Acceptable Use Policy

We sell machines that run untrusted code, so the boundary of what is acceptable has to be explicit. This policy forms part of the Terms of Service and applies to everything you run on our infrastructure.

Last updated: 22 August 2026

The short version

Use a sandbox as a workspace for your own code, your agents' code and your users' code. Do not use it as a platform for attacking, defrauding or spamming other people, and do not use it as a cheap way to buy raw compute for something unrelated to running and testing code.

Prohibited uses

You must not use a sandbox, or the API around it, to:

Testing your own security tooling against your own systems is fine. Testing it against someone else's is not, regardless of your intent.

What we monitor — and what we do not

We monitor aggregate resource usage per account, sandbox lifecycle events, API error patterns and abuse reports forwarded to us by our infrastructure provider and by third parties. Those signals are how abuse is normally detected: a machine saturating a CPU for hours, a burst of outbound connection attempts, or a complaint naming one of our IP addresses.

We do not routinely inspect the contents of sandboxes. We do not read your files, and we do not scan your workspace as a matter of course. Note, however, what is stated plainly in the privacy policy: the commands you submit and the output they produce are stored in our database, and we will read those records when we are investigating a specific abuse report, a security incident, or a support request you have raised. Where we are legally compelled to preserve or disclose data, we comply.

Reporting abuse

If traffic or content originating from our infrastructure is affecting you, write to abuse@sandbox-as-a-service.com. Include the IP address, timestamps with a time zone, and log excerpts or headers where you have them — that is what lets us map traffic to an account quickly. We treat abuse reports as a priority and will confirm receipt, although we cannot promise a fixed response time.

Vulnerabilities in the service itself belong at security@sandbox-as-a-service.com instead — see the security page for how we handle those.

Consequences

Depending on severity and on whether the behaviour looks deliberate, we may:

For clear-cut cases — active attacks, mining, illegal content — we act first and explain afterwards. For ambiguous cases we will normally contact you at the email address on your account and give you an opportunity to correct the problem. If you believe an enforcement action against your account was a mistake, reply to the notice or write to info@productivity-boost.com; we will look at it again.

Changes

We update this policy as new categories of abuse show up. The version in force is the one published here.