Threadway

Acceptable Use Policy

Effective 25 June 2026 · Version 2026-06-25

This Acceptable Use Policy ("AUP") applies to everyone who uses Threadway (the "Service"). It is part of our Terms of Service. Threadway is built for authorized security testing; this policy exists to keep it that way. Violating it may result in immediate suspension or termination without notice or refund, and may be reported to law enforcement.

The core rule: only point the Service at systems you own or are explicitly, currently, and verifiably authorized in writing to test. If you do not have permission, you may not use Threadway against it — full stop.

1. Authorization is your responsibility

Before tunneling to, capturing interactions from, or delivering any payload to a target, you must hold explicit written authorization from the system's owner that covers the activity and the time window. You must be able to produce that authorization on request. Lack of authorization is the single most common form of abuse and is strictly prohibited.

2. Prohibited uses

You may not use the Service, or allow it to be used, to:

  • Conduct phishing, credential harvesting, or social-engineering against people or organizations who have not consented to the test, or host pages that impersonate brands or login portals to deceive real users.
  • Host, stage, distribute, or operate malware, ransomware, spyware, botnets, or command-and-control (C2) infrastructure, droppers, or exploit delivery aimed at parties you are not authorized to test.
  • Gain or attempt to gain unauthorized access to, disrupt, overload, or attack any system, account, network, or data you do not own or are not authorized to test (including denial-of-service).
  • Store, transmit, or distribute illegal content — in particular any child sexual abuse material — or content that is fraudulent, defamatory, or that infringes intellectual-property or privacy rights.
  • Send spam or unsolicited bulk messaging, or operate open relays or redirectors for spam, scams, or traffic laundering.
  • Harvest, sell, or expose other people's personal data without a lawful basis.
  • Circumvent or attempt to circumvent the Service's quotas, rate limits, authentication, billing, or abuse controls; resell or sublicense the Service without our written permission; or attack, probe, or reverse-engineer Threadway's own infrastructure.
  • Use the Service for cryptomining, proxy/VPN resale, or other resource abuse unrelated to authorized testing.
  • Violate any applicable law, regulation, or export control, or facilitate anyone else in doing any of the above.

3. About the capture and tunneling tools

Threadway's tunnels, request catchers, and out-of-band collectors (DNS, HTTP, SMTP, TCP, LDAP, and similar) are intended to capture interactions caused by your own payloads in your own authorized engagements — for example, confirming a finding on a system you are permitted to test. They are not to be used to intercept, collect, or redirect the data or traffic of unconsenting third parties.

4. Monitoring and enforcement

We do not actively inspect the contents of your tunnels in the ordinary course, but we may review activity and metadata to operate the Service, enforce this policy, and respond to reports or legal process. When we identify abuse — or a credible report of it — we may, at our discretion and without prior notice: kill active tunnels, disable subdomains or ports, suspend or terminate accounts, block addresses, preserve relevant records, and notify or cooperate with hosting providers and law enforcement.

5. Reporting abuse

If you believe Threadway is being used to harm you or others, report it to abuse@threadway.cloud with the tunnel hostname, subdomain, or URL, the approximate time, and a description. We review reports promptly and act on credible ones.

Terms of Service · Privacy Policy · Acceptable Use · Report abuse