We host a lot of things. Some things we won't host. This policy is the short list of what falls in the second bucket.

The rule of thumb: don't use Nodara for anything that would get us defederated by IXPs, sued in Delaware or Germany, or that puts other customers at risk. If something isn't explicitly listed below but feels like it might be a problem, ask us — we reply within a business day.

1. What's never okay

  • CSAM. Any material sexually exploiting minors. Zero tolerance, immediate termination, reported to NCMEC / national CSAM hotlines and law enforcement.
  • Malware C2 and phishing infrastructure. Command & control for botnets or ransomware, phishing pages, credential-theft landing pages.
  • Sending unsolicited bulk email. The kind that gets our IP ranges on Spamhaus. Transactional email, opt-in newsletters, and cold outreach at reasonable volume are fine.
  • Denial-of-service origination. You don't launch floods, amplification attacks, or credential-stuffing runs from our network. Load-testing your own infrastructure with reasonable rates is fine (please tell us in advance for anything above 1 Gbps).
  • Unauthorized network scanning. Pentesting your own infra is fine. Sweeping public IPv4 space is not.
  • Content prohibited under Delaware, German, or the customer's local law. This includes terrorism-related content, incitement under German § 130 StGB, and content restricted under specific court orders served on us.
  • Fraudulent commerce. Card-testing, fake-goods stores, money-mule operations.
  • Cryptocurrency mining on shared plans. Fine on dedicated GPU tiers and bare metal. Not okay on Nano / Micro / Standard shared vCPU plans — it degrades everyone else's experience.

2. What's fine, contrary to internet folklore

  • Tor exit relays and I2P nodes, on dedicated plans with the exit-node template. Tell us so we can set the appropriate reverse DNS and abuse contact.
  • VPN services (WireGuard, OpenVPN, IPsec) for your own users. Public VPN businesses need a chat with support first so we can size DDoS protection.
  • Adult content that is legal in the customer's and our jurisdictions, hosted on the appropriate SKU, with age-verification.
  • Media hosting (video, streaming). At scale, budget for the bandwidth — overage is capped at $30/instance/month.
  • Reverse-engineering, security research, CTF infrastructure, red-team C2 emulation for licensed engagements. Please email security@ so we can annotate your account.

3. How we handle abuse reports

  1. Every abuse report goes to a human within 4 hours (median: 40 minutes). No form-letter autoresponders.
  2. For first-time reports on a customer in good standing, you get a 48-hour window to remediate before any action. Repeat offenders and clear-cut violations skip this step.
  3. We never null-route without notifying you first, unless the traffic is actively harming other customers.
  4. Law-enforcement requests: we require a legally binding order from a jurisdiction where we operate. We publish a transparency report every six months.

4. Reporting abuse

See something on Nodara that shouldn't be there? Email abuse@nodara.host. Include the IP, a timestamp, and (if possible) the raw evidence. We reply within 4 hours.