Acceptable Use Policy

Applies to anything published through Kaja's gateway — that is, any hostname we route traffic to on your behalf.

What Kaja is, in this context

We route to your content. We do not host it. Your applications run on machines you own, in clusters we have no login to. When you publish a hostname, our gateway forwards traffic to an agent you installed, which forwards it to your own server.

That has a specific consequence for abuse reports, and it is the reason this page exists. Our maximum technical remedy is to stop publishing a hostname. We cannot delete a file, take a page down, edit content, or preserve evidence that the operator removes — none of it is ours to reach. If content must actually be removed rather than made unreachable through us, the party who can do that is the operator, and after us the hosting provider or network that the machine sits on.

What you may not publish

You may not use a Kaja-published hostname to serve or facilitate:

  • Phishing and impersonation. Pages designed to collect credentials or payment details by imitating another organisation, or content passing itself off as someone it is not.
  • Malware distribution and command-and-control. Serving malicious executables, exploit kits, or acting as a control channel for compromised machines.
  • Attacking other systems. Using a published hostname to launch denial-of-service traffic, scan, brute-force, or otherwise interfere with infrastructure you do not own.
  • Child sexual abuse material. Reported to the relevant authorities and terminated immediately, with no notice period and no appeal.
  • Content that is illegal where it is served. Including material that infringes copyright, and content prohibited by the law applying to you or to us.
  • Evading enforcement. Re-publishing content we have stopped routing, under a new hostname, a new organisation, or a new account.

This applies to what you serve and to what you knowingly let others serve through you. Running a platform for your own users does not transfer the obligation, though it does change what a reasonable response looks like — see below.

Reporting abuse

Email abuse@kaja.dev. This address is monitored, and it is the fastest route to someone who can act.

A report is most useful when it includes:

  • the exact hostname and URL
  • what the content is doing, and when you observed it
  • anything time-sensitive we should know — an active phishing campaign is not the same as a stale listing

What we undertake: we acknowledge within one business day and tell you what we did. Where the law allows us to say so, we will tell you the outcome rather than only that the report was received.

How we respond

Proportionately, and usually starting with the operator — most abuse is a compromised application rather than a malicious customer, and cutting a hostname takes down a business that is itself a victim.

  1. We contact the operator with the report and a deadline to act.
  2. We stop publishing the hostname if they do not, or cannot be reached. Only that hostname — their other hostnames keep serving.
  3. We stop publishing everything for that account where the abuse is deliberate, repeated, or spans hostnames.
  4. We terminate the account.

We skip straight to the last steps for child sexual abuse material, active malware distribution, and attacks in progress. Nothing here obliges us to wait when waiting causes harm.

Stopping publication does not stop your application running. It stops us routing to it — your workloads keep running on your own hardware, and anything else you reach them by is unaffected.

If we act against you

We will tell you what was reported and what we did, unless the law prevents it. If you believe we got it wrong, reply to that message — a hostname we stopped publishing can be restored, and an account we suspended can be reinstated. We would rather be corrected than be right by default.

Related

This policy sits alongside our Terms of Service, Privacy Policy and security overview. Security vulnerabilities in Kaja itself go to security@kaja.dev, not to the abuse address.