ACCEPTABLE USE POLICY

  • Tuesday, 1st January, 2013
  • 17:00pm

ACCEPTABLE USE POLICY

Lebanese For Advanced Information Technologies SARL

LFAIT / MFAIT

This Acceptable Use Policy (“AUP”) governs all use of services, networks, servers, virtual machines, IP addresses, bandwidth, applications, storage, security services, proxy services, and other infrastructure supplied by LFAIT.

This AUP forms part of LFAIT's Terms of Service. Violation of this AUP constitutes a violation of the Terms of Service.


1. Customer Responsibility

The Customer is responsible for all activity originating from or conducted through its Services.

This includes activity performed by the Customer's employees, administrators, contractors, customers, subscribers, resellers, end-users, scripts, applications, servers, virtual machines, APIs, automated systems, or other persons receiving access directly or indirectly through the Customer.

A Customer may not avoid responsibility under this AUP merely by claiming that prohibited activity originated from an end-user, reseller, compromised server, compromised credential, automated application, or third party using Customer-controlled infrastructure.


2. General Prohibited Use

The Services must not be used to conduct, facilitate, assist, enable, conceal, or knowingly support unlawful, malicious, fraudulent, abusive, infringing, unauthorized, or materially disruptive activity.

The examples listed in this AUP are not exhaustive.


3. Copyright, Piracy, IPTV, Streaming, and Media

Customers using the Services for streaming, IPTV, retransmission, media distribution, restreaming, broadcasting, CDN activity, video delivery, or similar purposes represent and warrant that they possess all rights, permissions, licenses, and authorizations legally required for that activity.

Prohibited activity includes unauthorized:

  • IPTV distribution;
  • television retransmission;
  • restreaming;
  • pay-TV redistribution;
  • movie distribution;
  • sporting-event streaming;
  • broadcasting;
  • copyrighted media distribution;
  • software piracy;
  • circumvention of conditional-access systems; and
  • other infringement of intellectual-property rights.

A Customer may be required to provide reasonable evidence of authorization or licensing following a credible complaint.

Failure to provide sufficient information may result in restriction or suspension while the matter is investigated.


4. Malware and Malicious Software

The following are prohibited:

  • malware;
  • ransomware;
  • spyware;
  • botnets;
  • command-and-control infrastructure;
  • viruses;
  • worms;
  • trojans;
  • credential stealers;
  • cryptojacking malware;
  • malicious payload distribution; and
  • infrastructure primarily intended to facilitate malicious software.

5. Network Attacks and Unauthorized Access

Prohibited activity includes:

  • DDoS or denial-of-service attacks;
  • packet flooding;
  • reflection or amplification attacks;
  • unauthorized port scanning;
  • unauthorized vulnerability scanning;
  • unauthorized exploitation;
  • unauthorized penetration attempts;
  • credential attacks;
  • brute-force attacks;
  • account takeover attempts;
  • unauthorized access; and
  • attempts to interfere with third-party systems or networks.

Legitimate penetration testing or security research must be conducted only against systems for which the Customer has proper authorization and must not materially affect LFAIT, an Upstream Provider, or third parties.


6. Spam, Phishing, Fraud, and Deceptive Activity

Prohibited activity includes:

  • spam;
  • unsolicited bulk messaging;
  • phishing;
  • smishing;
  • credential harvesting;
  • fraudulent email;
  • impersonation;
  • identity theft;
  • scams;
  • deceptive commercial practices;
  • payment fraud;
  • account takeover operations; and
  • services primarily designed to facilitate fraud or abuse.

7. Illegal or Restricted Content

Customers may not host, distribute, transmit, advertise, facilitate, or knowingly support content or activity prohibited by applicable law.

Content involving unlawful exploitation, abuse of minors, terrorist activity, trafficking, serious financial crime, or other activity requiring immediate legal intervention may result in immediate restriction or termination and may be reported where required by law.


8. Network Abuse and Infrastructure Protection

Customers may not intentionally or negligently operate systems in a manner that materially:

  • disrupts the LFAIT network;
  • disrupts an Upstream Provider;
  • interferes with other customers;
  • damages network equipment;
  • consumes resources outside contracted limits;
  • bypasses technical restrictions;
  • causes routing instability;
  • generates abnormal malicious traffic; or
  • creates an unreasonable security or operational risk.

9. IP Address and Network Reputation

IP addresses supplied with the Services remain subject to LFAIT and applicable Upstream Provider network policies.

Customers must not use assigned IP addresses in a manner that causes or is reasonably likely to cause:

  • spam blacklist listings;
  • malware or phishing reputation listings;
  • DDoS blackholing;
  • route filtering;
  • abuse database listings;
  • widespread network blocking;
  • network sanctions;
  • material reputational damage; or
  • complaints from carriers, security organizations, or Upstream Providers.

LFAIT may, where reasonably required:

  • null-route IP addresses;
  • block ports;
  • restrict traffic;
  • withdraw an IP allocation;
  • replace an IP allocation;
  • require remediation; or
  • suspend affected Services.

IP addresses assigned with a Service do not become the Customer's property unless specifically transferred under a separate written agreement.


10. Proxies, VPNs, Relays, and Public Access Services

Customers operating proxies, VPNs, tunnels, relays, exit nodes, public gateways, residential proxy systems, or similar services must implement reasonable abuse controls appropriate to the risk of the Service.

LFAIT may require measures including:

  • customer or end-user identification;
  • access controls;
  • rate limits;
  • abuse contact information;
  • connection records where legally permitted;
  • blocking repeat offenders;
  • limiting high-risk ports;
  • responding to complaints; and
  • terminating abusive users.

Persistent abuse from proxy, VPN, relay, or public-access infrastructure may result in restriction or termination.


11. Customer Security Obligations

The Customer is responsible for securing Customer-controlled systems.

Customers should implement security practices appropriate to their Services, including:

  • strong passwords;
  • multi-factor authentication where available;
  • secure management interfaces;
  • current security updates;
  • restricted administrative access;
  • appropriate firewall rules;
  • secure API keys;
  • appropriate account permissions; and
  • regular backups.

If a system is compromised, the Customer must promptly:

  1. contain the compromise;
  2. stop continued malicious activity;
  3. secure affected credentials;
  4. remediate the underlying vulnerability; and
  5. cooperate with reasonable LFAIT security requests.

A compromised server does not automatically exempt the Customer from obligations under this AUP.


12. Abuse Reports and Investigation

Abuse reports should be submitted through the designated LFAIT abuse channel.

Reports should contain, where available:

  • complainant information;
  • affected IP addresses;
  • URLs or domain names;
  • timestamps and timezone;
  • logs;
  • screenshots;
  • evidence of the alleged activity;
  • applicable legal or intellectual-property basis; and
  • other information reasonably required to investigate.

LFAIT may request additional evidence where a complaint is incomplete or unclear.

LFAIT is not required to treat unsupported allegations as conclusive evidence.

Where immediate action is reasonably necessary to protect the network, prevent serious harm, satisfy legal obligations, or comply with an Upstream Provider requirement, temporary protective action may be taken before completion of an investigation.


13. Customer Response to Abuse Complaints

When LFAIT forwards an abuse complaint or requests remediation, the Customer must respond within the timeframe specified in the notice.

For high-risk, active, or ongoing abuse, a substantially shorter response period may be required.

The Customer may be required to:

  • stop abusive activity;
  • remove offending content;
  • disable an affected account;
  • isolate an infected system;
  • block malicious traffic;
  • provide an explanation;
  • provide evidence of authorization;
  • identify remediation performed; or
  • implement additional safeguards.

Failure to respond within the required period may result in restriction or suspension.

A denial that does not address credible technical evidence may not be considered adequate remediation.


14. Emergency Abuse and Security Action

LFAIT may take immediate action without prior notice where reasonably necessary to protect its network, customers, Upstream Providers, third parties, or legal interests.

Emergency action may include:

  • filtering traffic;
  • blocking ports;
  • null-routing IP addresses;
  • disconnecting network interfaces;
  • restricting bandwidth;
  • disabling credentials;
  • isolating a virtual machine;
  • shutting down a server;
  • temporarily suspending a Service; or
  • terminating severe abusive activity.

Such action may be taken in response to active attacks, malware, ransomware, botnets, phishing, fraud, exploitation, significant infringement supported by credible evidence, urgent upstream notices, legal orders, or other activity creating an immediate material risk.


15. Repeat Abuse

Repeated complaints, recurring malicious activity, repeated failure to secure compromised Services, repeated infringement, or continued violations after warnings may be treated as repeat abuse.

LFAIT may consider:

  • number of complaints;
  • severity;
  • credibility of evidence;
  • previous warnings;
  • remediation history;
  • recurrence;
  • Customer cooperation;
  • network impact; and
  • upstream consequences.

Repeat offenders may have Services terminated even where individual incidents might otherwise have resulted only in warnings.

Customers may not evade an abuse history by opening new accounts, changing contact information, moving activity to another server, or ordering through another controlled entity.


16. Upstream Providers and Data Centers

Certain Services depend upon Upstream Providers.

Where an Upstream Provider requires action relating to specific traffic, IP addresses, servers, or Services, LFAIT may implement the required action where reasonably necessary to maintain connectivity, contractual compliance, security, or Service availability.

LFAIT will not be responsible for an Upstream Provider action resulting from Customer abuse, unlawful activity, security threats, or violations attributable to the Customer, except to the extent liability cannot lawfully be excluded.


17. Abuse Investigation and Remediation Costs

Where Customer activity causes LFAIT to incur material and reasonably documented costs due to abuse investigation, mitigation, emergency technical intervention, replacement of blacklisted resources, legal requests, Upstream Provider penalties, IP remediation, or other extraordinary remediation, LFAIT may seek reimbursement from the Customer to the extent permitted by applicable law and the applicable contract.

This provision is not intended to create arbitrary penalties. Charges should reflect reasonable costs or contractual third-party charges attributable to the Customer's activity.


18. DDoS Protection and Security Services

Where DDoS protection, firewalling, filtering, mitigation, monitoring, or another security feature is provided, such Services reduce certain risks but cannot guarantee prevention of every attack or interruption.

LFAIT may change routing, apply filters, rate-limit traffic, or temporarily null-route a destination where reasonably necessary to protect network stability.

A DDoS-protected Service does not authorize a Customer to intentionally attract, provoke, participate in, or facilitate attacks.


19. Circumvention of Restrictions

Customers may not circumvent or attempt to circumvent:

  • bandwidth restrictions;
  • billing systems;
  • authentication mechanisms;
  • security controls;
  • port blocks;
  • DDoS controls;
  • IP restrictions;
  • license limitations;
  • suspension measures;
  • abuse controls; or
  • other technical restrictions applied to the Service.

Attempts to bypass an enforcement action may result in termination.


20. Suspension and Termination for Abuse

LFAIT may suspend, restrict, or terminate an affected Service where:

  • the Customer violates this AUP;
  • credible abuse complaints are not adequately addressed;
  • Customer activity creates material security or legal exposure;
  • Customer activity materially affects LFAIT or an Upstream Provider;
  • the Customer repeatedly generates abuse;
  • an applicable authority requires action; or
  • continued operation materially threatens LFAIT's infrastructure or ability to provide Services.

Prior notice is not required where immediate action is reasonably necessary to address serious abuse, active attacks, fraud, security threats, legal requirements, or network protection.

Suspension caused by Customer abuse does not by itself create a right to a refund or Service Level Agreement credit, except where required by applicable law or a specific written agreement.


21. Abuse Reporting Contact

Security, network abuse, copyright, phishing, malware, spam, fraud, and related complaints should be submitted to:

Abuse: [email protected]

Reports should contain sufficient technical evidence to allow a reasonable investigation.


IMPORTANT CUSTOMER NOTICE

Customers are responsible for activity originating from their Services, including activity performed by employees, contractors, customers, resellers, end-users, compromised systems, scripts, applications, and credentials.

LFAIT may take immediate protective action where activity creates a serious security, legal, abuse, network, or Upstream Provider risk.

If you receive an abuse notification from LFAIT, respond promptly and completely. Failure to remediate abuse may result in network restriction, IP null-routing, suspension, or termination.

Lebanese For Advanced Information Technologies SARL

 

« Back