Acceptable use
Effective 2026-08-05 · nitro.vn / nitrolet.com · preview
Nitro gives you a Linux machine with a shell and a network. That is a lot of trust for a free preview, and this page is the short version of what we ask in return. It is written to be read once and remembered, not to cover us.
The short version
Do not use a nitro box to harm somebody else's computer, network, or day.
Everything below is that sentence, made specific enough to act on.
Not allowed
- Attacking anything. Port scanning, credential stuffing, vulnerability scanning, exploitation or denial-of-service against hosts you do not own. This includes "just testing" against a target you do not have written permission for.
- Spam and unsolicited mail of any kind. Outbound SMTP (ports 25, 465, 587) is blocked at the network layer and will stay blocked.
- Proxying or anonymising other people's traffic — open relays, VPN exits, Tor exits, residential proxy nodes. One shared IP address is the platform's entire reputation.
- Cryptocurrency mining, and anything shaped like it. A preview box has one shared vCPU. Mining takes it from everybody else on the machine for a rounding error of value.
- Content that is illegal where the machine is (Ho Chi Minh City, Vietnam), including CSAM, which we report without exception, and content that infringes copyright you do not hold.
- Circumventing the platform's limits — quota evasion through multiple accounts, escaping the sandbox, reaching another tenant's box, or interfering with the host.
- Storing anything you cannot afford to lose. Not a rule so much as a warning; see below.
Allowed, and actively welcome
Development, builds and CI, running services and demos, agent and AI workloads, learning, teaching, scraping that respects robots.txt and rate limits, and anything else that would be unremarkable on a laptop.
What we do about it
- Automated controls come first. Default-deny egress, SMTP blocked, a per-source connection rate limit, guest-to-guest traffic dropped, and per-account quotas. Most abuse is prevented rather than punished.
- If we are notified of abuse from a box, we will suspend that box and email the account owner with what we were told. For anything ongoing and serious — an active attack, CSAM — we suspend first and explain afterwards.
- You get your data. A suspension is not a deletion. Unless the law requires otherwise, you have 14 days to retrieve anything on an attached volume before we remove it.
- Appeals go to the same address as everything else (below), and a person reads them.
⚠️ Our provider's terms are stricter than ours in one respect that matters to you: CloudFly suspends accounts immediately, with no refund and no backup, and we cannot appeal on your behalf after the fact. That is why the automated controls above are preventive rather than reactive — a violation that reaches them is one we may not be able to undo.
Reporting abuse
abuse@nitro.vn — include the hostname (<project>-<user>.nitrolet.com) or the IP address, a timestamp with a timezone, and a log excerpt if you have one. We aim to acknowledge within one business day. This is a small preview run by a small team; it is not a 24/7 desk, and we would rather say so than imply otherwise.
Changes
We will post changes here with a new effective date. A change that narrows what is allowed will be emailed to account holders before it takes effect.