Abuse Policy
BITFOO LLC · Version 1.0 · Effective
Guide to the document
In Plain Language
A short summary of what follows. It is here to help you understand this policy, not to replace it.
- Something abusive coming from our network? Tell us at abuse@bit.foo. A real person reads it.
- Tell us where and when. An IP address or URL, and a timestamp with the timezone. Without those we usually can't work out who was responsible, and we'd like to.
- We move fastest on active harm — live phishing, malware, attacks in progress, and anything involving the safety of a child.
- We don't monitor our clients' content, but we do watch public threat feeds for malicious activity on our own address space, and we act on what turns up.
- We'll tell you we got it. We can't always tell you what happened afterwards — that's our client's business, not ours to publish.
- Reports made in bad faith get read and then ignored. Volume doesn't make a report true, and we've seen competitors file them.
- Legal process goes to legal@bit.foo. Copyright goes to dmca@bit.foo.
This summary is not part of the policy and has no legal effect. The numbered sections below are the actual policy and govern in full.
The policy
1. Scope
1.1 This policy explains how to report abuse involving services provided by BITFOO LLC (“Bitfoo,” “we,” “us”), and what we do about it.
1.2 What belongs here: spam and unsolicited bulk email, phishing, malware and malicious hosting, network attacks and scanning, open resolvers and amplification, trademark infringement and impersonation, fraud, harassment, illegal content, and child sexual abuse material.
1.3 What belongs elsewhere:
- Copyright — our DMCA and Copyright Policy, to dmca@bit.foo
- Legal process, subpoenas, and court orders — Section 10, to legal@bit.foo
- Security vulnerabilities in our own systems — Section 11
- Your own account or billing — support@bit.foo
1.4 What our clients may and may not do is set out in our Acceptable Use Policy. This policy is about reporting and process; that one is about the rules.
1.5 We are a service provider, not a publisher. We do not create or select what our clients host, and we do not adjudicate disputes between third parties.
2. How to Report
2.1 Send reports to abuse@bit.foo.
2.2 This mailbox is not filtered. Abuse reports routinely contain malicious URLs, and a spam filter would throw away the reports we most need. Send us the evidence.
2.3 We accept reports from anyone. You do not need an account with us, and you do not need to be in the United States.
3. What to Include
3.1 So that we can act, please give us:
- The IP address, domain, or full URL involved. This is the single most important element.
- The date and time, including the timezone. Without it we often cannot match activity to an account.
- What kind of abuse you are reporting.
- Evidence — full message headers for spam or phishing, log excerpts with timestamps for network abuse, screenshots or archived copies for content.
- Your name and a contact email address, so we can come back to you if we need more. This is helpful rather than required — see Section 3.3.
3.2 Reports without an IP address or a timestamp with timezone usually cannot be investigated. That is not us being difficult — on a shared platform, or across a network, those two details are frequently the only way to identify which account was responsible.
3.3 Reporting anonymously. You may report without identifying yourself. We understand why that matters — Section 6.2 means a named reporter’s details usually reach the person they are reporting, and for harassment, stalking, threats, or extremist content that is a real deterrent.
But we may not be able to act on a report we cannot corroborate, because we have no way to come back to you for the detail we need. If you report anonymously, include as much evidence as you can up front — the IP or URL, the timestamp with timezone, and anything that lets us verify it independently.
3.4 Machine-generated reports in standard formats are welcome. Send them to the same address.
4. How Quickly We Respond
4.1 Our targets:
- Acknowledge within 24 hours.
- Act on verified critical reports within 4 hours.
- Act on verified standard reports within 24 hours.
4.2 These are targets, not guarantees. Where you have reported anonymously we cannot acknowledge receipt, but the report is read and triaged the same way as any other.
4.3 What counts as critical is our judgement, based on the harm being done and how quickly it is spreading. It generally includes active phishing, malware distribution, outbound attack traffic, amplification abuse, and anything involving the safety of a child. This list is illustrative and not exhaustive — we would rather assess each report on its facts than be bound by a category.
5. What We Can Actually Do
5.1 Our response depends on the service involved, and we are direct about this because it affects how fast something stops:
Shared hosting. We can reach the account directly and remove or disable the specific content, or suspend the account.
Virtual private servers. These are administered by our client, not by us. We do not have practical or appropriate access to remove individual files. We forward the report to the client with a deadline, and suspend the server if they do not act. Where harm is active and ongoing, we suspend first.
Network-level. We can filter, rate-limit, or null-route an address where necessary to stop harm to others.
Reseller accounts. We notify the reseller with a deadline, and act directly against the account, the reseller, or both if they do not.
Domains. Registering a domain is not hosting content. A complaint about a website belongs with whoever hosts it. Where we are only the registrar we will tell you so, and point you onward where we can.
5.2 Nothing here limits our rights under our Acceptable Use Policy or Terms of Service, which we may exercise independently of any report.
6. What We Tell Our Client
6.1 Where we act on a report, we notify the client and give them a copy of it, so they can understand what happened and fix it.
6.2 Reports often contain the reporter’s name and contact details. If you report abuse to us, expect that information to reach the person you are reporting. If that is a problem for you, tell us and we will consider what we can reasonably redact — but a report we cannot pass on is often a report we cannot act on.
6.3 We help our clients fix things. Most abuse comes from compromised sites rather than deliberate bad actors, and a client who knows what to do fixes it faster. Where we can, we point clients at remediation guidance rather than simply telling them there is a problem.
6.4 We do not disclose our client’s identity or contact details to a reporter. That requires legal process — see Section 10.
7. What We Tell You
7.1 We acknowledge reports we receive, where you have given us an address to reply to.
7.2 We may tell you the outcome, and often will — but we do not guarantee it. What happened to a client’s account is their business. Where the law requires us to tell you something, we will; beyond that, treat any update as a courtesy.
7.3 Copyright complaints work differently. Where you file a copyright notice and our client files a counter-notice, we are legally required to send you a copy and tell you when the material will be restored. See our DMCA and Copyright Policy.
8. Child Safety
8.1 Reports involving the sexual exploitation of a child are handled ahead of everything else. Send them to abuse@bit.foo and say clearly in the subject line what they concern.
8.2 Where we obtain actual knowledge of apparent child sexual abuse material or related offences, we report it to the National Center for Missing & Exploited Children as required by United States federal law, preserve the material and associated records as the law requires, and terminate the account. There is no notice period, no opportunity to cure, and no refund.
8.3 You can also report directly to the CyberTipline at report.cybertipline.org, or in an emergency to law enforcement. Reporting to us does not replace either.
9. What We Watch For Ourselves
9.1 We do not monitor our clients’ content, and we have no obligation to. Our Acceptable Use Policy and Privacy Policy both say so and both remain true.
9.2 We do, however, monitor public threat intelligence feeds for malicious activity associated with our own network and address space, and act on what they show us. Because we operate our own address space, its reputation is shared by every client on it, and we would rather find a problem than be told about it.
9.3 These are different things. A feed telling us a URL on our network is serving malware is not us reading our clients’ data. We act on the specific thing reported, nothing more.
10. Legal Process and Law Enforcement
10.1 Subpoenas, court orders, preservation requests, and other legal process should be sent to legal@bit.foo, or by post to the address in Section 15.
10.2 We disclose client information only where we are required to by valid legal process, or where the law otherwise permits or requires it. We are a United States company and we assess requests accordingly.
10.3 We may notify the affected client that we have received a request, unless we are prohibited from doing so or believe notice would prejudice an investigation or endanger someone.
10.4 Emergencies. Where there is a risk of death or serious physical injury, mark your request URGENT in the subject line and we will prioritise it ahead of other legal correspondence.
We do not operate a staffed 24-hour emergency desk and we do not commit to a response time. If someone is in immediate danger, contact emergency services and the relevant law enforcement agency directly — do not wait on us.
10.5 Nothing here obliges us to disclose information without valid process, and nothing here prevents us from disclosing where the law requires it.
11. Security Vulnerabilities
11.1 If you have found a vulnerability in our own systems, we would like to hear from you. Our Security and Vulnerability Disclosure Policy sets out how to report it, what is in scope, and what we commit to in return.
11.2 That policy covers our systems. Vulnerabilities in a client’s own website or server are not in its scope — report those to the client directly, or to us under Section 2 if the client cannot be reached or does not act.
12. Reports Made in Bad Faith
12.1 We read everything. We assess reports on their merits, not on how many arrive or how insistent they are.
12.2 We may decline to act on reports that are automated bulk submissions without substance, plainly invalid, unsupported by evidence, or demonstrably inaccurate on repetition.
12.3 We are aware that abuse reports are sometimes filed against a business by its competitors, or to harass. Volume does not make a report true. Reports that appear to be made in bad faith are recorded and disregarded, and we may decline to accept further reports from the same source.
13. Our Records
13.1 We log every report: when it arrived, who sent it, what it concerned, the address or URL involved, which account it related to, what we did, and when we closed it.
13.2 These records are retained in accordance with our Privacy Policy, and longer where an investigation, a legal obligation, or a repeat-conduct assessment requires it.
14. Changes
14.1 We may update this policy. For material changes we will give at least 30 days’ notice to account holders and publish the updated policy with a new version number and effective date.
14.2 Changes required by law may take effect immediately on publication.
15. Contact
Abuse reports: abuse@bit.foo
BITFOO LLC 146 East King St, Unit #1283 Lancaster, PA 17602 United States
Copyright: dmca@bit.foo · Legal process: legal@bit.foo · Privacy: privacy@bit.foo · Support: support@bit.foo