Effective 25 June 2026 · Version 2026-06-25
This Acceptable Use Policy ("AUP") applies to everyone who uses Threadway (the "Service"). It is part of our Terms of Service. Threadway is built for authorized security testing; this policy exists to keep it that way. Violating it may result in immediate suspension or termination without notice or refund, and may be reported to law enforcement.
Before tunneling to, capturing interactions from, or delivering any payload to a target, you must hold explicit written authorization from the system's owner that covers the activity and the time window. You must be able to produce that authorization on request. Lack of authorization is the single most common form of abuse and is strictly prohibited.
You may not use the Service, or allow it to be used, to:
Threadway's tunnels, request catchers, and out-of-band collectors (DNS, HTTP, SMTP, TCP, LDAP, and similar) are intended to capture interactions caused by your own payloads in your own authorized engagements — for example, confirming a finding on a system you are permitted to test. They are not to be used to intercept, collect, or redirect the data or traffic of unconsenting third parties.
We do not actively inspect the contents of your tunnels in the ordinary course, but we may review activity and metadata to operate the Service, enforce this policy, and respond to reports or legal process. When we identify abuse — or a credible report of it — we may, at our discretion and without prior notice: kill active tunnels, disable subdomains or ports, suspend or terminate accounts, block addresses, preserve relevant records, and notify or cooperate with hosting providers and law enforcement.
If you believe Threadway is being used to harm you or others, report it to abuse@threadway.cloud with the tunnel hostname, subdomain, or URL, the approximate time, and a description. We review reports promptly and act on credible ones.