Acceptable Use Policy.
Last updated: May 2026. This policy defines what you may and may not do with Roost Hosting infrastructure, services, and AI features. It applies to every account and every service.
1. Purpose and scope
This Acceptable Use Policy ("AUP") is incorporated by reference into the Roost Hosting Terms of Service. It applies to all services operated by Roost Hosting LLC ("Roost Hosting"), including VPS hosting, shared cPanel hosting, domain registration, the Roost AI assistant, and the Roost MCP server. It applies to you and to any party you permit to access your account or services.
The purpose of this AUP is to protect the security, reliability, and performance of our infrastructure and the internet at large, to comply with applicable law, and to protect other customers and third parties from harm caused by misuse.
2. Illegal activities
You may not use Roost Hosting services to conduct, facilitate, or enable any activity that violates applicable local, state, federal, or international law, including but not limited to:
- Storing, distributing, or transmitting any material that violates copyright, trademark, trade secret, or other intellectual property rights
- Conducting fraudulent activity, including identity theft, financial fraud, or impersonating another person or organisation
- Violating export control laws or sanctions regulations (OFAC, BIS, EU sanctions lists)
- Operating unlicensed gambling, lottery, or gaming platforms where prohibited by applicable law
- Distributing or facilitating access to controlled substances
- Any activity that constitutes a criminal offence in the jurisdiction where it occurs or where its effects are felt
3. Child sexual abuse material (CSAM)
Hosting, distributing, transmitting, linking to, or in any way facilitating access to child sexual abuse material (CSAM) or any content that sexually exploits minors is strictly prohibited and will result in:
- Immediate account termination without notice or refund
- Mandatory reporting to the National Center for Missing and Exploited Children (NCMEC) CyberTipline
- Reporting to relevant law enforcement agencies including the FBI
- Cooperation with all subsequent investigations
There are no warnings, no appeals, and no exceptions for this category.
4. Network and infrastructure abuse
You may not use Roost Hosting services to conduct or facilitate any of the following:
- Denial-of-service attacks: Launching, directing, or participating in distributed denial-of-service (DDoS) attacks, UDP floods, SYN floods, ICMP floods, amplification attacks, or any form of volumetric or application-layer attack against any system
- Port scanning: Unsolicited or unauthorised scanning of IP ranges, ports, or services belonging to third parties
- IP spoofing: Forging TCP/IP packet headers or source addresses for any purpose
- BGP hijacking: Announcing IP prefixes or ASNs that you do not own or are not authorised to announce
- Network intrusion: Attempting to gain unauthorised access to any system, network, device, or data — including systems you do not own or have explicit written permission to test
- Botnet operation: Operating command-and-control (C2) infrastructure, botnet nodes, zombie networks, or coordinated automated attack infrastructure
- Traffic interception: Eavesdropping, sniffing, or intercepting network traffic not destined for your services
- Open proxies and anonymisation: Operating open proxies, open relays, Tor exit nodes, or anonymisation services used to facilitate prohibited activity described in this AUP
Legitimate penetration testing, security research, and bug bounty work is permitted only on infrastructure you own or have explicit written permission to test. Testing against Roost Hosting infrastructure itself requires prior written approval from security@roosthosting.com.
5. Email abuse and spam
- Unsolicited bulk email (spam): Sending bulk email to recipients who have not explicitly opted in to receive communications from you
- Phishing: Sending emails that impersonate legitimate organisations or individuals to obtain credentials, financial data, or personal information
- Email header forgery: Falsifying sender addresses, reply-to headers, or any email authentication data (SPF, DKIM, DMARC)
- Malicious attachments: Sending emails containing malware, exploit documents, or payloads designed to compromise recipients
- Harvesting: Collecting, scraping, or purchasing email addresses for bulk unsolicited mailing
- Open mail relay: Configuring mail servers to relay email on behalf of unauthenticated third parties
Legitimate transactional and opt-in marketing email is permitted. If your IP addresses are listed on major DNSBLs (Spamhaus, SORBS, etc.) due to your activity, we may suspend your email service until the listings are resolved.
6. Malware and malicious code
You may not host, distribute, or use Roost Hosting services to develop, test, deploy, or propagate:
- Viruses, worms, trojans, ransomware, or spyware
- Exploit kits, vulnerability scanners used offensively, or remote access tools (RATs) without authorisation
- Keyloggers, credential stealers, or browser hijackers
- Cryptojacking scripts that execute mining code in visitors' browsers without their consent
- Phishing pages, credential harvesting pages, or fake login portals
- Drive-by download infrastructure or malvertising chains
Security research involving malware analysis is permitted only in isolated, non-network-accessible environments and only on infrastructure you control. Network-accessible malware infrastructure is never permitted regardless of stated purpose.
7. Cryptocurrency mining
- Shared hosting: Cryptocurrency mining is strictly prohibited on all shared hosting plans. The CPU and I/O load is incompatible with shared infrastructure.
- VPS hosting: Cryptocurrency mining is permitted on VPS plans within your provisioned resource limits. Mining that causes packet loss, network congestion, or excessive load on shared hypervisor resources may result in resource throttling or suspension with notice.
8. Harmful and objectionable content
Beyond CSAM (section 3), the following categories of content are prohibited:
- Content that incites violence against specific individuals or groups based on race, ethnicity, religion, gender, sexual orientation, disability, or nationality
- Non-consensual intimate imagery (NCII), including "deepfake" content produced without the subject's consent
- Content designed to harass, stalk, or intimidate a specific individual
- Doxing — publishing private personal information about individuals without their consent with intent to harm
We do not proactively monitor customer content. We respond to valid abuse reports and legal orders. We are not a general-purpose arbiter of lawful speech; restrictions in this section target content that causes direct harm to identifiable people.
9. Domain abuse
Domains registered or managed through Roost Hosting may not be used for:
- Cybersquatting: Registering domain names identical or confusingly similar to existing trademarks with intent to profit or disrupt the trademark holder's business
- Typosquatting: Registering misspellings of well-known domains to intercept user traffic
- Phishing infrastructure: Registering domains designed to impersonate legitimate organisations for credential theft or fraud
- Malware distribution: Using domains as command-and-control, payload delivery, or malware distribution infrastructure
- Spam domains: Domains registered solely for bulk unsolicited email campaigns
We will suspend and/or transfer domains that violate this section in response to valid UDRP decisions, ICANN policy enforcement, or court orders.
10. Roost AI — prohibited uses
The Roost AI assistant may not be used to:
- Prompt injection attacks: Attempting to override the AI's system instructions, inject malicious prompts, or manipulate the AI into performing actions outside its intended scope
- Cross-account probing: Attempting to use the AI to retrieve information about other customers' infrastructure, accounts, or data
- Policy circumvention: Using the AI to generate content, code, or instructions that would otherwise violate this AUP or Anthropic's Acceptable Use Policy — including malware code, exploit payloads, phishing templates, or harmful content
- Automated scraping: Driving the AI assistant programmatically at scale to scrape, enumerate, or harvest data from Roost Hosting systems beyond what a human user would access in normal use
- Sensitive data input: Inputting passwords, private keys, government-issued ID numbers, payment card numbers, or third-party personal data into the AI chat
- Deceptive use: Using AI-generated content to impersonate Roost Hosting staff or support in communications with third parties
AI responses are provided as-is and do not constitute professional advice. We are not liable for consequences of acting on AI output. You are responsible for reviewing all AI-generated commands and configurations before executing them.
11. MCP server — prohibited uses
The Roost MCP server may not be used to:
- Token sharing: Distributing MCP bearer tokens to unauthorised parties, committing them to public repositories, or embedding them in client-side code accessible to end users
- Privilege escalation: Attempting to use MCP requests to access data or perform actions beyond the scope your token was issued for
- Infrastructure enumeration: Using the MCP interface to systematically enumerate or probe Roost Hosting's internal systems, other customers' data, or network topology beyond your own account scope
- Automated exfiltration: Using the MCP interface to bulk-export account data at rates or volumes inconsistent with normal use, or to build external mirrors of your account data without Roost Hosting's written consent
- Unapproved write automation: Using MCP write capabilities (where enabled) to automate infrastructure changes at scale without human oversight, particularly actions that could cause data loss or service disruption
You are responsible for all actions taken via your MCP tokens, whether taken by you directly or by a third-party MCP client you have authorised. Revoke tokens immediately if you suspect compromise.
12. Resource abuse
On shared hosting plans, you may not consume resources (CPU, RAM, I/O, inodes, connections) in a way that materially degrades service for other customers. Specific limits are defined in your plan description. Sustained resource abuse may result in process termination, throttling, or plan upgrade requirements.
On VPS plans, you are allocated dedicated resources and may use them freely within your plan limits. Activity that impacts shared hypervisor resources (e.g., excessive network broadcast traffic, storage I/O storms) may be throttled with notice.
13. Reporting abuse
To report abuse originating from Roost Hosting infrastructure:
- Email: abuse@roosthosting.com
- CSAM reports: Submit directly to NCMEC CyberTipline and copy abuse@roosthosting.com
- Copyright / DMCA: dmca@roosthosting.com
- Security vulnerabilities: security@roosthosting.com
Please include: the offending IP address or domain, a description of the activity, timestamps (with timezone), and any supporting logs or screenshots. We investigate all credible reports.
14. Enforcement
When we determine (at our sole reasonable discretion) that a violation of this AUP has occurred or is imminent, we may take one or more of the following actions depending on the nature and severity of the violation:
- Warning: Written notice requiring remediation within a specified timeframe (used for first-time, non-critical violations)
- Traffic filtering or rate-limiting: Blocking specific traffic types or ports without suspending the service
- Null-routing: Routing affected IP addresses to null for network-abuse incidents pending investigation
- Service suspension: Suspending affected services while preserving data, pending investigation or remediation
- Account termination: Permanent termination of the account and all associated services, with or without refund depending on the nature of the violation
- Legal referral: Referral to law enforcement for criminal violations, including cooperation with investigations and legal process
For violations in sections 3 (CSAM), 4 (network abuse directed at third parties), and 6 (malware distribution), suspension or termination may occur immediately without prior warning. For all other violations we will provide reasonable notice and an opportunity to remediate where doing so does not endanger other customers or the integrity of our network.
15. Appeals
If you believe your account was suspended or terminated in error, you may appeal by emailing appeals@roosthosting.com within 14 days of the suspension or termination notice. Include your account details and a clear explanation of why you believe the action was taken in error. We will review and respond within 5 business days.
We are not obligated to restore services pending an appeal. Appeals for violations in section 3 (CSAM) are not accepted.
16. Changes to this policy
We may update this AUP at any time. We will notify registered users of material changes via email at least 14 days before they take effect, except where immediate changes are required to respond to a security incident or legal obligation. The current version is always available at roosthosting.com/aup.
17. Contact
General AUP questions: legal@roosthosting.com
Abuse reports: abuse@roosthosting.com
Roost Hosting LLC