Home Service Catalog About Contact PinPoint Software Documentation
Account
My Profile Billing Portal Service Status

Acceptable Use.

Prohibited and restricted uses across all ESS services. Designed to be fair and rarely relevant to normal usage — these rules exist to protect our network, our IP reputation, and other customers.

Last updated: 3 June 2026  ·  Eastall Software Systems Limited

Overview

This policy sets out what you may and may not do across all ESS services. You are responsible for everything you run on, or send through, our infrastructure, and for the conduct of anyone you grant access to.

You must not use any ESS service for activity that is unlawful in New Zealand, in your own jurisdiction, or in any jurisdiction your service reaches. You must also comply with applicable export-control and sanctions regimes; we will not knowingly provide service to, or for the benefit of, parties named on the consolidated sanctions lists maintained by New Zealand, the United Nations, the United States (OFAC), the United Kingdom, or the European Union.

The following are prohibited on every ESS service, regardless of product or plan, and cannot be authorised under any circumstances:

  • Malicious software: hosting, distributing, or operating malware, ransomware, spyware, exploit kits, or botnet command-and-control infrastructure
  • Network attacks: launching or participating in denial-of-service attacks, unauthorised scanning or brute-forcing of systems you do not own, and IP spoofing
  • Child sexual abuse material: zero tolerance — such content is removed immediately and reported to the relevant authorities
  • Illegal and infringing content: pirated software, cracked applications, unlicensed copyrighted media, and any content that infringes the rights of a third party
  • Fraud and deception: phishing, carding, payment fraud tooling, and any service built to deceive or defraud

The product sections below set out the additional prohibited and restricted uses that apply to each service. The categories listed are representative but not exhaustive.

Eastall Cloud Services

Eastall Cloud Services (eCloud) gives you full root access to a virtual server, so you carry primary responsibility for everything that runs on it. In addition to the universal prohibitions above, the following applies to eCloud instances.

Restricted uses — prior written approval required. These uses are legitimate but carry a real risk to our network or IP reputation, so we need to know about them in advance. Please contact us before deploying any of the following:

  • Mail servers: ESS applies strict controls on outbound mail to protect our IP address reputation. To run a mail server you must have approval from someone in the ESS Core Team or higher and pay an additional $4.00/month per instance. Outbound SMTP (port 25) is filtered by default until approval is granted.
  • Public VPN, proxy, and Tor exit nodes: permitted for legitimate use but restricted, as they attract abuse complaints. Tor exit nodes in particular require approval; relay and bridge nodes are assessed individually.
  • Open public services: public DNS resolvers, NTP, memcached, and similar UDP services must be rate-limited and approved, as misconfiguration enables reflection attacks.
  • Adult content: lawful adult content may be hosted only with prior approval, and only where it complies with all applicable law and age-verification requirements.
  • High-volume outbound traffic: public file-sharing or large-scale media distribution should be discussed in advance so we can confirm it fits your plan's bandwidth allocation.

Fair use. Resources described as "unmetered" or "unlimited" are subject to fair use — usage consistent with the intent of your plan and not disproportionately impacting other customers who share infrastructure. The following are treated as abuse:

  • Sustained CPU utilisation above 90% for extended periods on shared infrastructure tiers
  • Cryptocurrency mining or proof-of-work hashing on shared tiers (a dedicated plan is required)
  • Storing data volumes disproportionate to the disk space allocated to your plan
  • Scripted activity designed to circumvent per-instance or rate limits
  • Reselling or sub-allocating eCloud resources as a competing hosting product without a written reseller agreement

Metered-bandwidth plans incur overage at $0.02/GB, with email notifications at 80% and 100% of your monthly allowance.

Eastall Panel

Eastall Panel (ePanel) is available at no cost and may be installed on any server you own or manage, including non-eCloud servers. Because ePanel only controls software running on your own machines, most of these rules concern how you use the panel itself rather than what you host.

The following uses of ePanel are prohibited:

  • Managing prohibited workloads: using ePanel to deploy, run, or manage any workload prohibited under this policy — the prohibition follows the workload, not the tool
  • Unauthorised access: using ePanel to access, control, or manage servers you do not own or have written authorisation to manage
  • Reverse engineering and redistribution: decompiling, reselling, or redistributing the panel itself, or removing or obscuring its licensing
  • Limit circumvention: scripting around the per-installation process model (up to 50 PM2 processes per installation) or otherwise bypassing built-in resource limits

Automated use of the ePanel API must stay within the published rate limits. Managing servers on behalf of clients is permitted, provided each underlying workload complies with this policy. If you operate ePanel at scale and expect to approach its limits, please contact us to discuss.

Eastall Authentication

Eastall Authentication (eAuth) issues and verifies identity on your behalf, so misuse can directly affect your end users and the trust they place in your application. The following uses of eAuth are prohibited:

  • Deceptive applications: registering applications that impersonate another organisation, or using eAuth to power phishing or credential-harvesting flows
  • Synthetic authentication: bot-driven or automated authentication requests, including any activity intended to inflate usage figures or circumvent the Free tier's monthly request cap
  • Gating prohibited services: using eAuth to authenticate access to any service that is itself prohibited under this policy
  • Data misuse: harvesting, reselling, or otherwise misusing user data obtained through eAuth, or using it for purposes the user did not consent to

Application, redirect URI, and custom-domain allowances are subject to your plan and to fair use. Genuine high-volume use is supported on the Developer and Enterprise tiers — please contact us if you expect sustained volume so we can recommend the right plan.

PinPoint by ESS

PinPoint by ESS is a worksite management tool, not general-purpose file storage. Content and uploads should relate to legitimate worksite management. The following uses are prohibited:

  • Unrelated or unlawful content: uploading unlawful or infringing material, or storing content unrelated to worksite management as a way of using PinPoint for general file hosting
  • Privacy breaches: collecting or storing personal information in a manner that breaches applicable privacy law, including images of identifiable people captured without a lawful basis
  • Limit circumvention: creating duplicate accounts or scripting activity to bypass per-tier worksite, floor, pin, or export limits

Floor plan and worksite images must be in a supported format (JPEG, PNG, or WebP) and within the per-file size limit. Worksite data is retained for the duration of your active subscription. If your worksite management needs exceed what PinPoint is designed for, please contact us to discuss the options available.

Enforcement

For most fair-use or restricted-use concerns, we will contact you at your registered email address to discuss a resolution before taking any action. If usage can be brought within acceptable limits, no further action is taken.

For serious violations — active attacks, child sexual abuse material, malware distribution, or any activity that places our network, other customers, or third parties at immediate risk — we may suspend the affected service immediately and without prior notice, and where required by law we will report the activity to the relevant authorities.

Where usage cannot be brought within acceptable limits, ESS reserves the right to throttle, suspend, or terminate the affected service in accordance with our Terms of Service. If you require an exception for a legitimate workload, please contact us to discuss your options.