diff --git a/acceptable-use.mdx b/acceptable-use.mdx new file mode 100644 index 00000000..32dcf391 --- /dev/null +++ b/acceptable-use.mdx @@ -0,0 +1,132 @@ +--- +title: "Acceptable Use Policy" +description: "What is and isn't allowed on Kernel, including proxy fair use and platform abuse" +--- + +Last Modified: September 1, 2026 + +This Acceptable Use Policy ("AUP") governs your use of the Kernel platform and is incorporated into the [Terms of Service](/tos). It applies to everyone using Kernel, on every plan. If we say something here that conflicts with the Terms of Service, the Terms of Service control. + +## Our Principle + +**If a person may lawfully browse a site and take an action on it, their agent may too.** + +Kernel exists to let software do what people already do in a browser. We do not maintain a general list of approved use cases, and we do not require you to justify why your agent is visiting a site. What we prohibit is conduct that would be unlawful or abusive if a person did it by hand — automation does not make it acceptable, and it does not make it worse. + +Two limits sit on top of that principle: + +- **Third-party network policies.** Kernel's proxy networks are operated by upstream providers whose own policies restrict certain destinations. Those restrictions apply to you when you use a Kernel-provided proxy. See [Proxy Fair Use](#proxy-fair-use). +- **Your own agreements.** You are responsible for your relationship with the sites you visit, including their terms of use, their `robots.txt`, and any contract you have with them. Kernel does not evaluate or adjudicate those agreements on your behalf. + +## Prohibited Uses + +You may not use Kernel to: + +- **Break the law.** Violate any applicable law or regulation, or infringe anyone's intellectual property, privacy, or other rights. +- **Access accounts you are not authorized to use.** Credential stuffing, brute-forcing logins, session hijacking, or logging into accounts without the account holder's authorization. This does not prohibit using credentials you own, or that a user has authorized you to use on their behalf. +- **Attack or degrade infrastructure.** Denial-of-service attacks, traffic floods, port scanning, vulnerability exploitation against systems you do not own, or any request pattern designed to exhaust a target's resources rather than to use the site. This does not prohibit security testing against your own systems; testing against Kernel's is governed by our [Security Vulnerability Reporting Policy](/security-vulnerability-reporting). +- **Commit fraud.** Payment fraud, carding, money laundering, ad or click fraud, fake engagement, or impersonating a person or organization for deceptive purposes. +- **Farm accounts on other services.** Create, provision, verify, or sell accounts, seller storefronts, or identities on a third-party service in bulk, or in violation of that service's terms. This does not prohibit operating accounts you or your users legitimately hold. +- **Spam.** Bulk unsolicited messaging, posting, commenting, or form submission. +- **Handle prohibited content.** Child sexual abuse material, non-consensual intimate imagery, content that promotes terrorism or violent extremism, or material that facilitates the sale of illegal goods. +- **Resell the network.** Resell, sublicense, or relay Kernel's proxy capacity or browser infrastructure as a standalone proxy, VPN, or tunneling product. +- **Consume compute for its own sake.** Cryptocurrency mining, hash computation, proof-of-work, distributed computing, or any workload where the browser is incidental and the point is to consume CPU, GPU, or network capacity. See [Platform Abuse](#platform-abuse). +- **Take the platform without paying for it.** Multiplying free or trial credit across accounts, using payment instruments you are not authorized to use, or continuing to consume resources you have not paid for. See [Platform Abuse](#platform-abuse). +- **Evade enforcement.** Circumvent a suspension, rate limit, or restriction we have applied to your account, including by creating additional accounts or organizations. + +We also require compliance with U.S. export control and sanctions law. You may not use Kernel if you are located in, or acting on behalf of a party in, an embargoed jurisdiction or on a restricted-party list. + +## Platform Abuse + +The rules above are about how you treat other people's systems. These are about how you treat ours. Kernel gives every account real compute, real network egress, and free credit up front, deliberately and without gating it behind a sales call. That only works if it isn't farmed. + +### Compute must serve browsing + +Every session consumes real CPU, memory, and egress that Kernel pays for. Sessions are provided so you can browse and automate the web. You may not use them to run workloads that don't need a browser and exist to extract compute value: + +- Cryptocurrency mining or any in-browser miner, including WebAssembly and Web Worker miners and anything connecting to a mining pool. +- Hash computation, proof-of-work, key cracking, or brute-force compute of any kind. +- Distributed computing, rendering farms, or batch processing that happens to run inside a browser tab. +- Holding sessions open with no browsing activity in order to accrue runtime, including extending a session past its requested timeout by means other than genuine use. + +Heavy, legitimate browser work is fine. A page that pins a CPU because it is a real web application doing real work is not a violation. What we prohibit is using the browser as a wrapper around a compute job. + +### One account, one allocation + +Free and trial credit is a limited grant to evaluate Kernel, not an entitlement. One organization gets one allocation. You may not: + +- Create or operate multiple accounts or organizations to obtain more than one allocation of free or trial credit, or to exceed a plan limit on concurrency, sessions, or any other resource. +- Register accounts using address variations, aliases, disposable or relay email services, or other techniques whose purpose is to make one party look like many. +- Pace account creation, or coordinate accounts under common control, to avoid our abuse detection. + +Teams legitimately running separate organizations — for staging, for distinct products, for separate business units — are welcome and are not what this addresses. The test is whether the accounts exist to look like different customers than they are. + +We may require a verified payment method, a verified email domain, or reasonable identity or business verification before granting or continuing access to free credit, higher concurrency, or proxy capacity. + +### Payment + +- Use only payment instruments you are authorized to use. Using a stolen, misappropriated, or otherwise unauthorized card is fraud and will result in immediate termination and, where warranted, a report to the relevant issuer or authority. +- Do not use one payment instrument across multiple organizations to multiply plan entitlements. +- Do not attach a new payment method, change plans, delete an organization, or create a replacement organization in order to shed an outstanding balance or restore service without settling what is owed. Amounts you have incurred remain payable regardless of the state of your account. +- Do not initiate a chargeback for usage you actually incurred. Bring a billing dispute to us first — we will resolve honest ones. + +## Proxy Fair Use + +Kernel includes datacenter, ISP, residential, and mobile proxies at no additional charge. Bandwidth is not metered and not billed. + +**"Unlimited" means uncapped pricing, not uncapped capacity.** The proxies are provided so that your browser sessions can reach the sites they need to reach. In exchange, we ask for the following. + +### Fair use + +- Proxy traffic must originate from your Kernel browser sessions and be incidental to using them. Do not route external traffic through Kernel's proxy credentials or use a Kernel session as a general-purpose tunnel for other systems. +- Consumption should stay in a reasonable relationship to your browser usage. We may apply rate limits, or contact you to move to a [custom (BYO) proxy](/proxies/custom), where an organization's proxy bandwidth materially exceeds what its session activity would ordinarily require. +- Do not use proxies to obtain bandwidth-heavy content unrelated to browser automation — for example bulk media downloads, video streaming at scale, or torrenting. + +We would rather talk to you than throttle you. If you expect unusual volume, tell us in advance at [support@kernel.sh](mailto:support@kernel.sh) and we will plan capacity with you. + +### Restricted destinations + +Kernel's proxy networks are provided by third-party network operators. Those operators block certain categories of destination across their networks, and we pass those restrictions through to you. Requests to a restricted destination fail at the proxy layer; this is not a Kernel outage. + +Categories restricted by our upstream providers currently include: + +| Category | Examples | +|---|---| +| Government | `.gov` and country-specific government domains | +| Banking and financial services | Banks, brokerages, financial institutions | +| Payment processors | Card networks and payment service providers | +| National postal services | Country postal operators | +| Adult content | NSFW sites and services | +| Direct IP addresses | Requests to a bare IP rather than a hostname | +| Select e-commerce platforms | Evaluated by the provider case by case | + +This table is indicative, not exhaustive. Our providers maintain blocklists of thousands of domains, update them daily, and do not publish them in full. Treat it as a guide to what is likely to fail, not as a definitive list. + +**Nothing in the table above is prohibited by this policy.** These are destinations our proxy networks will not carry, not destinations you may not visit. The [Prohibited Uses](#prohibited-uses) above are the only limits this policy places on where your automation may go. + +Two things this restriction is **not**: + +- It is not Kernel's judgment about whether your use case is legitimate. Accessing a public government records site is lawful and ordinary; our residential network simply will not carry it. +- It is not a restriction on Kernel browsers. Restricted destinations are frequently reachable without a Kernel proxy — either directly or through a [custom proxy](/proxies/custom) you supply — and Kernel's browser-level anti-detection features work in both cases. If a destination is restricted, start there. + +### Custom (BYO) proxies + +When you supply your own proxy, your provider's policies apply instead of ours and you are responsible for complying with them. Everything in [Prohibited Uses](#prohibited-uses) still applies. + +## Enforcement + +If we believe you are violating this policy, we may rate limit your account, revoke API keys, terminate running sessions, restrict or revoke free and trial credit, suspend access to affected features, or suspend or terminate your account and any related accounts under common control. + +Where circumstances allow, we will contact you first and give you a chance to fix the problem. We may act immediately, without notice, where the conduct is illegal, actively harmful to a third party, involves an unauthorized payment instrument, or threatens the stability or economics of the platform — including the compute, account, and payment abuse described under [Platform Abuse](#platform-abuse). We may also act on a credible report or takedown request from a site operator, a network provider, or a regulator. + +Enforcement action does not relieve you of amounts already incurred, and we may pursue them. Where you obtained resources through a violation — farmed credit, mined compute, unpaid usage — we may invoice you for their value, forfeit remaining credit, and decline to serve you again. Terminating an organization and creating a new one does not clear either the balance or the enforcement. + +We do not monitor the content of your browser sessions. Enforcement is based on aggregate traffic patterns, resource consumption, billing and account signals, abuse reports, and the metadata described in our [Privacy Policy](/privacy). + +If you believe we have acted in error, reply to the notice we sent or email [support@kernel.sh](mailto:support@kernel.sh). We will look at it. + +## Reporting Abuse + +To report abuse of the Kernel platform, or to request that Kernel traffic be restricted from a domain you operate, email [security@kernel.sh](mailto:security@kernel.sh). Include the domain, the observed behavior, and timestamps where possible. We investigate every report and respond to the reporter. + +If you are a Kernel customer with a question about this policy or an enforcement action, use [support@kernel.sh](mailto:support@kernel.sh) instead. To report a vulnerability in Kernel itself, see our [Security Vulnerability Reporting Policy](/security-vulnerability-reporting). diff --git a/proxies/overview.mdx b/proxies/overview.mdx index 81a511e3..b29806c1 100644 --- a/proxies/overview.mdx +++ b/proxies/overview.mdx @@ -16,6 +16,10 @@ Kernel supports five types of proxies: Datacenter has the fastest speed, while residential and mobile are least detectable. ISP is a balance between the options, with less-flexible geotargeting. Kernel recommends using the first option in the list that works for your use case. + +Kernel-provided proxies are unmetered and not billed, subject to the fair use rules and restricted destinations in our [Acceptable Use Policy](/acceptable-use#proxy-fair-use). Some destination categories — including government, banking, and payment domains — are blocked by our upstream network providers and will fail at the proxy layer. Reach them directly or with a [custom proxy](/proxies/custom) instead. + + ISP proxies provide a **static exit IP that persists across sessions** — every browser session attached to the proxy exits through the same IP, and it only changes in rare ISP-initiated replacement events. This makes them suitable for IP allowlists or [managed auth](/auth/overview) health checks that must egress from a single IP. diff --git a/tos.mdx b/tos.mdx index 4a974bdf..38c0a3f5 100644 --- a/tos.mdx +++ b/tos.mdx @@ -1,13 +1,17 @@ --- title: "Terms of Service" --- -Last Modified: October 22, 2025 +Last Modified: September 1, 2026 PLEASE READ THIS MASTER SERVICES AGREEMENT (“AGREEMENT”) CAREFULLY BEFORE USING THE SERVICES OFFERED BY KERNEL TECHNOLOGIES, INC. (“COMPANY” OR “KERNEL”), A DELAWARE CORPORATION. BY CLICKING THE “SUBMIT” BUTTON, OR BY USING THE SERVICES IN ANY MANNER, YOU OR THE ENTITY YOU REPRESENT (“CUSTOMER”) AGREE THAT YOU HAVE READ AND AGREE TO BE BOUND BY THE TERMS AND CONDITIONS OF THIS AGREEMENT, TO THE EXCLUSION OF ALL OTHER TERMS. YOU REPRESENT AND WARRANT THAT YOU ARE AUTHORIZED TO BIND CUSTOMER TO THE TERMS OF THIS AGREEMENT. USE OF COMPANY’S SERVICES IS EXPRESSLY CONDITIONED UPON CUSTOMER’S ASSENT TO ALL THE TERMS AND CONDITIONS OF THIS AGREEMENT. IF THE TERMS OF THIS AGREEMENT ARE CONSIDERED AN OFFER, ACCEPTANCE IS EXPRESSLY LIMITED TO SUCH TERMS. THE “ORDER FORM” SHALL MEAN THE "CHOOSE A PLAN" PAGE ON THE KERNEL WEBSITE TO WHICH THE KERNEL SERVICES RELATE. IF YOU CANNOT OR DO NOT AGREE TO ALL TERMS AND CONDITIONS IN THIS AGREEMENT, YOU SHOULD NOT SELECT THE “SUBMIT” BUTTON BELOW AND YOU ARE PROHIBITED FROM ACCESSING OR USING THE KERNEL WEBSITE. THE PARTIES AGREE AS FOLLOWS: ## 1. Definitions **Affiliates** — means (a) an entity of which a party directly or indirectly owns more than fifty percent (50%) of the stock or other equity interest, (b) an entity that owns more than fifty percent (50%) of the stock or other equity interest of a party or (c) an entity which is under common control with a party by having more than fifty percent (50%) of the stock or other equity interest of such entity and a party owned by the same person, but such entity shall only be deemed to be an Affiliate so long as such ownership exists. +**AUP** — means Company's acceptable use policy, available at [https://www.kernel.sh/docs/acceptable-use](https://www.kernel.sh/docs/acceptable-use), as updated from time to time in accordance with Section 3.6. + +**Company-Provided Proxy Services** — means the proxy network access made available by Company as a feature of the Services, including datacenter, ISP, residential and mobile proxies, but excluding any proxy infrastructure supplied or operated by Customer. + **Customer Data** — means all data, information, and other materials submitted by Customer to the Services. **Documentation** — means any user guide, help information and other documentation and information regarding the Services that is delivered by Company to Customer in electronic or other form, available at [https://www.kernel.sh/docs](https://www.kernel.sh/docs), including any updates provided by Company from time to time. @@ -39,6 +43,9 @@ Customer acknowledges that the Services may require the reasonable cooperation o ### 2.7 Third-Party Integrations The Services may contain features designed to interoperate with services or applications operated or provided by third parties (“Third-Party Integrations”). To use such features, Customer may be required to obtain access to such Third-Party Integrations from their providers. Any exchange of Customer Data or other data between Customer and any third-party provider is solely between Customer and such third-party provider and is subject to such third party's terms. Company does not warrant or support Third-Party Integrations or services (whether or not they are designated by Company as being certified or otherwise).Company is not responsible for third-party integrations or their terms of use. +### 2.8 Company-Provided Proxy Services +Company-Provided Proxy Services form part of the Services and are made available at no additional charge, subject to the AUP, including its fair use provisions. Company provides Company-Provided Proxy Services over networks operated by third-party providers. The acceptable use policies and destination restrictions of those providers apply to Customer's use of Company-Provided Proxy Services and may be modified by those providers without notice to Company or Customer. Customer acknowledges that requests to destinations restricted by such providers will not be carried, and that such failures do not constitute a breach of this Agreement, a failure to provide the Services, or a service level event. Notwithstanding Section 2.4, Company may rate limit, modify, suspend or discontinue Company-Provided Proxy Services, in whole or in part and with respect to any individual Customer, where reasonably necessary to enforce the AUP, to comply with the requirements of a network provider, or to preserve the availability of the Services generally. Company-Provided Proxy Services, and any other feature of the Services that Company makes available at no additional charge, are provided “AS IS”, are excluded from any service level, uptime or availability commitment set forth in this Agreement or in any Order Form, and are subject to Section 6.4 in full. + ## 3. Proprietary Rights ### 3.1 Customer Data @@ -51,11 +58,14 @@ Customer agrees that Company is free to disclose aggregate measures of usage and Except for the limited rights and licenses expressly granted to Customer hereunder, no other license is granted, no other use is permitted and Company (and its licensors) shall retain all rights, title and interests (including all intellectual property and proprietary rights) in and to the Services, including all ideas, concepts, inventions, systems, platforms, software, interfaces, tools, utilities, templates, forms, techniques, methods, processes, algorithms, know-how, trade secrets and other technologies, implementations and information that are used by Company in providing the Services, and all Company trademarks, names, logos, all rights to patent, copyright, trade secret and other proprietary or intellectual property rights. Except for the limited rights and licenses expressly granted hereunder, no other license is granted, no other use is permitted and Customer (and its licensors) shall retain all rights, title and interest (including all intellectual property and proprietary rights) in and to Customer Data, which shall be deemed to be the Confidential Information (defined below) of Customer. ### 3.4 Restrictions -Except as expressly permitted in this Agreement, Customer shall not directly or indirectly (a) use any of Company's Confidential Information to create any service, software, documentation or data that is similar to or competes with any aspect of the Services, (b) disassemble, decompile, reverse engineer or use any other means to attempt to discover any source code of the Services, or the underlying ideas, algorithms or trade secrets therein, (c) use the Documentation for any reason other than in connection with the Services, (d) encumber, sublicense, transfer, rent, lease, time-share or use the Services in any service bureau arrangement or otherwise for the benefit of any third party, (e) copy, distribute, manufacture, adapt, create derivative works of, translate, localize, port or otherwise modify any aspect of the Services, (f) use or allow the transmission, transfer, export, re-export or other transfer of any product, technology or information it obtains or learns pursuant to this Agreement (or any direct product thereof) in violation of any export control or other laws and regulations of the United States or any other relevant jurisdiction or (g) permit any third party to engage in any of the foregoing proscribed acts. +Except as expressly permitted in this Agreement, Customer shall not directly or indirectly (a) use any of Company's Confidential Information to create any service, software, documentation or data that is similar to or competes with any aspect of the Services, (b) disassemble, decompile, reverse engineer or use any other means to attempt to discover any source code of the Services, or the underlying ideas, algorithms or trade secrets therein, (c) use the Documentation for any reason other than in connection with the Services, (d) encumber, sublicense, transfer, rent, lease, time-share or use the Services in any service bureau arrangement or otherwise for the benefit of any third party, provided that Customer may use the Services to provide Customer's own products and services to Customer's end users in the ordinary course of Customer's business, (e) copy, distribute, manufacture, adapt, create derivative works of, translate, localize, port or otherwise modify any aspect of the Services, (f) use or allow the transmission, transfer, export, re-export or other transfer of any product, technology or information it obtains or learns pursuant to this Agreement (or any direct product thereof) in violation of any export control or other laws and regulations of the United States or any other relevant jurisdiction or (g) permit any third party to engage in any of the foregoing proscribed acts. ### 3.5 Data Processing Addendum To the extent that, in connection with the Platform or Services, Customer provides any Customer Data that contains “Personal Data” from a European “Data Subject” that is subject to the European Union's General Data Protection Regulation, Provider's data processing addendum (“DPA”) available at [https://www.kernel.sh/docs/dpa](https://www.kernel.sh/docs/dpa) will apply. Any terms not defined in this Section 3.5 will have the meanings given to them in the DPA. +### 3.6 Acceptable Use Policy +Customer's use of the Platform and Services is subject to the AUP, which is incorporated into this Agreement by reference. Customer shall not, and shall not permit any third party to, use the Platform or Services in violation of the AUP. Company may modify the AUP from time to time to reflect changes in applicable law, the policies of its network providers, or the Services. Company may suspend, restrict or terminate Customer's access to all or part of the Services, including the Company-Provided Proxy Services and any free or trial credit, where Company reasonably believes Customer's use violates the AUP, and may take the same action with respect to any other account or organization under Customer's common ownership or control that Company reasonably believes was created or used to further the same violation. Except where the violation is unlawful, harmful to a third party, involves an unauthorized payment instrument, or threatens the stability, security or economics of the Platform, Company will provide Customer notice and a reasonable opportunity to cure before suspending access. Suspension or termination under this Section 3.6 does not relieve Customer of Fees or other amounts accrued prior to such action, and Company reserves all rights and remedies with respect to such amounts. + ## 4. Confidentiality ### 4.1 Confidentiality Obligations