Legal

Acceptable Use Policy

What may and may not run on our servers, in our racks and across our network.

Last updated: 9 September 2026

1. Scope

This Acceptable Use Policy applies to every service we provide, to all address space announced by AS208949, and to everyone who uses your service — your staff, your customers and any automated system you run.

It forms part of the Terms of Service. You are responsible for the behaviour of anyone using your service, including resellers and end users, and for enforcing equivalent rules on them.

2. Prohibited content

  • Child sexual abuse material — reported to the authorities and terminated immediately, without notice or refund.
  • Content that incites terrorism, genocide or violence against people or groups.
  • Material that infringes copyright, trademarks or other intellectual property rights, including sites whose main purpose is distributing infringing files.
  • Fraudulent content: phishing pages, fake shops, fake support sites, counterfeit goods and investment scams.
  • Malware, ransomware, exploit kits, credential stealers and command-and-control infrastructure.
  • Content that is illegal in the country where the service is hosted.

3. Prohibited activity

  • Attacking, scanning, brute-forcing or attempting to gain unauthorised access to any system, ours or anyone else's.
  • Launching or commissioning denial-of-service attacks, including operating booter or stresser services.
  • Operating open resolvers, open relays, open proxies or any service that can be abused for reflection or amplification.
  • ARP or route poisoning, and announcing address space you are not authorised to announce.
  • Sending unsolicited bulk email, running snowshoe or list-washing operations, or hosting infrastructure that supports spam sent elsewhere.
  • Circumventing bandwidth, power or resource limits, or interfering with other customers' services.
  • Using a service for cryptocurrency mining where your order does not permit it, or exceeding the power committed for your rack.

4. Email rules

Outbound mail must be sent only to recipients who have opted in, must include a working unsubscribe mechanism, and must use accurate headers and a real return path.

You must publish valid SPF, DKIM and DMARC records for any domain you send from, and keep bounce and complaint rates within accepted industry norms.

Outbound port 25 may be closed by default and opened on request once you describe your sending practice. Repeated blocklistings of your IP addresses may result in the port being closed again.

5. Network conduct

Your service must not degrade the network for anyone else. Traffic that saturates a shared uplink, generates excessive packet rates or triggers upstream filtering may be rate-limited or blackholed while we contact you.

If your IP addresses attract a volumetric attack that exceeds our contracted mitigation capacity, we may null-route the targeted address to protect other customers. We will restore it as soon as it is safe.

Security scanning of third-party networks is only allowed with written authorisation from the target, which you must be able to produce on request.

6. Authorised testing and IP spoofing

We recognise that legitimate security research, training, education and internal lab work sometimes require the controlled use of techniques that are otherwise restricted. IP spoofing is therefore permitted within a dedicated, self-contained lab or test environment that you own or control, for the purpose of testing, teaching and learning.

Such use must be confined to address space and systems you are authorised to operate. Spoofed traffic must not leave your lab or reach any third party, and you must be able to demonstrate on request that the traffic could not affect other customers, our network or the wider internet.

Permission covers research and education only. It does not extend to evading blocking, concealing the source of an attack, interfering with another service, or any activity whose purpose is to deceive, harm or gain unauthorised access.

If you are unsure whether your planned test qualifies, contact us at abuse@hbing.uk before you begin.

  • Allowed: IP spoofing within an isolated lab you control, for security testing, coursework and education.
  • Not allowed: spoofing directed at third parties, at our network, or to mask attacks.
  • Not allowed: DDoS attacks of any kind, volumetric floods, booter or stresser services, or participation in distributed attacks.

7. IP addresses and reputation

IP addresses are assigned for the purpose stated on your order. Reassigning them to unrelated third parties, reselling them, or using them in a way that harms the reputation of our address space is prohibited.

You must keep accurate contact and, where required, reassignment records for space delegated to you, and respond to registry requests about it.

We may renumber a service, with reasonable notice, where address reputation, registry policy or an operational need requires it.

8. Colocation and facility rules

  • Only pre-authorised people may enter the facility, and only during arranged windows.
  • Equipment must stay within its allocated rack space, power draw and cooling envelope.
  • No modification of shared infrastructure — power distribution, cabling paths, cross-connects or cooling — without our written approval.
  • No photography of other customers' equipment, and no interference with any equipment that is not yours.
  • Hazardous materials, unsafe or non-compliant equipment, and unlabelled hardware may be refused or removed.

9. Reporting abuse

Send abuse reports to abuse@hbing.uk. Include the offending IP address or URL, timestamps with the time zone, and log extracts or headers showing the behaviour. Reports without evidence cannot be actioned.

We acknowledge reports and pass them to the customer responsible with a deadline for response. We do not disclose customer identities to reporters; law enforcement requests must come through the correct legal channel.

We acknowledge abuse reports within 24 hours and aim to resolve or escalate within 72 hours; reports involving active attacks or illegal content are handled immediately. Law enforcement requests should be sent to legal@hbing.uk and to our registered office at 124 City Road, London, United Kingdom, EC1V 2NX.

10. Enforcement

Our response is proportionate to the harm. Minor or first-time issues normally get a notice and a deadline to fix. Serious issues result in immediate suspension.

The following are grounds for immediate termination without notice or refund: child sexual abuse material, active attacks on other networks, and anything that puts the facility, our address space or other customers at serious risk.

Suspension for abuse does not stop billing, and time lost to a suspension is not credited.

Repeated breaches, even minor ones, are treated as a serious breach of the Terms of Service.

  • Notice — you are told what happened and given a deadline to fix it.
  • Filtering or rate-limiting — traffic is limited while the issue is investigated.
  • Suspension — the service is powered off or disconnected from the network.
  • Termination — the service ends and data is deleted after the grace period in the Terms.

11. Appeals and contact

If you believe an enforcement action was wrong, reply to the abuse notice or email legal@hbing.uk with an explanation and any evidence. We review appeals and restore service where the action was mistaken.

We may update this policy as attack patterns and legal duties change. Material changes are announced by email and in the portal.

This policy exists to keep the network usable for everyone. If you are unsure whether something you plan to run is allowed, ask us at legal@hbing.uk before you deploy it.