Abuse policy
ViaductCDN serves privacy-focused websites. We don’t monitor traffic flowing through our edge — technically, we can’t, and that’s the entire point of running a Tor-native CDN. We don’t currently perform any proactive scanning of uploads either; when we do, it will be limited to hash-matching against catalogued known-bad content (see “Proactive scanning” below). We act on specific, evidenced reports of content that violates this policy. This page explains what we’ll act on, what we won’t, the planned scope of upload-time scanning, how reports are handled, and how site operators can appeal.
The site is accountable; the operator can be anonymous. We act on a site_id, not on a person. A crypto-paying tenant (BTC or XMR) we’ve never identified can still have a site suspended for clear policy violations. Their identity is none of our business, but their content is.
What we will act on
- CSAM (child sexual abuse material). Site suspended on credible report pending verification. On confirmed match: account suspended (other sites by the same operator are pulled), matched content preserved for 90 days per 18 U.S.C. § 2258A(h), and a report filed with NCMEC.
- Direct, specific threats of violence against an identified person or group.
- Active malware distribution: drive-by exploits, credential phishing pages targeting third parties, command-and-control endpoints for active campaigns.
- Doxing: non-consensual publication of identifying information about private individuals (home address, government ID, workplace, contact details) where the publication appears intended to enable harassment or violence.
- Lawful orders from courts with jurisdiction over us. We comply with valid orders. We push back on orders that appear overbroad, sealed without justification, or issued by jurisdictions to which we have no nexus, and we publish aggregate transparency data annually.
What we will not act on
- Content you disagree with politically.
- Speech that is legally protected in the United States, even if it’s offensive or illegal in your jurisdiction.
- Reports without evidence. A URL alone is not a report; we need to be able to see what you’re reporting.
- Copyright complaints sent only to us. We are infrastructure; the operator is the publisher. Send DMCA notices to the operator first. We will forward valid complaints we receive, but we will not act as a primary takedown channel for copyright disputes.
- Requests to identify operators. We cannot reveal information we don’t have, and we will not seek information for the purpose of revealing it. See /security for the technical detail on what is and is not structurally hidden from us. Lawful orders compelling disclosure are processed through our registered agent.
Proactive scanning
We do not currently perform any proactive scanning of content hosted on ViaductCDN. Today, violations surface through reports. Nothing scans uploads as they arrive.
We intend to change that, narrowly, as a near-term priority. We plan to integrate hash-matching against three catalogued databases of known-bad content:
- PhotoDNA (Microsoft) — for known CSAM.
- StopNCII (SWGfL) — for non-consensual intimate imagery whose subjects have submitted hashes.
- GIFCT (Global Internet Forum to Counter Terrorism) — for terrorist content catalogued by member platforms.
Three limits matter as much as the commitment itself:
- Hash-matching only. No classification-based machine learning, no novel-content detection, no behavioral analysis. The matching looks for files that have already been catalogued by the operators of these databases. It does not make judgments about new material.
- Upload path, not serving path. Matching runs when a tenant uploads content to an origin we host on their behalf. We do not inspect requests in flight at the edge, and the Tor-native delivery posture described elsewhere on this page is unchanged.
- No timeline commitment. We’re saying this is a priority and that we intend to do it, not that it is shipping next quarter. We’d rather be late than ship something we cannot operate responsibly.
When the integrations land, action on a match will follow these rules:
- PhotoDNA / CSAM: site and account suspended immediately (the hash match is the confirmation), matched content removed from serving but preserved for 90 days per 18 U.S.C. § 2258A(h), and a report filed with NCMEC.
- StopNCII / NCII: immediate removal of the matched file and site suspension pending operator response.
- GIFCT: the match is forwarded to the operator with a 24-hour response window before further action. The underlying categorization is more contested than CSAM or NCII and warrants human review before automated suspension.
How to report
Submit a report via the form below. Include:
- The site_id or .onion address. If you’re reading this with a prefilled site ID, you pulled it from the X-Viaduct-Site-ID response header on the offending site.
- A short description of the violation and which policy clause it falls under.
- Evidence: screenshots, archive.org links, specific URLs.
- Optionally, your contact information. Anonymous reports are accepted but we cannot reply or follow up on them.
What happens after
Reports enter a triage queue, reviewed during US business hours. Possible outcomes:
- Dismissed: the report doesn’t show a policy violation. No action; reporter is notified if they left contact info.
- Forwarded to operator: for issues that appear remediable, we send the report to the operator with a 72-hour window to respond before further action.
- Site suspended: the hidden service stops publishing and clearnet returns HTTP 451 with a link to this policy. Effective within 60 seconds. Operator is notified through their portal.
- Account suspended: all sites belonging to the operator are suspended. Reserved for repeated violations or imminent harm.
Every decision is logged with the operator handling it, the timestamp, and the evidence reviewed. Logs are retained for 90 days.
Operator appeals
If your site is suspended, you can file an appeal from the portal. Appeals are reviewed in the same triage queue. We review appeals as promptly as initial reports.
For crypto-only accounts (BTC or XMR): your prepaid balance is preserved through the appeal window. If suspension stands, you may withdraw the unspent balance to an address you control in the same currency after a 30-day cooldown.
What suspension does not do
- We do not delist suspended sites from search engines. Cached copies elsewhere on the internet are not under our control.
- We do not announce suspensions publicly. Aggregate counts appear in our annual transparency report; individual sites are not named.
- We do not retain content from suspended sites beyond what’s needed for the appeal window. Cache is flushed; configuration is retained for the 30-day soft-delete window per the standard lifecycle.
Transparency
We publish an annual transparency report covering:
- Total reports received, broken down by category.
- Action distribution (dismissed / forwarded / site-suspended / account-suspended).
- Lawful orders received and complied with, in aggregate.
- Median and 95th-percentile time-to-action.
We do not publish individual site IDs, operator names, or report contents. The report exists to demonstrate the policy is real and consistently applied.
Submit a report
Questions about this policy
Email support@viaductcdn.com. Press inquiries: press@viaductcdn.com. Legal service of process: registered agent listed in our terms of service.