Acceptable Use Policy (AUP)
This Acceptable Use Policy (“AUP”) governs the use of the serverless computing platform operated by evrtng functions, Dorfstrasse 1, CH-8934 Knonau (“Provider”, “we”, “us”). By using the Service, you (“Customer”, “you”) agree to comply with this AUP.
1. Purpose
This AUP defines acceptable use of the serverless platform (based on Apache OpenWhisk) provided by evrtng functions. It exists to ensure a reliable, secure, and lawful environment for all customers. The platform is operated on infrastructure in Zurich, Switzerland, and is intended exclusively for use by customers located in Switzerland.
2. Prohibited Uses
You must not use the Service, nor permit anyone else to use the Service, directly or indirectly, for any of the following purposes:
- Malware: Distributing, hosting, or executing malicious software, including viruses, trojans, ransomware, spyware, or any code designed to harm or gain unauthorised access to systems.
- Crypto mining: Mining cryptocurrencies or operating mining pools, including but not limited to CPU, GPU, or ASIC-based mining, regardless of whether for the customer’s own benefit or that of third parties.
- Spam: Sending unsolicited bulk email, unsolicited commercial messages, or any form of unsolicited electronic communication, as well as operating mail relays or providing infrastructure for spam operations.
- Illegal content: Hosting, processing, or distributing content that violates Swiss criminal law, including content related to child exploitation, terrorism, hate speech (StGB Art. 259, 260ter, 261), or defamation (StGB Art. 173 et seq.).
- Resource abuse: Deliberately consuming excessive CPU, memory, network, or storage resources beyond the reasonable needs of the deployed functions, including running persistent background processes or using the platform as a general-purpose compute instance.
- Denial of Service: Launching, participating in, or facilitating denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks against any target, whether internal or external to the platform.
- Scraping: Scraping, crawling, or harvesting data from third-party services without their explicit permission, or using the platform to automate unauthorised access to external systems.
- Copyright infringement: Hosting, processing, or distributing material that infringes the intellectual property rights of third parties, including copyrighted software, media, or documents, unless the customer holds the necessary rights or licences.
- Unauthorised access: Attempting to gain unauthorised access to the Provider’s infrastructure, other customers’ namespaces or data, or any third-party systems, including port scanning, vulnerability scanning, or credential stuffing.
- Interference: Interfering with the proper operation of the platform, including bypassing rate limits, quotas, or security controls, or reverse engineering the Provider’s proprietary components.
3. Resource Limits
The Service is subject to per-plan rate limits and monthly quotas. Rate limits are applied per namespace and measured in action invocations per minute:
- Free (CHF 0/month): 60 invocations/minute, monthly quota as published in the plan description.
- Starter (CHF 9.95/month): 300 invocations/minute, monthly quota as published in the plan description.
- Pro (CHF 49.95/month): 600 invocations/minute, monthly quota as published in the plan description.
- Enterprise (CHF 199.95/month): 1500 invocations/minute, monthly quota as published in the plan description.
Requests exceeding the applicable rate limit receive a HTTP 429 (Too Many Requests) response. Exceeding monthly quotas may result in throttling or temporary suspension of invocation capability until the next billing cycle. The Provider reserves the right to adjust rate limits and quotas with 14 days’ notice (see Section 7).
4. Security
You are responsible for securing your account, API keys, namespaces, and authentication credentials. Specifically:
- Credential protection: You must store API keys, tokens, and other credentials securely. Never embed credentials in client-side code or commit them to public repositories.
- No sharing: You must not share your account credentials, API keys, or namespace access with third parties. Each user must use their own Authentik identity. Shared or service accounts must be individually attributable.
- Namespace isolation: You must use namespaces to isolate workloads and enforce least-privilege access. Do not deploy production and development workloads in the same namespace without appropriate access controls.
- Prompt reporting: You must report any suspected or actual security incident, credential compromise, or unauthorised access to security@evrtng.cloud without undue delay.
- Function code security: You are responsible for the security of the code you deploy. The Provider is not responsible for vulnerabilities introduced by customer function code.
5. Enforcement
The Provider enforces this AUP through a graduated response. Depending on the severity and nature of the violation, the Provider may take the following steps, not necessarily in this order:
- Warning: For minor or first-time violations, the Provider sends a written warning to the account owner with a description of the violation and a deadline for remediation.
- Suspension: For repeated violations, failure to remedy after a warning, or serious violations, the Provider may suspend the affected namespace or account. Suspension may include blocking action invocations, disabling API access, or quarantining deployed functions.
- Termination: For severe or persistent violations, or where required by law, the Provider may terminate the contract with immediate effect. This includes violations involving illegal content, attacks on infrastructure, or activities that expose the Provider to legal liability.
In emergencies, where the integrity of the platform or other customers is at immediate risk, the Provider may suspend access without prior warning. The Provider will notify the customer of the reason for any suspension as soon as reasonably possible.
6. Reporting Abuse
To report abuse, security incidents, or violations of this AUP, contact:
Email: abuse@evrtng.cloud
PGP: Available on request
Response time: Within 24 hours during business hours (Mon-Fri, 08:00-18:00 CET/CEST)
Please include as much detail as possible: affected namespaces, timestamps, relevant logs, and a description of the incident.
7. Changes to this AUP
The Provider may update this AUP at any time. Material changes will be announced by email to the account owner at least 14 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated AUP. If you do not agree to the changes, you may terminate your contract in accordance with the General Terms and Conditions (AGB).
8. Liability
You are solely responsible for the function code you deploy, the data you process via the Service, and the consequences of your use of the platform. The Provider is not liable for damages arising from customer function code, customer data, or customer violations of this AUP.
You indemnify the Provider against all claims by third parties arising from your use of the Service in violation of this AUP, applicable law, or third-party rights. This indemnification covers reasonable legal and defence costs.
The Provider’s liability is further governed by the General Terms and Conditions (AGB) and applicable Swiss law. Nothing in this AUP limits the Provider’s liability for gross negligence or wilful misconduct.
evrtng functions, Dorfstrasse 1, CH-8934 Knonau. Version 1.0. Swiss law applies.
