Acceptable Use Policy
Privacy is for people who have done nothing wrong, and it stays credible only if the people who have done something wrong are shown the door. These are the lines.
Last updated 13 August 2026.
What you must not do
Through this service, you must not:
- Attack anything. No denial of service, no port scanning or vulnerability scanning of systems you do not own, no brute-forcing credentials, no intrusion attempts.
- Distribute malware. No hosting, delivering or controlling malicious software, no botnet command and control, no ransomware infrastructure.
- Touch child sexual abuse material. Possessing, distributing or accessing it ends the account immediately and permanently, and we report it where the law requires.
- Send spam. No unsolicited bulk email or messaging, no operating open relays or proxies on top of ours.
- Commit fraud. No carding, no credential stuffing, no phishing pages, no impersonation for financial gain.
- Harass or threaten people. No stalking, doxxing, or threats of violence.
- Traffic in illegal goods — weapons, controlled substances, stolen data or stolen credentials.
- Infringe copyright at scale. Occasional personal use is between you and the law where you are; running a distribution operation through our servers is not.
- Abuse the infrastructure. No reselling access, no exceeding your plan's device limit, no circumventing rate limits or authentication, no automated mass account creation.
How this is enforced without reading your traffic
We do not inspect the contents of your tunnel and we are not going to start. That is not a loophole — it just means enforcement works from the outside rather than the inside, and it is worth knowing exactly how, because a policy nobody can enforce is decoration.
- We receive abuse reports from the operators of networks our exit addresses talk to, and we act on them.
- We see connection-level signals at an exit — a sudden fan-out to thousands of destinations, sustained SMTP to many hosts, traffic patterns characteristic of a flood — without seeing content.
- We apply protocol-level limits at exits, such as rate-limiting outbound mail, that make some categories of abuse impractical without touching legitimate use.
What we cannot do is tell you which account was responsible after the fact, because we do not keep the record that would say. Enforcement therefore happens while it is happening, and the answer to repeated abuse from a class of traffic is usually a limit for everyone rather than a punishment for one person. We think that is the right trade, and we would rather say so plainly than imply we have a capability we do not.
What we do when we act
Depending on severity we may rate-limit an account, block a specific port or protocol for it, suspend it, or terminate it. For anything short of the most serious categories we try to warn first. For child sexual abuse material, credible threats to life, and active attack infrastructure, we do not warn.
A termination for breach is not refunded. If you think we got it wrong, write to abuse@axonvpn.com and a person will look at it again.
Reporting abuse
If traffic from one of our exit addresses is causing you a problem, write to abuse@axonvpn.com with the address, timestamps with a timezone, and what you saw. We answer abuse reports within one business day, and we will tell you honestly what we were and were not able to do about it.
Security research
Reports of vulnerabilities in our own software and infrastructure are welcome at support@axonvpn.com. Test only against your own account, do not degrade the service for others, do not access anyone else's data, and give us a reasonable window before publishing. We will not pursue research conducted on those terms.
Questions about this policy? Write to abuse@axonvpn.com. We answer every message from a person, usually within two business days.