Acceptable Use Policy
Rules governing responsible use of the IOBend platform, developer infrastructure, repositories, APIs and related services.
1.Purpose & Scope
This Acceptable Use Policy ("AUP") sets out the rules governing access to and use of the IOBend Unified Developer Experience Platform, IOBend CLI, developer control planes, devcontainers, APIs, web console, artifact repositories, AI developer assistance tools, and related services (collectively, the "Services") provided by IOBend Technologies Private Limited ("IOBend", "we", "us", or "our").
IOBend is built for legitimate software development, engineering collaboration, infrastructure configuration, container orchestration, dependency management, artifact distribution, and automated developer workflows. This AUP exists to:
- Protect our customers, users, and the developer ecosystem from harm;
- Protect shared cloud infrastructure, compute clusters, and network stability;
- Prevent abusive, fraudulent, or unlawful activities;
- Protect connected third-party systems, repositories, and registries;
- Support legitimate, responsible security research and vulnerability verification; and
- Maintain a reliable, high-performance developer control plane for all engineering teams.
This AUP applies to all individuals, developers, organizations, and automated systems accessing or using our Services.
2.Prohibited Activities
You agree not to use the Services, and shall not permit any user, agent, or third party under your account to use the Services, to engage in or facilitate any of the following prohibited categories of activity:
A. Illegal or Unlawful Activity
Using the Services for any purpose that violates applicable local, state, national, or international laws, regulations, or statutory orders. Users must comply with all applicable laws and regulations governing software development, data privacy, intellectual property, and trade compliance.
B. Malware and Destructive Payloads
Distributing, hosting, transmitting, executing, or operating ransomware, computer viruses, worms, trojan horses, destructive payloads, rootkits, botnet command-and-control (C2) servers, keyloggers, credential-stealing malware, or any software intentionally designed to damage, disrupt, or gain unauthorized access to computer systems. (Note: Legitimate malware analysis, decompilation, and vulnerability remediation conducted within isolated, controlled local environments with explicit authorization that does not harm shared infrastructure or other users is not prohibited).
C. Unauthorized Access & Intrusion
Attempting to gain unauthorized access to, or breach the security of, IOBend systems, servers, networks, developer environments belonging to another customer, another user's account, repositories, private artifact stores, or administrative control planes.
D. Security Boundary & Tenant Isolation Abuse
Circumventing, disabling, or exploiting flaws in authentication, authorization, multi-tenant isolation barriers, container sandbox boundaries, session management, or role-based access controls (RBAC).
E. Denial of Service & Resource Exhaustion
Engaging in distributed denial-of-service (DDoS) attacks, network packet flooding, socket exhaustion, amplification attacks, intentionally overwhelming shared cloud endpoints, or running automated scripts designed to degrade platform responsiveness for other engineering teams.
F. Cryptocurrency Mining & Unauthorized Compute
Utilizing IOBend cloud infrastructure, remote developer containers, build agents, or shared orchestration nodes for cryptocurrency mining, blockchain validation, or running high-intensity compute jobs unrelated to the permitted development and testing purposes of the Services.
G. Piracy & Intellectual Property Abuse
Knowingly storing, distributing, or publishing pirated proprietary software, cracked executables, unauthorized copyrighted source files, stolen trade secrets, or commercial software license keys obtained without legal entitlement.
H. Credential Harvesting & Password Attacks
Conducting credential stuffing, brute-force password spraying against unauthorized endpoints, harvesting third-party API keys or authentication cookies, or publishing stolen credential databases.
I. Spam, Phishing & Malicious Campaigns
Operating bulk unsolicited email relays, deceptive phishing landing pages, credential phishing portals, spoofed authentication pages, or malicious social engineering tools on IOBend-hosted domains or environments.
J. Fraud & Deceptive Identity Use
Creating fraudulent accounts, impersonating another developer, company, or entity without authorization, falsifying repository provenance, or attempting to deceive security verification workflows.
3.Security Testing & Research
As a developer-centric platform, IOBend recognizes the critical value of security research, code analysis, container vulnerability scanning, and diagnostic inspections. We distinguish between authorized security testing and prohibited attacks:
- Inspecting your own code, container base images, and dependencies;
- Running local workstation diagnostics (
iobend doctor); - Scanning applications and APIs that you own or have explicit written authorization to test;
- Conducting controlled internal penetration testing within your own isolated tenant environment in a manner that does not affect shared infrastructure.
- Probing, scanning, or stress-testing IOBend cloud infrastructure without prior authorization;
- Attempting to bypass multi-tenant isolation or access another customer's data;
- Conducting volumetric DDoS tests against IOBend endpoints;
- Exfiltrating, retaining, or publicly disclosing another user's data or secrets.
4.Shared Compute & Fair Use
Shared infrastructure and compute resources may be subject to usage limits, rate limits, concurrency limits, storage limits, or other fair-use controls. IOBend may throttle, restrict, suspend, or otherwise limit activity that materially impacts platform availability, infrastructure stability, or other customers.
Applicable capacity allocations, API allowances, and environment concurrency quotas are documented in our Subscription Plans, Documentation, and applicable Order Forms. Users requiring specialized compute allocations or high-concurrency pipelines should configure appropriate enterprise tier entitlements.
5.API & Automation Rules
When utilizing IOBend REST APIs, webhooks, CLI sync loops, or automated CI/CD integrations, you agree to observe standard API etiquette and automation governance:
- You must not circumvent, tamper with, or evade API rate limits (such as rotating authentication tokens or IP addresses to bypass quotas);
- You must implement exponential backoff and jitter when retrying failed API requests;
- You must not write automated scripts that generate unreasonable request volumes or create runaway recursive synchronization loops;
- You must not use headless automation to scrape private platform interfaces without authorized API credentials.
6.Repositories & Artifacts
IOBend provides artifact registry connectors, project linking, and software metadata management. You must not knowingly use IOBend to store, cache, proxy, or distribute:
- Malicious binaries, compromised npm/pip/maven packages, or weaponized container layers;
- Files containing unencrypted, stolen authentication credentials or exposed private certificates;
- Unlawful or pirated proprietary software archives.
IOBend does not pre-screen every artifact uploaded to customer repositories. However, IOBend may investigate reported or detected violations in accordance with applicable law and its policies.
7.Container & Developer Environments
IOBend orchestrates devcontainers and localized developer runtime environments. When using cloud-managed environments or executing IOBend orchestration scripts:
- Environments must be used solely for development, testing, building, debugging, and maintaining software applications;
- You must not use devcontainer runtimes to run persistent background services unrelated to development (such as hosting public VPNs, proxy networks, or file-sharing relays);
- You must not use environment networking to conduct port scanning, subnet sniffing, or probing of cloud provider metadata services (e.g.,
169.254.169.254).
8.Third-Party Systems & Networks
The Services facilitate integration with external version control platforms (GitHub, GitLab), cloud hosting providers (AWS, GCP, Azure), container registries, and notification channels.
You must not use IOBend integrations to attack, flood, probe, or abuse third-party services. You are solely responsible for ensuring that you hold proper authorization, valid API credentials, and comply with the applicable terms and conditions of each third-party provider you connect to IOBend. IOBend assumes no liability for customer interactions with third-party networks.
9.AI & MCP Workflows
IOBend provides developer assistance, configuration generation, and Model Context Protocol ("MCP") integrations. You agree that you will not use IOBend AI or MCP capabilities to:
- Automate cyberattacks, exploit generation, or malware synthesis;
- Generate deceptive phishing materials or malicious social engineering scripts;
- Bypass security guardrails, access boundaries, or software licensing restrictions;
- Exfiltrate confidential source code or personal data belonging to third parties.
IOBend AI tools provide developer suggestions based on context and prompts. IOBend does not warrant that AI outputs will be error-free or free from security vulnerabilities. Developers remain solely responsible for reviewing and verifying all generated configurations and code before deployment.
10.Privacy & Personal Data
You must not use IOBend to unlawfully collect, harvest, expose, or process personal data in violation of applicable data protection legislation, including India's Digital Personal Data Protection Act, 2023 (DPDP Act) or other applicable global privacy regulations.
Customers are responsible for ensuring that any personal data contained within repository configurations, commit logs, or test fixtures is processed lawfully with necessary consents or legal bases. For details on how IOBend handles personal data, please consult our Privacy Policy.
11.Intellectual Property
You agree not to use the Services to knowingly infringe, misappropriate, or violate the copyright, patent, trademark, trade secret, or other intellectual property rights of any individual or entity.
You are solely responsible for ensuring that all source code, software libraries, dependencies, and container layers managed through IOBend comply with their respective open-source or proprietary licenses. IOBend does not verify or determine third-party licensing compliance for customer codebases.
12.Credentials & Secrets Handling
You must not intentionally store, upload, or inject stolen credentials, unauthorized API tokens, private SSH keys, or certificates belonging to third parties into IOBend environments.
Legitimate secret management workflows—such as injecting your organization's authorized API keys into devcontainers or using encrypted secret synchronization—are expressly permitted and encouraged when managed in accordance with platform security guidelines.
13.Reporting Security Vulnerabilities
We welcome responsible disclosures from security researchers and developers. If you believe you have discovered a potential security vulnerability affecting IOBend infrastructure, APIs, or software components:
Please report the details promptly to our security team at:
Please include technical reproduction steps, affected endpoints, and system logs. To protect other developers, please do not disclose the vulnerability publicly until our engineering team has had reasonable time to investigate and address the report.
14.Monitoring & Enforcement
IOBend reserves the right, at its reasonable discretion and in accordance with applicable law, to monitor platform activity, examine telemetry patterns, and investigate reported violations of this AUP.
If we determine that an account, workspace, or user has violated this AUP, IOBend may take one or more of the following discretionary enforcement actions depending on the severity of the violation:
- Issue a written warning and request immediate remediation;
- Temporarily throttle, rate-limit, or restrict specific API or compute capabilities;
- Revoke active CLI authentication tokens, session cookies, or API keys;
- Temporarily suspend user or organizational access to the Services;
- Permanently terminate the account and associated subscription;
- Remove or restrict access to offending content, artifacts, or repositories;
- Cooperate with competent law enforcement or regulatory authorities where required by applicable law; and
- Take any other protective measures reasonably necessary to safeguard platform infrastructure and other customers.
15.Notice & Review
Where reasonably practicable and legally permissible, IOBend will endeavor to provide advance notice to the primary account administrator prior to taking enforcement action, allowing a reasonable opportunity to cure the violation.
However, in emergency situations—such as active DDoS attacks, critical security breaches, credential theft, or severe infrastructure degradation—IOBend reserves the right to take immediate protective action without prior notice. If you believe your account was restricted in error, you may contact security@iobend.com to request an administrative review.
16.Customer Responsibility
Customers and organizations are directly responsible for all activities conducted under their accounts and workspaces, including actions taken by their employees, contractors, invitees, and automated CI/CD service accounts.
Organizations must maintain appropriate internal administrative controls, enforce the principle of least privilege, promptly revoke credentials of departed team members, and ensure all authorized users adhere strictly to this AUP.
17.No Guarantee of Prevention
IOBend does not guarantee that every prohibited use, abusive request, or malicious script will be detected or prevented. IOBend assumes no duty or obligation to actively police customer source code, local scripts, or developer environments beyond its standard operational, security, and administrative controls.
18.Relationship with Other Agreements
This Acceptable Use Policy is incorporated by reference into the IOBend Terms of Service. Any violation of this AUP constitutes a material breach of the Terms of Service.
Where a customer has executed a separate Enterprise Agreement, Master Subscription Agreement (MSA), or customized Order Form with IOBend, the terms of that executed agreement shall govern the relationship, and where a separately executed agreement expressly conflicts with this AUP, the applicable executed agreement will control to the extent of the conflict.
19.Changes to this Policy
IOBend may update or modify this Acceptable Use Policy from time to time to address emerging security threats, new platform capabilities, or legal requirements.
When updates occur, we will update the "Last Updated" and "Effective Date" at the top of this document. Continued use of the Services following the posting of modifications indicates your agreement to the revised policy.
20.Contact & Abuse Reporting
If you encounter any violation of this Acceptable Use Policy, or wish to report abuse, spam, or security incidents originating from or targeting IOBend Services, please contact our teams immediately:
Governing Entity: IOBend Technologies Private Limited, India.
