Acceptable Use Policy

Clear rules. Fair enforcement. Zero tolerance for abuse.

Our Commitment

The Trinity Beast Infrastructure serves developers, partners, and organizations worldwide. We operate with transparency, and we expect the same respect in return. This policy defines what we consider acceptable use, what constitutes a violation, and the actions we will take to protect our network and our community.

What We Monitor

Our automated threat detection system continuously monitors all activity. This is not surveillance — it is protection. We monitor patterns, not people.

  • Every API request: IP address, endpoint, frequency, response codes
  • Rate limit violations: per-key and per-IP tracking
  • Authentication failures: invalid keys, expired tokens, brute-force attempts
  • Network scanning: port probes, vulnerability scanners, path enumeration
  • Geographic anomalies: sudden changes in access location for a given key
  • Payload inspection: SQL injection, XSS, SSRF, and code injection attempts
  • WAF block patterns: repeated blocked requests from the same source
  • Honeypot endpoints: decoy paths that no legitimate user would access — any hit is immediate proof of scanning or malicious intent, and triggers automatic IP blocking after 2 attempts

Violations

The following activities are strictly prohibited. Any of these will trigger our escalation process.

🚫 Unauthorized Access Attempts

Attempting to access admin endpoints, internal APIs, or any resource you are not authorized to use. This includes path enumeration, directory traversal, and probing for hidden endpoints.

🚫 API Key Abuse

Sharing your API key with unauthorized parties, using a single key from multiple unrelated IP addresses simultaneously, or exceeding your tier's rate limits repeatedly after receiving warnings.

🚫 Vulnerability Scanning

Running automated vulnerability scanners, penetration testing tools, or security assessment software against our infrastructure without explicit written authorization.

🚫 Injection Attacks

Submitting SQL injection, cross-site scripting (XSS), server-side request forgery (SSRF), or any form of code injection in API parameters, headers, or request bodies.

🚫 Denial of Service

Any attempt to overwhelm, degrade, or disrupt our services through volumetric attacks, resource exhaustion, or coordinated request flooding.

🚫 Data Scraping Beyond Tier Limits

Systematically extracting data beyond your subscription tier's monthly allocation, or using automated tools to circumvent rate limits through key rotation or IP cycling.

🚫 Credential Theft Attempts

Attempting to access AWS metadata endpoints, environment variables, configuration files, or any system credentials through SSRF or path traversal techniques.

🚫 Impersonation

Using forged headers, spoofed IP addresses, or stolen API keys to impersonate another user or bypass security controls.

Enforcement & Escalation

We believe in fair warning before action. Our response is proportional to the severity of the violation. However, critical threats receive immediate action with no prior warning.

Severity Violation Type Our Response Timeline
MEDIUM Rate limit violations, minor key sharing Warning email sent with evidence. 48-hour grace period to correct behavior. Warning → 48h
HIGH Repeated violations after warning, vulnerability scanning, data scraping API key revoked. IP address blocked. Account suspended pending review. Immediate
CRITICAL Injection attacks, credential theft, DDoS, active exploitation Immediate IP ban. Key revoked. All associated accounts terminated. Evidence preserved for potential legal action. Instant — no warning

Autonomous Enforcement

Our enforcement is not manual. The Trinity Beast Infrastructure operates a 5-layer autonomous operations system (AutoOps) that detects, analyzes, and responds to threats in real-time — without human delay.

  • Honeypot hits trigger automatic WAF blocking after 2 attempts — no human review required
  • AI-powered threat analysis (Amazon Bedrock) correlates signals every 5 minutes and executes safe auto-actions
  • GuardDuty HIGH/CRITICAL findings trigger immediate automated response
  • Anomaly detection identifies unusual patterns that deviate from learned baselines
  • All autonomous actions are logged with full evidence and reported to the operator

The system does not sleep. It does not negotiate. It responds to actions, not intentions.

What We Record

When a violation is detected, the following evidence is automatically captured and preserved:

  • Your IP address and geographic location (city, country, ISP)
  • Full request details: method, path, headers, user-agent, timestamp
  • Your API key and associated account (email, name, tier)
  • Complete request history for the past 93 days
  • All IP addresses that have used your API key
  • Rate limit violation count and pattern analysis
  • WAF rule that triggered the block (IP Reputation, SQL Injection, etc.)
  • Network flow logs showing connection attempts and data transfer

This evidence is included in any warning email we send. You will see exactly what we see.

We Are Forgiving — But Firm

We understand that mistakes happen. A misconfigured script, a shared key you didn't know about, a testing tool that went too far — these things happen in development. That's why we warn first.

If you receive a warning and correct the behavior within 48 hours, your account remains in good standing. No record is held against you. We move on.

But if you ignore the warning, or if your actions are clearly malicious from the start — there is no second chance. We will protect our network, our subscribers, and the mission this infrastructure supports.

We do not judge people. We respond to actions. Our system is objective — it logs what you do, measures it against clear rules, and responds proportionally. The evidence speaks for itself.

If your access is terminated, your remaining subscription balance is refunded immediately. We don't keep your money and close the door — we close the door and hand you back what's yours. No debt owed in either direction.

The Trinity Beast is not a playground for creative mischief. The TBI exists to serve CPMP and the people we protect. Unfortunately, the TBI must protect itself. We do not judge who you are, but we will judge your actions when it comes to the TBI and CPMP.

100% of our revenue funds freedom from brick kiln debt bondage in Pakistan. We take the protection of this mission very seriously.

Questions or Disputes

If you believe you received a warning in error, or if you need to report a security concern, contact us. We review every response personally.

Contact Support