Acceptable Use Policy
What you may and may not run on G7Cloud, how we handle abuse reports, and what happens if something on the platform breaks these rules.
1. Why this policy exists
This policy forms part of the Terms of Service. It exists so that one customer cannot damage another, cannot damage a third party, and cannot put the platform at risk. It applies to everything you run on G7Cloud and to anything your users or your own customers do on your sites.
We are not in the business of policing lawful content. The rules below are about harm, not taste.
2. What you must not do
Unlawful activity. Anything illegal under UK law, including hosting or distributing child sexual abuse material, content that incites violence or terrorism, or material that infringes another person's intellectual property rights.
Attacking others. Using the platform to launch denial of service attacks, port scans, intrusion attempts, credential stuffing, or any unauthorised access attempt against any system, whether ours or anyone else's.
Malware and deception. Distributing malware, ransomware, or spyware. Operating phishing pages or sites designed to impersonate another organisation to obtain credentials, payment details or personal data.
Spam. Sending unsolicited bulk email, sending to purchased or scraped lists, forging headers or sender addresses, or operating an open relay. Mail you send must comply with the Privacy and Electronic Communications Regulations and the UK GDPR, which in practice means a lawful basis for each recipient and a working unsubscribe.
Cryptocurrency mining, and any other workload whose purpose is to consume compute rather than to serve your site.
Undermining the platform. Attempting to escape your container, access another customer's data, interfere with the security or caching layer, circumvent plan limits, or probe our infrastructure without written authorisation. If you want to security-test your own site, tell us first at security@g7cloud.com and we will agree a window with you.
Misrepresenting your identity to us or to your visitors, and reselling the services as your own without a written reseller or agency arrangement with us.
3. Fair use of resources
Every site runs in its own container with its own allocation, so a busy site is not taking capacity from a neighbour in the way it would on shared hosting. Traffic spikes, launch days and seasonal peaks are normal and expected, and we do not treat them as a problem.
What is not fair use is sustained consumption far beyond the plan you are paying for, or a workload the plan is not sold for: a background job farm, a video transcoding pipeline, a file distribution service, or storage used as an archive rather than to serve a site.
If a site consistently outgrows its plan we will contact you and discuss the right plan for it. We will not silently throttle you, and we will not send a surprise bill for usage you have not agreed to.
4. Your security responsibilities
We secure the platform. You are responsible for what runs on your site: keeping applications, plugins and themes updated where you manage them yourself, using strong credentials, removing code you no longer use, and responding when we tell you a site is compromised.
A compromised site is a risk to its own visitors and to our address reputation, so we treat it seriously and will contact you quickly. We would rather help you clean it than suspend it.
5. How we enforce this
Our default is to contact you and give you a chance to put things right. We escalate only as far as the situation requires.
- We contact you describing the problem and what needs to change, with a reasonable deadline.
- We restrict the specific problem where we can: blocking an abusive endpoint, disabling a compromised script, or rate limiting a single path, rather than taking a site down.
- We suspend the affected site, leaving the rest of your account running.
- We suspend the account, for repeated or serious breaches.
- We terminate, for the most serious breaches or for a persistent pattern.
We will act without prior notice only where a delay would cause real harm: active distribution of malware or child sexual abuse material, an attack in progress from your site, or a legal obligation to act immediately. In that case we will tell you what we did and why as soon as we can.
If you think we have got it wrong, reply and say so. We will look again, and a suspension made in error is lifted immediately at no cost to you.
6. Reporting abuse
To report abuse of a site hosted by us, email abuse@g7cloud.com with the URL, what you observed, and when. We investigate every report from a real person.
To report a security vulnerability in G7Cloud itself, email security@g7cloud.com. We will acknowledge within two working days, keep you updated, and will not pursue anyone who reports a genuine vulnerability in good faith, gives us a reasonable opportunity to fix it before disclosure, and does not access or alter another customer's data in the process.