Acceptable Use Policy

Draft — not yet reviewed by a lawyer

A structured draft, not reviewed or approved by a qualified legal professional. Highlighted items need real decisions before this is relied on.

This policy forms part of the Terms of Service and applies to everyone using CIAN and this website. It exists so the boundaries are written down rather than improvised, and it is written to be short enough to actually read.

1. The general rule

Do not use CIAN to do something illegal, to harm other people, to attack systems you have no right to touch, or to interfere with CIAN working for anyone else. Almost everything below is a specific case of that.

2. Do not use CIAN against systems you are not authorised to use

You may only point CIAN at code, repositories, infrastructure and accounts you own or are clearly authorised to work on. Specifically, do not use it to:

Security work done with authorisation — penetration testing under contract, research on your own systems, CTF and training environments, and building defensive tooling — is expressly permitted. The line is authorisation, not subject matter.

3. Do not use CIAN to harm people

4. Do not abuse the infrastructure

5. Do not abuse this website's support form

The support form is for genuine support requests. Do not use it to send advertising, bulk mail, or automated submissions, and do not attempt to bypass its anti-bot protection or rate limits.

6. Respect other people's rights

Do not use CIAN to infringe copyright, trademarks, patents or trade secrets, or to strip licence and attribution notices from code you do not own. You are responsible for the licence compatibility of code CIAN produces for you.

7. Reporting a problem

To report abuse, a security vulnerability, or content that breaches this policy, use the support form. For a suspected vulnerability, please describe the issue without including working exploit detail; we will follow up with a private channel.

Add a dedicated abuse and security contact address, and — if one is offered — a coordinated disclosure policy with response timelines.

8. What happens if you breach this policy

Depending on what happened and how serious it is, we may contact you, limit or suspend your access, remove content, or terminate your account. Where the law requires it, or where there is a risk to someone's safety, we may report the matter to the authorities.

We aim to warn first and act proportionately, but we may act immediately without warning where there is serious or ongoing harm. Confirm whether an appeals route is offered, and describe it here if so — some jurisdictions require one.

9. Changes

We may update this policy as new problems appear. The date above will change and material changes will be notified alongside changes to the Terms of Service.