours. A compromised machine that is attacking others will be suspended like any other source of abuse, however it was compromised.
8. Reporting abuse
Report abuse to andy@shota.hk. Include logs with timestamps and time zone, and the IP addresses involved. We act on reports 24 hours a day.
9. What happens if you breach this policy
Depending on severity, we may ask you to fix it, filter the traffic, suspend the service, or terminate it. Where the abuse is active and harming others, we suspend first and explain afterwards.
Suspension or termination for breach of this policy does not entitle you to a refund, and does not release you from fees already due, including the cost of any hardware you damaged.
Questions about this document? Email andy@shota.hk.