Keelson

Acceptable Use Policy (AUP)

Last updated: September 7, 2026

Provider: Strictus GK, trading as “Keelson” (hereinafter referred to as the “Company”).

This Acceptable Use Policy (this “AUP”) sets forth the prohibited uses and the enforcement rights that apply to every User of the service “Keelson” (the “Service”). This AUP constitutes a Supplemental Policy to the Keelson Terms of Service (specifically Article 11, “Prohibited Acts”) and forms an integral part of the Terms. Where a conflict arises between the Terms of Service and this AUP, the more restrictive provision prevails.

This AUP defines the minimum baseline the Company considers necessary to preserve the safety, reliability, and coexistence with third parties of the Service, and to allow the Company to suspend or remove abuse patterns that cannot be adequately addressed by technical design alone on a contractual basis.

Note on authoritative language. These Terms are executed in Japanese, and the Japanese-language AUP constitutes the authoritative text. This English version is provided for reference only; in the event of any discrepancy, the Japanese text prevails (see Terms of Service, Article 27).

1. Definitions

Capitalized terms not defined in this AUP have the meanings given to them in the Terms of Service.

  • “User Application”: an application deployed to and running on the Service by a User. Any communication or processing performed by such application is deemed to be under the User’s control.
  • “Keelson Infrastructure”: the control-plane API, authentication gateway, edge, shared networks, shared cloud accounts, shared domains (including *.keelson.run), shared CI/CD infrastructure, shared secrets management systems, and any other shared infrastructure operated by the Company to provide the Service.

2. Prohibited Uses

The User shall not engage, directly or indirectly, manually or through automation, in any of the following acts or acts that are likely to constitute the following, when using the Service.

2.1 Security testing, vulnerability research, and intrusion

  • Without the Company’s prior written authorization (including participation in any bug bounty or similar program that the Company expressly establishes), performing vulnerability scans, port scans, penetration tests, fuzzing, brute-force attempts against authentication mechanisms, or any other form of security research targeting the Keelson Infrastructure, other Users’ applications, or third-party services on which the Service depends.
  • Attempting to escape the sandbox (container escape), elevate privileges, or cross Workspace isolation boundaries.
  • Bypassing, disabling, or spoofing security mechanisms implemented by the Company, including authentication, rate limits, WAF, isolation boundaries, region boundaries, and audit logs.
  • Interfering with the Company’s monitoring, including through detection evasion (throttling, source distribution, user-agent spoofing, etc.).

Note: Diagnosing vulnerabilities in the User’s own application is not, by itself, prohibited; however, any such diagnosis that affects the Keelson Infrastructure, other Workspaces, or third parties falls within this section. Research conducted under the terms of any bug bounty or similar program that the Company establishes is permitted within the scope of that program.

2.2 Resource abuse, mining, and anonymization

  • Cryptocurrency mining, participation in mining pools, provision of mining compute resources, staking, and any other use of compute, bandwidth, or storage resources that departs from the intended use of the Service.
  • Free-riding on distributed compute, using the Service as a general-purpose load-balancing tier, or offloading the compute of other services onto Keelson.
  • Operating Tor exit nodes, open proxies, public VPN relay servers, open DNS resolvers, open mail relays, or any other anonymization or relay service on the Service.

2.3 Spam, unsolicited communications, phishing, and malware

  • Sending bulk email, SMS, messages, push notifications, webhook calls, or similar communications without the recipient’s consent.
  • Distributing phishing content, hosting phishing sites, or presenting forms intended to harvest credentials by deception.
  • Distributing, hosting, or executing malware, ransomware, spyware, keyloggers, botnet command-and-control, or any other malicious software.
  • SEO spam, fake review or fake account generation, CAPTCHA-solving services, and any other automation that degrades trust and safety.

2.4 Origination of attacks

  • Using the Service as an origin for DoS or DDoS attacks, amplification attacks, reflection attacks, UDP floods, or any other form of deliberate overload directed at third parties.
  • Port scanning, brute-force attempts against network services, credential stuffing, or credential-reuse verification.
  • Unauthorized access or attempted unauthorized access to third-party systems, privilege takeover, or use of the Service as a pivot for data exfiltration.
  • Outbound communication that damages IP reputation, including sustained communication with known-malicious destinations, command-and-control servers, or malware distribution infrastructure.

2.5 Illegal content and third-party rights infringement

  • Distributing, storing, or processing content that violates applicable law, including but not limited to illegal drugs, illegal gambling, child sexual abuse material (CSAM), and content that incites or facilitates terrorism.
  • Content that infringes third-party intellectual property, privacy, publicity, honor, or other rights.
  • Non-consensual collection or publication of personal information (doxxing), facilitation of stalking, and content whose purpose is discrimination or harassment.
  • Use that violates export control laws or sanctions programs of Japan, the United States, or any other applicable jurisdiction.

2.6 Fraud, financial crime, and misrepresentation

  • Hosting pyramid schemes, Ponzi schemes, or any other fraudulent scheme.
  • Using the Service in a manner that misleads the Company or third parties, including through false registration information, fraudulent use of payment instruments, and chargeback abuse.
  • Facilitating money laundering, terrorist financing, or sanctions evasion.

2.7 Attacks on and disruption of the Service and platform infrastructure

  • Deliberately disrupting the normal operation of the Keelson Infrastructure, including bulk requests intended to cause overload, probing intended to reverse-engineer internal APIs, and exploratory traffic against the control plane.
  • Damaging the reputation of shared domains assigned to the Service (including *.keelson.run) — including use that causes the shared domain to be subject, in whole or in part, to blocklists, browser warnings, or upstream provider sanctions as a result of phishing, spam, or malware hosting.
  • Damaging the reputation of shared IP ranges, shared cloud accounts, shared build infrastructure, or shared domains assigned to the Service.

3. Scope of Responsibility

The User is responsible for all of the following:

  1. The overall behavior of the User Application. All communication, processing, and data storage performed by the User Application is deemed to be the User’s act, regardless of whether it was initiated by the User itself, its employees, contractors, or end users of the User Application.
  2. Unsolicited communications, attacks, and rights infringement that the User Application directs at third parties.
  3. Violations of this AUP that use the User Application as a pivot, including account takeover, credential leakage, and compromise via vulnerabilities in dependency libraries.
  4. The legality of the data handled by the User Application and the acquisition of any necessary consents and licenses.

The User shall properly manage credentials such as IDs, API keys, and access tokens relating to the use of the Service, and remains responsible for AUP violations that occur as a result of unauthorized use of such credentials by third parties.

4. Reporting

Third parties may report events that give rise to a reasonable suspicion of a violation of this AUP on the Service to abuse@keelson.dev. Reports should include, to the extent possible, the target URL, screenshots, timestamps, observed behavior, and any other information reasonably necessary for the Company’s investigation.

The User shall immediately notify the Company if it becomes aware of a suspected AUP violation relating to its account, and shall reasonably cooperate with the Company’s investigation.

5. Enforcement

5.1 Company Discretion

If the Company determines, in its reasonable judgment, that the User has violated or is reasonably suspected of violating any provision of this AUP, the Company may take the following measures, without prior notice or demand, in any order, individually or in combination:

  1. Temporary or permanent suspension of the affected User Application, cron, background workloads, and egress.
  2. Temporary or permanent suspension of the affected account, Workspace, or all applications tied to such Workspace.
  3. Removal or unpublication of the affected deployment, build, revision, or content in distribution.
  4. Immediate revocation of API keys, access tokens, database credentials, and other credentials associated with the affected account.
  5. Permanent termination of the affected account, Workspace, and Service Agreement, and, at the Company’s discretion, refusal to re-register or re-contract.
  6. Refusal of future new registration by the same principal or related principals, based on identifiers held by the Company (including email address, payment instrument, IP, device fingerprint, and business entity information).
  7. Provision of records related to the AUP violation to law enforcement, regulatory authorities, the Company’s legal counsel, affected third parties, and upstream providers (cloud providers, registries, CAs, blocklist operators, etc.) to the extent necessary to maintain the reputation of shared infrastructure and shared domains.

5.2 Emergency Response

The Company may take the measures described in the preceding paragraph prior to completing its usual investigation procedures if any of the following applies:

  • Continuation would cause or expand concrete harm to third parties.
  • The overall operation of the Service, the reputation of shared domains, or other Users is being affected, or there is imminent risk of such an effect.
  • The Company is required to respond under applicable law, order of a judicial or administrative authority, or the terms of an upstream provider.

5.3 Disclaimer Regarding Enforcement Measures

The measures described above are rights, not obligations, of the Company. Except in cases of the Company’s willful misconduct or gross negligence, the Company shall not be liable for any loss of business opportunity, lost profits, data loss, or any other damages incurred by the User as a result of measures taken under this Article. The cap on liability shall be as set forth in Article 15 (Limitation of Liability) of the Terms of Service.

The Company’s failure to take action against a particular AUP violation, or against similar violations in the past, shall not be construed as a waiver of the Company’s right to take action against future violations.

5.4 Handling of Data

When terminating an account for an AUP violation, the Company may delete the User Data associated with such account in accordance with Article 20 of the Terms of Service, except where retention is required by law or is reasonably necessary for investigation, dispute resolution, or law enforcement cooperation. The opportunity to export data is provided to the extent the Company reasonably determines appropriate in light of the nature and urgency of the violation.

6. Changes

The Company may amend this AUP in light of operational realities of the Service, threat environment, laws and regulations, or changes to the terms of upstream providers. Amendments will be publicized and take effect in accordance with the method set forth in Article 22 (Changes to Terms) of the Terms of Service.

7. Contact

  • Abuse reports: abuse@keelson.dev
  • Security reports: security@keelson.dev
  • General inquiries: via the Service’s contact page

End