Acceptable Use Policy
Last updated: 20 August 2026
The one rule that matters: only attack targets we provide, or systems you personally own or have explicit written permission to test. Everything else follows from that.
Allowed
- Learning and practising ethical hacking against the isolated targets we provide.
- Running tools, writing scripts, and experimenting inside your own sandbox.
- Authorized security testing of systems you own or are contracted to test, where your plan permits external access.
- Capture-the-flag (CTF) and coursework.
Strictly prohibited
- Attacking, scanning, or attempting to access any system you do not own or are not explicitly authorized to test.
- Any denial-of-service, mass-scanning, spam, or phishing directed at third parties.
- Attempting to escape the sandbox, attack the platform, or interfere with other users.
- Storing or distributing malware for real-world deployment, illegal content, or stolen data.
- Cryptocurrency mining or running services for unrelated third parties.
- Any activity that is illegal in your jurisdiction or ours.
Enforcement
Environments are isolated and, by default, cannot reach the public internet. We monitor for abuse. Violations may result in immediate suspension or termination of your account and, where required by law, reporting to the relevant authorities.
Reporting abuse
If you believe the Service is being misused, contact abuse@kali-cloud.example.
By using Kali-Cloud you confirm you understand and accept this policy. Unauthorized access to computer systems is a crime in most countries.