Acceptable Use Policy
This Acceptable Use Policy ("AUP") applies to all use of CDN.MN services provided by NicNames, Inc. ("CDN.MN," "NicNames," "we," "us," or "our").
Capitalized terms not defined in this AUP have the meanings stated in the CDN.MN Terms of Service.
You may not use, assist another person to use, or permit the Service to be used for conduct prohibited by this AUP. This AUP applies to human users, Agents, automated clients, Customer Content, Origins, generated hostnames, custom domains, analyzer activity, APIs, MCP operations, CLI activity, and integrations.
1. General rule
You must use CDN.MN lawfully, responsibly, and in a manner that does not:
- harm another person;
- violate third-party rights;
- compromise systems or data;
- interfere with the Service;
- evade limits or security controls;
- expose NicNames or third parties to unreasonable legal, financial, security, reputational, or operational risk; or
- use the Service for a purpose materially different from its documented purpose.
2. Illegal activity
You may not use the Service to:
- violate applicable law, regulation, sanction, court order, or legal restriction;
- facilitate, promote, or conceal criminal activity;
- traffic in stolen goods, unlawfully obtained data, or illegal services;
- facilitate fraud, extortion, bribery, money laundering, or tax evasion;
- impersonate another person or falsely claim authority;
- evade export controls or sanctions; or
- assist another person in prohibited conduct.
3. Intellectual property and unauthorized content
You may not retrieve, transform, cache, reproduce, transmit, or deliver content unless you have the necessary rights and authority.
Prohibited conduct includes:
- copyright infringement;
- trademark infringement;
- unauthorized distribution of software, films, music, books, photographs, streams, or broadcasts;
- unauthorized use of a person's name, likeness, or confidential material;
- counterfeit-goods promotion;
- removal or circumvention of rights-management controls;
- unauthorized mirroring;
- delivery from an Origin you do not control or have permission to use; and
- repeated infringement.
Copyright complaints are handled under the CDN.MN Copyright and DMCA Policy.
4. Child sexual abuse and exploitation
The Service may not be used for:
- child sexual abuse material;
- sexual exploitation of minors;
- grooming;
- trafficking of minors;
- sexualized imagery of minors;
- sexual extortion involving a minor;
- content facilitating abuse or exploitation; or
- attempts to conceal or evade detection of such material.
We may preserve and report apparent child sexual abuse or exploitation material to appropriate authorities or reporting organizations as required or permitted by law.
5. Nonconsensual and exploitative intimate content
The Service may not be used to distribute:
- nonconsensual intimate imagery;
- sexual imagery produced or distributed without authorization;
- sexual extortion material;
- voyeuristic material;
- manipulated intimate imagery presented without consent;
- content facilitating coercion or trafficking; or
- content depicting sexual violence for exploitative purposes.
6. Adult content
Sexually explicit content is not permitted through free previews, free compressor functions, or shared generated *.cdn.mn delivery hostnames.
Lawful adult content may be considered only:
- on a paid plan;
- through a Customer-controlled custom domain;
- after prior written approval from NicNames;
- where every depicted person is an adult and has consented;
- where the Customer maintains legally required age and consent records;
- with legally required age controls, notices, and geographic restrictions; and
- where the content does not involve exploitation, trafficking, coercion, nonconsensual material, or another prohibited category.
NicNames may decline or withdraw approval where the content creates disproportionate legal, infrastructure-provider, payment-provider, security, or operational risk.
7. Malware and harmful code
You may not use the Service to create, host, cache, transform, transmit, conceal, or facilitate:
- malware;
- ransomware;
- spyware;
- credential stealers;
- malicious browser extensions;
- botnet software;
- command-and-control traffic;
- exploit kits;
- destructive payloads;
- unauthorized cryptomining;
- malicious JavaScript, SVG, document, or media content;
- drive-by downloads;
- code designed primarily to evade security controls; or
- software intended to compromise or surveil systems without authorization.
Security research is permitted only where authorized, lawful, nonharmful, and conducted under the CDN.MN Vulnerability Disclosure Policy.
8. Phishing, fraud, and deception
You may not use the Service for:
- phishing;
- credential collection;
- fake login pages;
- fraudulent payment pages;
- deceptive downloads;
- impersonation;
- business-email compromise;
- fraudulent advertising;
- investment or advance-fee scams;
- deceptive subscription enrollment;
- fake customer support; or
- other schemes intended to obtain property, credentials, data, or money through deception.
9. Unauthorized access and security abuse
You may not:
- access an Account, Workspace, Site, Origin, domain, repository, Agent, system, or data without authorization;
- probe, scan, or test a system without permission;
- bypass authentication, authorization, approval gates, rate limits, spending controls, or domain verification;
- exploit a vulnerability;
- interfere with availability;
- conduct denial-of-service activity;
- manipulate DNS or routing without authorization;
- attempt server-side request forgery, DNS rebinding, request smuggling, cache poisoning, or host-header attacks;
- access cloud metadata or internal networks through the Service;
- forge request information;
- interfere with logs or audit trails; or
- conceal prohibited activity.
10. Open-proxy and Origin abuse
You may not use CDN.MN as:
- an open proxy;
- an anonymizing relay;
- a general-purpose scraping relay;
- a method to bypass geographic or access restrictions;
- a way to hide the source of abusive content;
- a way to fetch arbitrary third-party URLs;
- an unauthorized mirror;
- a bandwidth-amplification mechanism; or
- a way to shift abusive traffic or cost to another person.
Origins must be owned, controlled, administered, or authorized by Customer and remain within CDN.MN verification and configuration rules.
11. Spam and abusive communications
You may not use the Service to support:
- unsolicited bulk email or messaging;
- harvested contact lists;
- automated spam;
- spam landing pages;
- deceptive redirects;
- abusive tracking; or
- systems primarily intended to facilitate such activity.
12. Harassment, threats, privacy, and personal data abuse
You may not use the Service to:
- make credible threats;
- coordinate harassment;
- stalk or intimidate;
- dox a person;
- publish sensitive personal information to facilitate harm;
- incite targeted violence or unlawful discrimination;
- distribute stolen personal data;
- expose passwords, authentication tokens, private keys, or financial credentials;
- facilitate identity theft;
- deploy unlawful tracking;
- violate confidentiality duties; or
- process personal information in violation of applicable law.
Do not place secrets or highly sensitive data in public CDN URLs.
13. Violent extremism, terrorism, and dangerous conduct
You may not use the Service to:
- promote, support, or recruit for a designated terrorist organization;
- provide operational assistance for terrorism;
- distribute terrorist propaganda where prohibited;
- credibly threaten violence;
- facilitate targeted violence;
- instruct or coordinate an imminent violent act;
- facilitate illegal weapons trafficking; or
- provide instructions intended to enable imminent serious harm.
News reporting, documentary, research, historical, educational, and counterspeech material may be considered in context and remains subject to law.
14. Regulated and high-risk data or services
Unless NicNames expressly agrees in writing, you may not use the Service to process or deliver:
- protected health information subject to HIPAA;
- full payment-card account data;
- government-classified information;
- defense-controlled technical data;
- biometric templates used for identification;
- authentication secrets;
- data requiring a dedicated regulated environment; or
- other data identified as unsupported in the Documentation.
Customers offering regulated goods or services, including financial, healthcare, gambling, pharmaceutical, alcohol, nicotine, cannabis, weapons, transportation, or age-restricted services, are solely responsible for licensing, notices, geographic controls, and legal compliance.
15. Resource abuse
You may not:
- intentionally submit malformed, adversarial, decompression-bomb, pixel-bomb, parser-bomb, or resource-exhaustion files;
- use files designed to consume disproportionate CPU, memory, storage, or network capacity;
- generate artificial transformations solely to increase cost or degrade service;
- bypass encoded-size, decoded-pixel, frame, dimension, time, request, or transformation limits;
- create excessive variants to exhaust cache or storage;
- perform abusive purge loops;
- create traffic with no legitimate service purpose;
- perform benchmarks that harm availability;
- resell free or promotional capacity; or
- consume resources in a manner materially disproportionate to the applicable plan.
We may rate-limit, reject, quarantine, suspend, or charge for usage according to the applicable plan.
16. Credit, billing, and Account abuse
You may not:
- create multiple Accounts or Workspaces to obtain repeated credits;
- use false, disposable, stolen, or misleading identity or payment information;
- coordinate credit farming;
- transfer or resell promotional credit;
- create sham Origins or Workspaces;
- use compromised payment methods;
- manipulate metering;
- fraudulently dispute legitimate charges;
- evade plan limits;
- share service entitlements to avoid fees; or
- interfere with billing or fraud controls.
We may combine technical, billing, domain, organization, device, network, and other reasonable signals to identify related Accounts and reverse or withhold abusive credit.
17. Agent and automation abuse
Agents and automated clients may not:
- misrepresent their identity, provider, user, or authority;
- request scopes unrelated to the stated task;
- conceal requested permissions or billing effects;
- bypass user-claim or approval steps;
- reuse a user code, device code, identity assertion, or token for an unauthorized purpose;
- use a credential for a different audience, Workspace, Site, or resource;
- continue acting after expiry or revocation;
- create duplicate or conflicting resources intentionally;
- approve restricted operations without the required human decision;
- alter or conceal an audit record;
- deploy to production without required approval;
- modify DNS, billing, Origin, ownership, or deletion settings without the required scope;
- store credentials in source code or public files;
- ignore an applicable repository restriction;
- submit fabricated test or verification results;
- exploit idempotency or concurrency behavior; or
- use CDN.MN tools to compromise another service.
Customer is responsible for Agents Customer authorizes.
18. Misrepresentation and misuse of CDN.MN
You may not:
- imply that NicNames endorses you without permission;
- impersonate CDN.MN or NicNames;
- use CDN.MN branding deceptively;
- falsely state that CDN.MN verifies the legality or accuracy of Customer Content;
- claim that a CDN.MN hostname establishes authenticity;
- obscure required error or security notices;
- reverse engineer protected portions of the Service except where law permits;
- resell or sublicense the Service without authorization; or
- systematically extract nonpublic Service functionality to build a direct competing service.
19. Sanctions and export controls
You may not use, export, reexport, or provide the Service in violation of applicable trade sanctions or export-control laws.
You represent that you are not prohibited from receiving the Service and will not make it available to a prohibited person, entity, destination, or end use.
20. Reporting abuse
Report suspected abuse to:
abuse@cdn.mn
Include where available:
- the affected CDN or custom-domain URL;
- a description of the issue;
- timestamps;
- screenshots or evidence;
- relevant headers or request identifiers;
- the legal or policy basis;
- your contact information; and
- a statement that the report is accurate.
Copyright notices should use subject "DMCA Notice" and comply with the CDN.MN Copyright and DMCA Policy.
Security vulnerabilities should be sent to security@cdn.mn, not the abuse mailbox.
21. Investigations and enforcement
We may investigate suspected violations and may:
- request information;
- preserve relevant records;
- rate-limit activity;
- block requests;
- disable transformations;
- remove or invalidate cached content;
- disable a hostname;
- suspend an Agent or token;
- restrict a Site or Workspace;
- suspend or terminate an Account;
- remove promotional credit;
- require renewed domain verification;
- notify an Origin, domain, repository, payment, or infrastructure provider;
- notify an affected party;
- cooperate with lawful investigations; or
- take other reasonable protective action.
We consider severity, immediacy, legality, harm, intent, recurrence, Customer response, feasibility of narrower action, security risk, and effect on third parties.
We may act immediately and without notice where delay could increase harm, risk, or legal exposure.
22. Appeals
A Customer may appeal an enforcement decision by emailing abuse@cdn.mn with subject "AUP Appeal" within fourteen days after notice.
Include:
- Account and Workspace;
- affected Site or domain;
- decision being appealed;
- explanation;
- supporting evidence; and
- corrective actions taken.
An appeal does not automatically stay enforcement. We may decline repetitive, abusive, or unsupported appeals.
23. Changes to this AUP
We may update this AUP to address new products, threats, laws, provider requirements, and abuse patterns.
Material changes will be communicated as described in the Terms of Service.
24. Contact
NicNames, Inc. 131 Continental Drive, Suite 301 Newark, Delaware 19713 United States +1 (302) 883-8888
Abuse and policy reports: abuse@cdn.mn Security: security@cdn.mn Privacy: privacy@cdn.mn General support: support@cdn.mn