Customers must have authority to configure and protect each domain, origin, DNS zone, and network resource added to the service.
Using Hexa Shield to conceal or facilitate unauthorized access, malware delivery, credential theft, phishing, or exploitation of systems you do not own or have permission to test.
Using protected domains to distribute unlawful content or operate services prohibited by the applicable hosting, network, registrar, or payment-provider terms.
Intentionally overwhelming Hexa Shield, upstream providers, customer origins, or third-party services with abusive traffic.
Attempting to bypass tenant isolation, authentication, billing entitlement, API-key scope checks, or administrative access controls.
Submitting third-party registrar credentials to Hexa Shield unless a supported connector explicitly requests a scoped token or OAuth authorization.
The final production policy should include the operator's abuse-reporting address, enforcement process, jurisdiction-specific requirements, and any category-specific restrictions required by infrastructure or payment partners.