Effective date: August 2, 2026
Pre-release notice: GlobalStacks is a pre-release project and is not currently offered by an incorporated company. This policy describes the conduct expected on project-operated services. It is informational, may change before commercial launch, and is not legal advice.
Scope and responsibility
This policy applies when you use GlobalStacks websites, accounts, APIs, the console, CLI, hosted control plane, managed capacity, system-provided AI, Marketplace, extension services, access gateways, or connected agents. It also applies to users, workloads, agents, publishers, and third parties you authorize through your organization.
You are responsible for having authority over every host, account, repository, credential, network, data source, model, provider, and deployment target you connect. You must configure permissions and review automated actions in proportion to their consequences.
Customer-controlled infrastructure remains subject to the customer's own policies and applicable law. That ownership does not permit use of GlobalStacks control-plane, routing, identity, Marketplace, billing, AI, or access services to facilitate prohibited activity.
Unlawful conduct and serious harm
Do not use GlobalStacks to create, host, distribute, coordinate, conceal, or materially facilitate:
- Activity that violates applicable law, sanctions, court orders, or the legal rights of another person.
- Child sexual exploitation or abuse material, grooming, trafficking, or any sexual exploitation of minors.
- Credible threats, incitement, planning, or facilitation of violence, terrorism, human trafficking, or other serious physical harm.
- Non-consensual intimate imagery, sexual extortion, or synthetic media used for sexual abuse or exploitation.
- Fraud, scams, deceptive commercial practices, identity theft, impersonation, forged authority, or evasion of lawful accountability.
- Targeted harassment, doxxing, unlawful discrimination, or publication of private or highly sensitive personal information without authority.
- Infringement or misappropriation of copyright, trademarks, patents, trade secrets, publicity rights, or other proprietary rights. Copyright complaints follow the Copyright and takedown process.
Unauthorized access and technical abuse
Do not use GlobalStacks services or connected capacity to:
- Access, scan, test, exploit, disrupt, or control a system, account, device, model, service, or network without explicit authorization.
- Deliver malware, ransomware, destructive payloads, credential stealers, cryptojacking software, or command-and-control infrastructure for an active harmful campaign.
- Conduct denial-of-service attacks, traffic amplification, resource exhaustion, destructive automation, or deliberate interference with another user's service.
- Phish for credentials, intercept communications without authority, bypass access controls, or obtain, trade, or expose authentication secrets.
- Remove or evade audit evidence, provenance, signatures, policy checks, tenant boundaries, network controls, usage metering, quotas, safety systems, or approval requirements.
- Misrepresent the identity, permissions, security posture, source, behavior, dependencies, data access, egress, or resource requirements of a host, workload, agent, template, extension, provider, model, or Marketplace release.
Authorized security research and dual-use tools
Legitimate defensive research, vulnerability testing, malware analysis, incident response, and dual-use security development are allowed only when you have documented authorization and keep the work within its approved scope. A tool is not prohibited merely because it can be used offensively.
Testing must not access another user's tenant or data, degrade shared services, persist beyond the authorized engagement, distribute live credentials or harmful payloads, or use GlobalStacks as attack infrastructure. Follow the target's vulnerability-disclosure or bug-bounty rules and stop when authorization is withdrawn.
Spam, inauthentic activity, and abusive automation
Do not use GlobalStacks to send unsolicited bulk messages, generate fake engagement, operate deceptive account networks, scrape or harvest personal data for spam, evade platform bans, manipulate rankings, create abusive numbers of accounts, or relay traffic intended to conceal prohibited activity.
Automation must use documented interfaces, respect rate and concurrency limits, identify itself when required, and use exponential backoff. Do not divide activity among accounts, organizations, agents, addresses, or provider connections to bypass a limit or enforcement action.
Resource and service abuse
Do not place an unreasonable or unanticipated burden on GlobalStacks, its users, or upstream providers. On shared or GS-funded capacity, this includes unauthorized cryptocurrency mining, bandwidth resale, open proxies or VPN exit services, hotlinking or bulk media relay, sustained benchmark traffic without approval, artificial generation of billable usage, and workloads primarily intended to consume free allowances.
Resource-intensive lawful workloads may be permitted on customer-owned or appropriately purchased dedicated capacity, but they must still respect declared limits, provider terms, network policy, safety boundaries, and the rights of others.
Marketplace and software supply chain
Marketplace publishers and extension operators must provide accurate identity, provenance, permissions, dependencies, pricing, compatibility, network access, data use, and runtime behavior. Do not publish:
- Malicious, deceptive, typosquatted, dependency-confused, or impersonating packages and listings.
- Hidden payloads, undeclared downloads, dormant harmful behavior, credential collection, unauthorized telemetry, or functionality designed to appear only after review.
- Copied or repackaged software without the required rights, notices, source offers, or license compliance.
- Artifacts or metadata intended to bypass signature, review, certification, billing, consent, permission, or compatibility gates.
Installation approval does not transfer responsibility away from the publisher or customer. Customers should review requested capabilities and use only releases appropriate for their environment.
AI, agents, and automated decisions
When using system-provided AI, AI Gateway routes, agents, or customer-connected models, you must also follow the applicable provider terms. Do not:
- Use agents to perform an action the authenticated user or workload is not permitted to perform directly.
- Circumvent provider safeguards, extract models or secrets without authorization, trade provider keys, falsify model usage, or evade customer budgets and metering.
- Represent synthetic output as verified human work when that representation could materially deceive or harm another person.
- Delegate consequential employment, housing, credit, insurance, healthcare, legal, education, public-benefit, or law-enforcement decisions without the authorization, review, transparency, and safeguards required by applicable law.
- Send data to a model, tool, or provider unless you are authorized to disclose it and the configured route is appropriate for its sensitivity and residency requirements.
System-provided AI allowances are for authenticated customer use. Attempts to resell, pool, automate extraction from, or disguise consumption of those allowances may be blocked and attributed to the responsible organization.
Credentials, identity, and customer data
Do not share credentials across people or organizations, publish access tokens, request broader permissions than an integration needs, or move secrets into sandbox files, prompts, source repositories, logs, images, or artifacts when a brokered path is available. Revoke credentials that may be exposed.
Access to personal, confidential, regulated, or customer data requires a lawful basis, appropriate authorization, purpose limitation, retention controls, and any contractual safeguards that apply. A technical ability to reach data is not permission to use it.
Reporting suspected abuse
Send a report to support@globalstacks.dev with the subject Abuse report. Include the exact URL, organization, listing, release, host or sandbox identifier when known; the observed conduct; relevant dates and times; why it violates this policy; and a safe way to reproduce or verify the report.
Do not send live malware, private keys, passwords, unnecessary personal data, or exploit instructions in ordinary email. State that sensitive evidence is available so a safer transfer method can be arranged. For immediate danger, contact the appropriate emergency service or competent authority first.
Investigation and enforcement
We may use automated signals and human review to investigate suspected violations. We may request information, preserve relevant records, limit a specific operation, quarantine an artifact, remove a Marketplace listing, revoke a token, restrict network access, suspend managed capacity, or suspend an account or organization.
Where risk permits, we aim to give notice, identify the policy concern, and allow correction before broader action. We may act without advance notice when reasonably necessary to stop active compromise, serious harm, unlawful conduct, material service disruption, evidence destruction, or continued evasion.
Enforcement should be proportionate to severity, intent, recurrence, affected scope, cooperation, and available containment. Action against GlobalStacks services does not imply that GlobalStacks has erased customer-controlled infrastructure or adjudicated criminal or civil liability.
Appeal and reinstatement
Send an appeal to the same address with the subject Acceptable use appeal. Identify the affected account, organization, resource, or release; explain why the action was mistaken or disproportionate; describe corrective steps; and provide relevant authorization or evidence.
A person not involved in the original decision should review the appeal when practical. Restoration may be conditioned on remediation, narrower permissions, removal of content, credential rotation, capacity limits, monitoring, or other controls reasonably related to the violation.
Changes and related policies
This policy works together with the Terms of Service, Marketplace terms, Publisher Agreement, Copyright and Takedown policy, privacy notices, provider terms, and any organization-specific agreement. The more specific rule governs when two rules address the same activity.
Material revisions should receive a new effective date and be published through the normal legal and product communication channels.