Policies · Acceptable use
Acceptable use policy
GPUFarm runs customer code on hardware owned by independent hosts. To keep that safe for both sides, these workloads are prohibited — for customers who submit them and for hosts who knowingly run them.
Prohibited workloads#
| Not allowed | Includes |
|---|---|
| Unauthorized cryptocurrency mining | Miners (xmrig, ethminer, nbminer, t-rex, lolMiner…), stratum pool connections, hashing for any chain on rented GPUs. |
| Password and credential cracking | hashcat, John the Ripper, hydra or custom brute-forcing of hashes, keys or logins you don't own. |
| Credential theft and data exfiltration | Harvesting secrets, tokens, cloud metadata endpoints or other users' data; probing the host for keys. |
| Malware, ransomware and botnets | Building, testing against real targets, or operating malicious payloads; command-and-control, reverse shells, bot operation. |
| Network attacks and scanning | DoS/DDoS, port or vulnerability scanning (masscan, nmap, zmap), exploitation of third-party systems, spam. |
| Sandbox escape and illicit access | Attempts to break out of the container, reach the host, its LAN or other jobs, or bypass the network policy. |
| Illegal content | Generating or processing child sexual abuse material, non-consensual intimate imagery, or any content illegal where the host or customer operates. |
| Rights violations and deception at scale | Workloads designed to infringe intellectual property, impersonate real people without consent, or run fraud and influence operations. |
| Interfering with the network | Spoofing GPU hardware or benchmarks, faking telemetry or results, manipulating reputation, or abusing the escrow and dispute process. |
Security research
Benchmarking, fuzzing your own software and training models on security data are fine. Attacking, scanning or cracking anything you don't own or aren't authorized to test is not.
How it's enforced#
- Before funding: every job spec passes the workload policy — banned images and digests, miner/cracker/scanner signatures in the image name, command and environment, privilege requests and LAN egress are rejected or held for review.
- While running: containers have no network by default, no privileges and only their reserved GPUs; allowlisted egress reaches only the hosts the job named.
- After the fact: telemetry, logs and reports are reviewed; images can be banned by digest or reference, GPUs and machines flagged, and accounts suspended. Admin actions are audit-logged.
- Hosts can decline workload types they don't want with their machine policy — a declined type is never offered to them.
Reporting abuse#
Signed-in users can report a job or a machine from its page. Reports go to the GPUFarm admin queue with the category you choose:
| Category | Covers |
|---|---|
| Unauthorized crypto mining | Mining software, pool connections or wallet addresses. |
| Credential theft | Reading secrets, keys, metadata endpoints or other users' data. |
| Malware | Known malicious software or payloads. |
| Botnet / remote control | Command-and-control, reverse shells, bots. |
| Password cracking | Hashcat, John the Ripper, brute-force tools. |
| Network attack or scanning | DoS, port scans, exploitation of third parties. |
| Illicit access | Escaping the sandbox, reaching the host or its LAN. |
| Something else | Anything else that breaks the acceptable-use policy. |
Hosts: if a job on your machine looks malicious, report it from your host dashboard. Nothing is suspended automatically on a report alone; an administrator reviews logs, telemetry and the job spec first.
Consequences#
- The job is stopped and its image may be banned network-wide.
- A customer harmed by a host breaking this policy can dispute the job during its challenge window; the arbiter can return the escrow to the customer.
- Accounts, machines and farms involved can be suspended; illegal activity may be reported to the relevant authorities.