Legal

Acceptable use policy

What you may and may not do with Apex Actions. Part of the terms of service.

Last updated

This policy is part of the terms of service. It says what the service is for and what it is not for. A job runs your code on a machine we operate, and most of what follows is the consequence of that one fact: what a job does, it does with our address and on our account with our providers, and what one tenant does can reach the next.

What the service is for

Continuous integration and delivery for your own projects: building, testing, checking, packaging and deploying software from repositories you have the right to run workflows on.

What you may not do

Use the machines for something other than CI. In particular you may not use a job to mine cryptocurrency, to run a general-purpose server, proxy, VPN or relay, to train or serve models as a workload in itself, to run distributed computing for its own sake, or to keep a job alive for the sake of the machine it is on. A build that happens to be heavy is fine; a workload that is a build in name only is not.

Attack anything. You may not use a job to scan, probe, flood, brute-force, exploit or otherwise attack any system — including ours, including your own without our written agreement, and including "testing" against another customer. Denial of service in any form, from any job, is a breach.

Reach for what is not yours. You may not attempt to access another customer's jobs, data, secrets or network; to break out of the isolation a job runs in; to reach the machine that runs it, the service that scheduled it, or the identity of either; or to interfere with how the service meters, limits or bills work.

Abuse the allowance. You may not circumvent plan limits or rate limits, share one subscription across organisations that are not yours, create accounts to gain repeated trials, or automate the creation of installations to distribute a workload across them.

Distribute what is unlawful or harmful. You may not use the service to build, host or distribute malware, to store or transmit content that is unlawful where you or we are, to infringe anybody's rights, or to send unsolicited messages.

Process what you are not entitled to process. You are responsible for having the rights and, where personal data is involved, the lawful basis for everything your workflows handle. You may not use the service to process data that the law forbids us from processing on your behalf.

Misrepresent. You may not use the service under a false identity, on behalf of an organisation you are not entitled to act for, or to impersonate anybody.

Outbound traffic

A job may make outbound network requests, and most builds do. You are responsible for that traffic: for having the right to reach what it reaches, for the rate at which it reaches it, and for what it sends. A job that a third party reports to us as abusive is a breach of this policy whether or not that was its purpose.

Secrets and credentials

A secret you give a job is provided to that job. You may not put into a job a credential you are not entitled to use, and you may not use a job to extract, exfiltrate or publish a credential that belongs to somebody else — including one the service itself holds.

What happens

We may suspend a job, a repository, an installation or an account that breaches this policy, as the terms describe, and we may end the agreement for a breach that cannot be cured. We will tell you what we found where we lawfully can. Where the law requires us to report something, we will.

Reporting

If a job on this service is reaching you in a way you did not ask for, or if you believe a customer of ours is breaching this policy, write to abuse@apexactions.com with what you saw. We answer within one business day.