Scope
This Acceptable Use Policy (the “Policy”) applies to your use of Runzemi (the “Service”), operated by [[Company legal name, Inc.]] (“Runzemi”, “we”, “us”). It forms part of our Terms of Service (the “Terms”). If you violate this Policy, you violate the Terms. Capitalized terms that aren’t defined here have the meanings given in the Terms.
The Policy covers every job that runs on a runner provisioned for your account, whoever or whatever started it. You’re responsible for jobs triggered by your team members, collaborators, bots and automations, and by pull requests in the repositories you connect. If you connect public repositories, use GitHub’s workflow approval settings to control whether contributions from outside your organization can start jobs on your account.
If you become aware of a violation on your account, stop it and let us know at abuse@[[your-domain.com]].
Permitted use
You may use the Service to run continuous integration and delivery (CI/CD) workloads triggered through GitHub Actions, for repositories you own or are otherwise authorized to use. That includes compiling and packaging code, running tests and linters, building container images, running service containers, generating documentation, and deploying the software that the repository builds. Building and testing software for your clients is fine, as long as you’re authorized to work on their repositories.
Prohibited uses
You may not use the Service, or allow it to be used, for any of the following.
Cryptocurrency mining
Mining cryptocurrency, or running proof-of-work, proof-of-space or similar consensus workloads of any kind, at any scale. This includes “test” mining, joining mining pools, plotting, and mining as a side task inside an otherwise legitimate job.
Compute unrelated to your software
Runners are for the software development lifecycle of the repository that triggered the job. Don’t use them as general-purpose compute, including for:
- hosting websites, APIs or other long-running services, or keeping a job alive to serve traffic;
- game servers, proxies, VPNs, Tor relays or other traffic relays;
- bulk web scraping or crawling, or generating content for content farms or spam;
- media transcoding, rendering, data processing, or AI model training that isn’t part of building, testing or releasing the software in the repository;
- any workload whose main purpose is to obtain compute capacity rather than run CI/CD.
Compute-heavy work is permitted when it is genuinely part of building, testing or releasing that software – large builds, long test suites, end-to-end and browser tests, fuzzing or benchmarking your own code, or training and evaluating a model the repository itself ships.
Network abuse
- Denial-of-service attacks, traffic flooding, or load testing systems you don’t own or aren’t authorized to test.
- Sending spam or unsolicited bulk email, messages or notifications, or operating open mail relays or open proxies.
- Scanning ports, probing for vulnerabilities or brute-forcing credentials on third-party systems without their owner’s authorization.
- Forging packet or email headers, or otherwise disguising the origin of traffic.
- Generating fake clicks, accounts, reviews, votes or other engagement.
Malware and fraud
- Creating, hosting or distributing malware, ransomware or spyware.
- Hosting or operating command-and-control servers or botnets.
- Phishing, credential harvesting, or any other fraudulent or deceptive activity.
Illegal and infringing content
- Child sexual abuse material (CSAM). We have zero tolerance. We will terminate the account and report it to the National Center for Missing & Exploited Children (NCMEC) and to law enforcement as required by law.
- Content or activity that infringes or misappropriates intellectual property, including distributing pirated software or circumventing license controls.
- Collecting or processing personal data in violation of applicable law.
- Any other unlawful content or activity.
GitHub, law and safety
- Anything that violates GitHub’s Terms of Service or GitHub’s Acceptable Use Policies.
- Using the Service in violation of US export control or sanctions laws, including from a comprehensively sanctioned country or region, or by or for a person on a US government restricted-party list.
- Any activity that endangers the life, health or safety of others, or relying on a job in a way where a delayed, failed or cancelled run could directly cause injury or physical harm.
Protecting the Service
Unless we have given you prior written permission, you may not attack, probe or interfere with Runzemi, our service providers or other customers. That includes:
- attempting to escape a VM, reach its host, or keep a VM running or reuse it beyond the job it was created for;
- accessing instance metadata, credentials, tokens or networks that weren’t provided to your job, or using credentials provided to a job for anything other than that job;
- scanning, mapping or load testing our infrastructure, dashboard or APIs;
- attempting to access, observe or interfere with other customers’ jobs, VMs, logs or data;
- tampering with secret masking, log collection, usage metering or billing;
- reverse engineering the Service to bypass its security, limits or billing, except where applicable law expressly permits it.
Accounts, limits and resale
- Don’t circumvent spend caps, concurrency limits, funding checks or other limits on your account – for example, by splitting one workload across several accounts.
- Don’t create accounts to evade a suspension, termination or unpaid balance.
- Don’t resell, sublicense, rent or otherwise provide access to the Service to third parties, for example by offering runner capacity or CI minutes as your own product, without our written agreement. Running CI for client repositories you’re authorized to use is fine.
- Each person signs in with their own GitHub account; don’t share accounts.
Security research
You’re welcome to use the Service for security work on your own code and resources, such as fuzzing, dependency scanning, or testing systems you own or are authorized to test.
Research that targets Runzemi itself – our infrastructure, dashboard, APIs, runner environment or other customers – requires our prior written permission, which you can request at security@[[your-domain.com]]. If you discover a vulnerability, including during normal use of the Service, stop and report it to the same address with enough detail for us to reproduce it. When you do:
- act in good faith and do no more than is needed to demonstrate the issue;
- don’t access, modify or keep data that isn’t yours, and stop and tell us if you encounter any;
- don’t degrade the Service for others, and don’t use social engineering or physical attacks;
- give us reasonable time to fix the issue before disclosing it publicly.
If you follow these rules, we won’t treat your research as a violation of this Policy and we don’t intend to take legal action against you over it. We can’t authorize testing of anyone else’s systems, including GitHub’s.
Fair use of resources
Capacity is shared by everyone who uses the Service. We may limit your concurrency or throughput, delay new jobs, or cancel jobs that put unreasonable load on the Service or degrade it for other customers – for example, unusually large bursts of jobs, or jobs that saturate shared network resources. Where practical, we’ll contact you first and work with you on a fix. Cancelled jobs are not rerun automatically.
Enforcement
We aren’t obligated to monitor your use of the Service, but we may investigate suspected violations, including by reviewing job metadata, resource usage and logs. If we reasonably believe this Policy has been violated, we may:
- cancel running jobs;
- block new jobs from starting;
- suspend or terminate your account, in whole or in part;
- remove or disable access to content, including stored logs;
- report the activity to, and cooperate with, law enforcement, GitHub and affected third parties.
Where reasonable, we’ll give you notice and a chance to fix the problem first. For serious violations – including attacks, malware, CSAM, cryptocurrency mining, or activity that threatens the Service, other customers or third parties – and for repeated violations, we may act immediately and without notice.
Enforcement doesn’t cancel charges. Usage consumed before we act, including the time a cancelled job ran, is billed under the Terms.
If you believe we made a mistake, email support@[[your-domain.com]] with your account or organization name and why you think the action was wrong. We’ll review it and reply.
Reporting abuse
To report a suspected violation, including abusive traffic coming from a Runzemi runner, email abuse@[[your-domain.com]]. Include as much of the following as you can:
- what happened and when, with time zone;
- source IP addresses, URLs or repository names;
- relevant logs, headers or screenshots;
- how we can reach you.
Report security vulnerabilities to security@[[your-domain.com]] instead. We may not be able to tell you what action we took. We handle information in reports as described in our Privacy Policy.
Changes to this Policy
We may update this Policy from time to time. We’ll post the new version on this page and update the “Last updated” date above. For material changes, we’ll notify you by email or in the dashboard at least 30 days before they take effect. Changes needed to address new forms of abuse or security risks, or to meet legal requirements, may take effect sooner. If you keep using the Service after a change takes effect, you accept the updated Policy.