ACCEPTABLE USE

Acceptable use

Short version: store your work, do not use this service to hurt people or their machines, and do not use it to get around another project's stated wishes.

What this covers

These rules apply to everything stored, published, or transmitted through CodeRook, and to how you use the service itself. They apply to public and private projects alike, though what we can see, and therefore what we can act on, differs enormously between the two.

Storing something private that only concerns you is not our business. We are not scanning private projects looking for reasons to act, and most of what follows becomes relevant only when something is published or reported.

Content that is not allowed

  • Material that is unlawful where you are or where we operate, including material that sexualises children.
  • Malware, ransomware, credential stealers, or anything built to run on a machine without its owner's knowledge. Security research, proof-of-concept exploits, and offensive-security tooling are welcome — the line is intent and honesty about what a thing is, not the subject matter.
  • Phishing kits, fake sign-in pages, and material designed to impersonate a person or organisation in order to deceive.
  • Credentials, keys, or tokens belonging to someone else, and personal information published to harass or expose a person.
  • Content you do not have the right to publish. You are responsible for having the rights to what you upload and distribute.

Conduct that is not allowed

  • Using the service to attack anybody — as a control server, a staging host for an intrusion, or a source of traffic against someone else.
  • Harassment, threats, or targeting an individual through any part of the service that reaches other people.
  • Deliberately overloading the service, evading request budgets, or spreading activity across accounts to get around a limit rather than asking for a higher one.
  • Circumventing another project's machine access settings — automating past a human verification step, or collecting a project whose owner has declined automated access. Those settings are terms of access, not suggestions.
  • Automating account creation, or using the service through another account to escape a restriction placed on yours.

What is explicitly fine

Worth stating, because policies like this are often read as broader than they are.

  • Projects written with AI tools, in whole or in part. You are never required to say whether AI was involved.
  • Security tooling, exploit code, and research artefacts, published honestly as what they are.
  • Forks, mirrors, and archives you have the rights to keep.
  • Automated clients, within the published request budgets and each project's stated wishes.
  • Large files and unusual formats. That is what the service is for.

What happens if something crosses the line

We aim to use the smallest step that fixes the problem. In most cases that means asking you to change something before anything is restricted.

  • Notice — we tell you what the problem is and give you the chance to resolve it.
  • Restricting one project — its public access is turned off while the question is resolved. You keep your access to it, including the ability to download and delete it.
  • Suspending an account — reserved for serious or repeated cases. You keep the ability to export your projects.
  • Removal — for content that is unlawful or that we are legally required to remove.

We may act immediately and explain afterwards when something is actively harming people or systems — an ongoing attack, malware being served, or material we are obliged to remove on sight. That is the exception, not the normal path.

If you think we got it wrong

You can appeal any restriction by replying to the notice we sent, or by writing to security@coderook.com if you did not receive one. Tell us what you think we misread. A decision made in error will be reversed.

Nothing in this policy removes rights you have under Australian Consumer Law, and we do not treat a restriction as a reason to keep money for a service you can no longer use.

Reporting something

Write to security@coderook.com with a link and a short description of the problem. Reports about security vulnerabilities have their own route — see vulnerability disclosure.