Have the right to store it
No illegal, exploitative, privacy-violating, infringing, or deliberately harmful material.
svc.nz stores opaque bytes, but “opaque” does not mean “anything goes.” These rules protect people, rights, infrastructure, and the tiny private trial running underneath it.
No illegal, exploitative, privacy-violating, infringing, or deliberately harmful material.
No malware delivery, phishing, credential theft, spam, denial of service, or unauthorised access.
No quota evasion, abusive automation, resource mining, or traffic designed to degrade availability.
This policy applies to everyone who accesses the hosted svc.nz service, including anyone who uploads or retrieves content, holds or passes on a capability, controls an account key, configures a webhook, or builds another service on top of svc.nz.
You are responsible for use made through credentials you control and for reasonable steps to prevent misuse by your users or recipients. This policy forms part of the Terms of Service.
Do not upload, store, request, or distribute content that:
Context matters. Legitimate security research, journalism, archival work, and defensive tools are not prohibited merely because they discuss harmful behaviour, but you must have authority, minimise risk, and comply with law.
Do not use svc.nz to:
Do not interfere with svc.nz or other users. That includes:
Normal protocol experimentation against boxes you control is welcome when it is safe, proportionate, and consistent with the documented interfaces.
Do not use the hosted private trial as the sole or primary system for emergency services, healthcare or clinical decisions, critical infrastructure, weapons, custody or liberty decisions, high-value financial execution, or any workload where delay, loss, corruption, or unauthorised access could foreseeably cause death, serious injury, major financial loss, or loss of fundamental rights.
Do not upload state secrets, regulated production credentials, or highly sensitive personal information unless you have independently assessed the service, have a lawful basis, use appropriate client-side encryption, and accept the published trial limits. The current hosted trial does not offer a data-processing agreement, compliance certification, or bespoke security terms.
A capability is a bearer credential. Keep it out of URLs, public repositories, logs, screenshots, issue trackers, and ordinary email. Use the Authorization header, choose read-only or name-scoped access when possible, adopt rotated capabilities, and invalidate exposed access promptly.
Do not knowingly use a capability you are not authorised to hold. If you receive one unexpectedly, do not explore the box; report the situation without including the live capability in the initial message.
We may investigate reports and available technical signals. Depending on risk, context, law, and repeat behaviour, we may warn, rate-limit, restrict, quarantine, disable access, invalidate capabilities, delete an object or box, disable an account, preserve relevant evidence, or refer a matter to an appropriate provider or authority.
Urgent or severe risks may be addressed without notice. Where practical and lawful, we will try to notify an identifiable account holder and allow a response. Because many boxes have no user contact details, notice is not always possible. Enforcement decisions do not create a duty to monitor all content, and inaction in one case does not waive our right to act later.
Use the Abuse Process for harmful or illegal content, the Copyright page for intellectual-property complaints, and the Security page for vulnerabilities. For urgent danger, contact the emergency or law-enforcement service responsible for the affected location; svc.nz is not an emergency channel.