Acceptable Use Policy
Draft — not yet reviewed by a lawyer
A structured draft, not reviewed or approved by a qualified legal professional. Highlighted items need real decisions before this is relied on.
This policy forms part of the Terms of Service and applies to everyone using CIAN and this website. It exists so the boundaries are written down rather than improvised, and it is written to be short enough to actually read.
1. The general rule
Do not use CIAN to do something illegal, to harm other people, to attack systems you have no right to touch, or to interfere with CIAN working for anyone else. Almost everything below is a specific case of that.
2. Do not use CIAN against systems you are not authorised to use
You may only point CIAN at code, repositories, infrastructure and accounts you own or are clearly authorised to work on. Specifically, do not use it to:
- access, scan or attack systems without the owner's permission;
- develop or distribute malware, ransomware, or tooling whose purpose is unauthorised access;
- build systems for large-scale unlawful surveillance;
- circumvent authentication, licensing or access controls you are not entitled to circumvent.
Security work done with authorisation — penetration testing under contract, research on your own systems, CTF and training environments, and building defensive tooling — is expressly permitted. The line is authorisation, not subject matter.
3. Do not use CIAN to harm people
- No harassment, stalking, threats or targeting of individuals.
- No child sexual abuse material, under any circumstances. We report it.
- No content designed to deceive people into giving up credentials, money or personal data.
- No impersonation of another person or organisation, including us.
4. Do not abuse the infrastructure
- Do not attempt to break out of, tamper with or reverse-engineer the isolation between projects.
- Do not attempt to bypass, disable or fake the pipeline's security or human-approval gates. They are enforced deliberately; working around them is a breach of this policy as well as a bad idea.
- Do not use CIAN to send bulk unsolicited messages, to mine cryptocurrency, or to run workloads unrelated to developing your own software.
- Do not probe, load-test or otherwise stress our systems without written permission.
5. Do not abuse this website's support form
The support form is for genuine support requests. Do not use it to send advertising, bulk mail, or automated submissions, and do not attempt to bypass its anti-bot protection or rate limits.
6. Respect other people's rights
Do not use CIAN to infringe copyright, trademarks, patents or trade secrets, or to strip licence and attribution notices from code you do not own. You are responsible for the licence compatibility of code CIAN produces for you.
7. Reporting a problem
To report abuse, a security vulnerability, or content that breaches this policy, use the support form. For a suspected vulnerability, please describe the issue without including working exploit detail; we will follow up with a private channel.
Add a dedicated abuse and security contact address, and — if one is offered — a coordinated disclosure policy with response timelines.
8. What happens if you breach this policy
Depending on what happened and how serious it is, we may contact you, limit or suspend your access, remove content, or terminate your account. Where the law requires it, or where there is a risk to someone's safety, we may report the matter to the authorities.
We aim to warn first and act proportionately, but we may act immediately without warning where there is serious or ongoing harm. Confirm whether an appeals route is offered, and describe it here if so — some jurisdictions require one.
9. Changes
We may update this policy as new problems appear. The date above will change and material changes will be notified alongside changes to the Terms of Service.