1. Purpose
Extent Technologies operates enterprise digital infrastructure used by businesses and organisations. This AUP is intended to protect:
- our customers;
- Internet users;
- our network and IP reputation;
- telecommunications systems;
- our physical data center;
- our employees and contractors;
- upstream and peering partners; and
- the reliability and security of our services.
Customers must use Extent Technologies services lawfully, responsibly and in a manner that does not interfere with other users or networks.
2. Customer Responsibility
Customers are responsible for all activity originating from or conducted through services assigned to them, including activity performed by employees, contractors, administrators, customers, application users, API users, resellers, and other persons given access to the service.
Customers must take reasonable measures to prevent unauthorised use. This includes maintaining secure credentials, applying appropriate security updates, restricting administrative access and responding promptly to compromise or abuse reports.
A customer may not avoid responsibility merely because prohibited activity was performed by an end user or compromised system where the customer fails to take reasonable corrective action after becoming aware of the issue.
3. Compliance with Law
Services must not be used to violate applicable laws or regulations. Customers are responsible for determining whether their particular use of our infrastructure is lawful in every jurisdiction relevant to their activities.
Extent Technologies may restrict, suspend or terminate services where required by a valid legal or regulatory obligation.
4. Prohibited Security Activity
Customers must not use Extent Technologies infrastructure to:
- gain unauthorised access to systems, networks or accounts;
- attempt to bypass authentication or access controls;
- exploit security vulnerabilities without authorisation;
- distribute malware;
- operate botnets;
- deploy ransomware;
- steal credentials;
- conduct phishing attacks;
- intercept communications without lawful authority;
- distribute malicious scripts;
- knowingly host command-and-control infrastructure;
- perform password attacks against systems without authorisation;
- conduct malicious network scanning; or
- intentionally compromise third-party systems.
Legitimate security testing is permitted only against systems that the customer owns or where the customer has explicit authorisation to conduct the testing. Security research must be performed in a manner that does not materially affect other customers or Extent Technologies infrastructure.
5. Network Scanning and Penetration Testing
Authorised vulnerability scanning and penetration testing may be permitted. Customers must ensure that:
- the target systems belong to them or they have written authorisation from the owner;
- testing does not target shared Extent infrastructure;
- testing does not create excessive network load;
- denial-of-service testing is not conducted without prior written approval; and
- testing complies with any service-specific restrictions.
Large-scale penetration testing, stress testing or denial-of-service simulation requires prior coordination with our NOC.
6. Denial-of-Service Activity
Customers must not intentionally initiate, participate in or facilitate:
- denial-of-service attacks;
- distributed denial-of-service attacks;
- amplification attacks;
- reflection attacks;
- packet floods; or
- other activity designed to impair availability of a network or system.
If a customer's service becomes the target of an attack, Extent Technologies may implement filtering, rate limiting, traffic diversion, null routing or temporary suspension where reasonably necessary to protect the network. Such protective action does not constitute a violation of the Service Level Agreement where the relevant SLA exclusion applies.
7. IP Spoofing and Network Manipulation
Customers must not:
- spoof source IP addresses;
- manipulate packet headers for deceptive or malicious purposes;
- impersonate another network;
- announce network prefixes without authorisation;
- hijack routes;
- forge routing information;
- use unauthorised autonomous system numbers; or
- interfere with routing protocols.
Customers using BGP or other routing services must announce only prefixes authorised by Extent Technologies or the applicable resource holder.
8. IP Address Resources
IP addresses supplied by Extent Technologies remain under the administrative control of Extent Technologies or the applicable Internet number-resource provider unless formally transferred through an authorised process.
Customers must maintain responsible use of allocated IP addresses. Activity that materially damages IP reputation may result in investigation, additional verification, outbound filtering, port restriction, IP replacement, suspension, or termination.
Customers may not sell, transfer, sub-allocate or announce Extent Technologies IP resources outside the agreed service without written permission.
9. Email and Anti-Spam Requirements
Extent Technologies maintains strict controls against unsolicited email. Customers must not use our infrastructure to send spam or facilitate spam. This prohibition applies to dedicated email servers, corporate email, cloud servers, bare-metal servers, applications, websites, APIs, and other systems connected to our network.
Bulk or marketing email must be sent only to recipients for whom the sender has an appropriate lawful basis to communicate. Customers conducting legitimate bulk email campaigns should maintain evidence of consent or another lawful basis where required. Marketing communications should include an effective unsubscribe mechanism where applicable.
10. Prohibited Email Practices
Customers must not:
- send unsolicited bulk email;
- send phishing email;
- send fraudulent or deceptive email;
- distribute malware by email;
- use harvested email addresses;
- use unlawfully obtained recipient lists;
- forge sender identities;
- intentionally evade spam filtering;
- operate malicious open relays;
- perform email bombing;
- send messages using misleading routing information; or
- continue sending marketing messages to recipients who have validly opted out where applicable.
Purchased, rented or scraped mailing lists must not be used unless the customer can demonstrate that use of the addresses complies with applicable law and recipient consent requirements.
11. Email Authentication and Reputation
Customers using dedicated email infrastructure may be required to implement appropriate email authentication, including SPF, DKIM, DMARC, PTR/reverse DNS, and other technical controls appropriate to the service.
Customers must reasonably cooperate with measures intended to protect shared network and IP reputation. Extent Technologies may temporarily restrict outbound email where we identify compromised accounts, abnormal sending patterns, phishing, malware, blocklist events or other significant reputation risks.
12. Email Deliverability
Extent Technologies provides infrastructure, configuration and reputation-management services designed to improve email delivery. However, customers acknowledge that final delivery and inbox placement are controlled by independent recipient networks and mailbox providers.
Customers must not use published deliverability statistics as permission to engage in unsolicited messaging. No inbox-placement percentage constitutes a guarantee unless expressly stated in a separate written agreement.
13. Fraud and Deceptive Activity
Services must not be used for financial fraud, payment fraud, identity theft, impersonation, phishing, fake investment schemes, fraudulent e-commerce, credential theft, deceptive technical-support operations, scams, or other intentionally deceptive activity.
We may immediately suspend services associated with credible fraud or phishing incidents where prompt action is required to protect users or infrastructure.
14. Malware
Customers must not knowingly store, distribute, execute or control malware intended to compromise third-party systems. This includes ransomware, trojans, credential stealers, spyware, destructive malware, botnet payloads, malicious browser extensions, and command-and-control software.
This restriction does not prohibit legitimate cybersecurity research involving malware samples where adequate safeguards are in place and Extent Technologies has approved the activity where necessary.
15. Content and Intellectual Property
Customers must not knowingly use our services to distribute content that violates applicable law or infringes enforceable intellectual-property rights. When we receive a sufficiently substantiated complaint, we may contact the customer and request appropriate action.
Extent Technologies does not ordinarily monitor customer content proactively except where necessary for security, technical operation, abuse prevention or legal compliance.
16. Resource Abuse
Customers must use resources within the limits of their purchased service. Customers must not deliberately interfere with the performance of shared infrastructure. Examples may include uncontrolled processes, abusive traffic generation, excessive I/O, unauthorised resource bypass, attempts to escape virtualisation boundaries, deliberate hypervisor interference, or other activity materially affecting neighbouring systems.
Where a workload requires additional resources, we may request migration or upgrade to an appropriate dedicated service tier.
17. Cryptocurrency and High-Density Compute
Cryptocurrency mining, GPU-intensive compute or other unusually high-density workloads must remain within the electrical, thermal and resource limits of the purchased service. Where a service plan specifically prohibits a workload, customers must obtain written permission before operating it. Colocation customers must not exceed contracted rack or circuit power limits.
18. Proxies, VPNs and Relay Services
Customers may operate legitimate VPN, proxy, DNS or relay services where permitted by their service agreement. Such systems must not be operated in a manner that knowingly facilitates abuse, spam, attacks, credential theft, fraud, or concealment of malicious activity. Customers operating publicly accessible services are responsible for implementing reasonable abuse-prevention controls.
19. Telecommunications and IPBX
Customers using IP phone, SIP or IPBX infrastructure must comply with applicable telecommunications requirements. Services must not be used for fraudulent calls, telephone scams, caller-ID manipulation intended to deceive, unlawful robocalling, harassment, unauthorised interception, unlawful call recording, or bypass of applicable carrier or regulatory restrictions.
Customers are responsible for obtaining any consent required for call recording or monitoring.
20. Physical Data Center Conduct
Persons accessing an Extent Technologies data center must comply with facility security procedures. Customers and authorised visitors must not:
- enter restricted areas without permission;
- permit unauthorised persons to enter;
- bypass access-control systems;
- interfere with another customer's equipment;
- photograph restricted infrastructure without permission;
- disconnect network or power systems not assigned to them;
- introduce dangerous or prohibited materials;
- obstruct cooling or ventilation;
- exceed allocated electrical capacity; or
- interfere with security systems.
Access credentials and facility access rights must not be shared with unauthorised persons.
21. Customer Equipment
Colocation customers are responsible for equipment installed within their allocated space. Equipment must be safe for data-center operation, comply with relevant electrical requirements, be properly installed, remain within agreed power limits, not create excessive heat, not expose dangerous wiring, not interfere with adjacent racks, and not present a fire or safety risk.
Extent Technologies may require removal or shutdown of unsafe equipment.
22. Credentials and Access Security
Customers must take reasonable steps to secure root passwords, administrator accounts, control panels, IPMI/iLO interfaces, SSH keys, API credentials, email credentials, VPN credentials, and other privileged access mechanisms.
Customers should enable multi-factor authentication where supported and appropriate. Credentials known or reasonably suspected to have been compromised should be replaced promptly.
23. Compromised Systems
A compromised server remains subject to this AUP even if the prohibited activity was not intentionally initiated by the customer. Where compromise occurs, we may:
- notify the customer;
- restrict ports;
- temporarily isolate the server;
- null route an affected address;
- block malicious traffic;
- require credential replacement;
- require system remediation; or
- suspend the service where necessary.
Our objective will normally be to contain the incident while allowing the customer a reasonable opportunity to remediate it, unless immediate action is required.
24. Abuse Reports
Abuse reports relating to Extent Technologies infrastructure must be sent directly to:
A useful abuse report should include affected IP address, date and time, timezone, relevant logs, message headers, URLs, screenshots, source and destination information, and a clear description of the incident.
25. Abuse Investigation
Extent Technologies may investigate suspected violations using information reasonably available to us, including network logs, security alerts, abuse complaints, authentication records, traffic metadata, system information, IP reputation information, and information supplied by the customer.
Investigations will be conducted in accordance with applicable law and our Privacy Policy.
26. Enforcement
The action taken depends on the seriousness of the violation, immediate risk, customer history, whether the activity appears intentional, whether a system has been compromised, legal obligations, and the customer's response to previous notices.
Actions may include warnings, remediation requests, port blocking, traffic filtering, outbound email restriction, IP null routing, temporary isolation, service suspension, termination, or reporting to appropriate authorities where required or permitted. We may take immediate action without prior notice where necessary to prevent significant harm, fraud, attack, compromise or legal exposure.
27. Repeated Violations
Repeated violations may result in progressively stronger enforcement. A customer that repeatedly allows compromised systems, spam, phishing, malicious traffic or other abuse to recur without appropriate remediation may be suspended or terminated permanently.
28. Emergency Measures
Extent Technologies may immediately take technically reasonable measures where necessary to protect human safety, the physical facility, customer equipment, network stability, Internet number resources, IP reputation, other customers, or third parties. Emergency protective measures are not intended as punishment and will be removed when the underlying risk has been adequately addressed.
29. Law-Enforcement and Regulatory Requests
Extent Technologies may respond to legally valid requests from courts, law-enforcement agencies and regulatory authorities in accordance with applicable law. Customer information will be handled according to our Privacy Policy.
30. Resellers and Downstream Customers
Customers who resell or provide services to third parties using Extent Technologies infrastructure are responsible for maintaining an acceptable-use policy for their downstream users. The downstream policy must not permit activity prohibited by this AUP. Resellers must maintain a functioning abuse-contact process and reasonably cooperate with Extent Technologies regarding abuse originating from their downstream customers.
31. No Monitoring Obligation
Nothing in this AUP creates a general obligation for Extent Technologies to monitor all customer traffic, communications or content. We may nevertheless use automated or manual security and network-monitoring systems as reasonably necessary for network operation, security, abuse prevention, troubleshooting, legal compliance, and protection of infrastructure.
32. Relationship with the SLA
Suspension, filtering, null routing or other intervention resulting from a customer's violation of this AUP may be excluded from availability calculations under the applicable Service Level Agreement. An AUP violation does not create a right to an SLA credit.
33. Relationship with Refund Policy
Suspension or termination resulting from fraud, unlawful activity, material abuse or a serious violation of this AUP may affect refund eligibility as described in our Refund Policy.
34. Changes to This Policy
Extent Technologies may update this AUP to address changes in technology, security threats, network operations, products, regulations, or industry practices. The current version will be published on our website with its latest revision date.
35. Support and Contact
Existing Customers
Existing customers should create a support ticket through the customer portal for service-related matters.
Non-Customers
Abuse Reports
All security, spam, phishing, malicious traffic and network abuse reports should be sent to:
Assistance & Official Contacts
For questions regarding this policy, service level reviews, billing adjustments, or network abuse reports, please direct your communication through the designated channels:
Spam, phishing, malicious traffic, botnet activity, or copyright infringement originating from Extent Technologies IP allocations:
abuse@extentit.com