svc.nz
Policies
House rules

Acceptable use

svc.nz stores opaque bytes, but “opaque” does not mean “anything goes.” These rules protect people, rights, infrastructure, and the tiny private trial running underneath it.

Effective and last updated 28 August 2026
Content

Have the right to store it

No illegal, exploitative, privacy-violating, infringing, or deliberately harmful material.

Systems

Do not turn bytes into harm

No malware delivery, phishing, credential theft, spam, denial of service, or unauthorised access.

Load

Respect the small service

No quota evasion, abusive automation, resource mining, or traffic designed to degrade availability.

On this page
  1. Who must comply
  2. Content rules
  3. Security abuse
  4. Platform abuse
  5. Sensitive uses
  6. Capability hygiene
  7. Enforcement
  8. Report a problem

1. Who must comply

This policy applies to everyone who accesses the hosted svc.nz service, including anyone who uploads or retrieves content, holds or passes on a capability, controls an account key, configures a webhook, or builds another service on top of svc.nz.

You are responsible for use made through credentials you control and for reasonable steps to prevent misuse by your users or recipients. This policy forms part of the Terms of Service.

2. Content that does not belong here

Do not upload, store, request, or distribute content that:

  • is illegal, facilitates illegal activity, or breaches a court or regulatory order;
  • sexually exploits or abuses a child, depicts such abuse, or grooms or endangers a child;
  • is non-consensual intimate material, voyeuristic material, or sexual content published without the subject’s permission;
  • threatens, stalks, harasses, defames, doxxes, blackmails, or is intended to cause serious emotional harm;
  • infringes copyright, trade marks, trade secrets, privacy, publicity, confidentiality, or other rights;
  • fraudulently impersonates another person or organisation, or materially misrepresents its source;
  • contains unlawfully obtained personal, financial, health, authentication, or confidential information; or
  • promotes or materially enables violence, exploitation, trafficking, terrorism, or other serious wrongdoing.

Context matters. Legitimate security research, journalism, archival work, and defensive tools are not prohibited merely because they discuss harmful behaviour, but you must have authority, minimise risk, and comply with law.

3. Cybersecurity abuse

Do not use svc.nz to:

  • host, stage, command, distribute, or update malware, ransomware, botnets, spyware, credential stealers, or destructive code;
  • phish, spoof, harvest credentials, intercept secrets, or evade security controls;
  • scan, probe, exploit, access, modify, or disrupt systems or data without clear authorisation;
  • launder or conceal traffic for an attack, or operate as an abusive drop site, proxy, relay, or command-and-control channel;
  • send spam, unsolicited bulk messages, or deceptive communications; or
  • test svc.nz outside the boundaries of the Security Disclosure Policy.

4. Abuse of the service

Do not interfere with svc.nz or other users. That includes:

  • denial-of-service activity or traffic intended to exhaust compute, storage, bandwidth, concurrency, or operator attention;
  • bypassing or attempting to bypass authentication, capability scope, rate limits, quotas, expiry, suspension, or creation controls;
  • creating boxes, capabilities, accounts, versions, resumable sessions, or webhook traffic primarily to evade limits or impose cost;
  • using the service for cryptocurrency mining or similarly disproportionate resource consumption;
  • automated scraping or testing at a rate that degrades the service; and
  • using svc.nz to mislead people about affiliation with Anphase Ltd or endorsement by svc.nz.

Normal protocol experimentation against boxes you control is welcome when it is safe, proportionate, and consistent with the documented interfaces.

5. Uses the trial is not built for

Do not use the hosted private trial as the sole or primary system for emergency services, healthcare or clinical decisions, critical infrastructure, weapons, custody or liberty decisions, high-value financial execution, or any workload where delay, loss, corruption, or unauthorised access could foreseeably cause death, serious injury, major financial loss, or loss of fundamental rights.

Do not upload state secrets, regulated production credentials, or highly sensitive personal information unless you have independently assessed the service, have a lawful basis, use appropriate client-side encryption, and accept the published trial limits. The current hosted trial does not offer a data-processing agreement, compliance certification, or bespoke security terms.

6. Capability hygiene

A capability is a bearer credential. Keep it out of URLs, public repositories, logs, screenshots, issue trackers, and ordinary email. Use the Authorization header, choose read-only or name-scoped access when possible, adopt rotated capabilities, and invalidate exposed access promptly.

Do not knowingly use a capability you are not authorised to hold. If you receive one unexpectedly, do not explore the box; report the situation without including the live capability in the initial message.

7. How we enforce this policy

We may investigate reports and available technical signals. Depending on risk, context, law, and repeat behaviour, we may warn, rate-limit, restrict, quarantine, disable access, invalidate capabilities, delete an object or box, disable an account, preserve relevant evidence, or refer a matter to an appropriate provider or authority.

Urgent or severe risks may be addressed without notice. Where practical and lawful, we will try to notify an identifiable account holder and allow a response. Because many boxes have no user contact details, notice is not always possible. Enforcement decisions do not create a duty to monitor all content, and inaction in one case does not waive our right to act later.

8. Report a problem

Use the Abuse Process for harmful or illegal content, the Copyright page for intellectual-property complaints, and the Security page for vulnerabilities. For urgent danger, contact the emergency or law-enforcement service responsible for the affected location; svc.nz is not an emergency channel.

svc.nzHouse rules for the private trial.Operated by Anphase Ltd in Aotearoa New Zealand.
Policy centreTermsPrivacyAcceptable useAbuseSecurityCopyrightCookiesSubprocessors