Trust & Safety Policy

The rules that keep our network safe, how we enforce them, and how to report abuse

Last Updated: July 6, 2026

1. Our Commitment to a Safe Network

Bypass.io(“Company,” “we,” “us,” or “our”) operates a premium proxy network and white-label reseller platform, offering Residential (rotating), Static Residential (ISP), Datacenter, and LTE/Mobile proxies through our self-serve dashboard at dashboard.bypass.io. Our infrastructure exists to give legitimate businesses and individuals privacy, resilience, and reliable access to the open internet — not to enable harm.

This Trust & Safety Policy (the “Policy”) explains the conduct we prohibit on our network, how we detect and enforce against abuse, and how you can report it. It applies to every user, reseller, and downstream customer, and to all use of our website, dashboard, APIs, and proxy Services. This Policy supplements our Terms of Service, Privacy Policy, and any acceptable-use commitments referenced in them. Where this Policy and those documents overlap, they are intended to be read together; the stricter standard applies.

Capitalized terms not defined here have the meaning given to them in our Terms of Service. We may update this Policy from time to time; the “Last Updated” date above reflects the current version, and your continued use of the Services after an update constitutes acceptance of the revised Policy.

2. Guiding Principles

Everything in this Policy follows from a small set of commitments:

  1. Lawful use only. Our network may be used only for purposes that are legal in every jurisdiction that applies to you, your traffic, and your targets.
  2. Respect for others' rights. Privacy, security, intellectual property, and the integrity of third-party systems are not ours to give away, and they are not yours to violate using our Services.
  3. Proportionate, consistent enforcement.We match our response to the severity of the abuse — from a warning for a first, low-harm issue to immediate termination and reporting for serious crimes.
  4. Zero tolerance for the gravest harms.Some conduct — above all, child sexual abuse material — results in immediate termination and referral to authorities, without warning and without exception.

3. Prohibited Activities

You may not use the Services, and you may not permit anyone using your Account or reseller sub-accounts to use the Services, to engage in, facilitate, or conceal any of the following. This list is illustrative, not exhaustive: conduct that is comparable in character or harm is equally prohibited even if not named here.

3.1 Fraud and Financial Crime

  • Fraud of any kind, including payment fraud, chargeback abuse, advertising or affiliate fraud, click fraud, fake-account or fake-engagement schemes, and deceptive or pyramid/Ponzi-style solicitations.
  • Carding— testing, validating, or using stolen, generated, or otherwise unauthorized payment-card or bank-account data, and any related BIN testing or anti-fraud-evasion activity.
  • Money laundering, sanctions evasion, or any transaction designed to disguise the origin, ownership, or destination of unlawfully obtained funds.

3.2 Account and Credential Abuse

  • Account takeover (ATO)— accessing or attempting to access any account, system, or data you are not authorized to access.
  • Credential stuffing, password spraying, and brute-force attacks, or any automated attempt to guess, cycle, or validate login credentials against third-party services.
  • Trafficking in stolen credentials, session tokens, cookies, or personal data, or using such material obtained from breaches, phishing, or malware.

3.3 Abusive Messaging and Deception

  • Spam— unsolicited bulk messaging across any channel (email, SMS, social, forums, comments), including the creation or operation of accounts to evade anti-spam controls.
  • Phishing and social engineering, including the creation, hosting, or distribution of pages, forms, or messages that impersonate a person or brand to harvest credentials, payment data, or other sensitive information.
  • Impersonation of any person, entity, or of Bypass.io, and any misrepresentation of your identity, affiliation, or authorization.

3.4 Malicious Technical Activity

  • Malware and botnets— developing, hosting, distributing, or operating viruses, ransomware, spyware, remote-access trojans, command-and-control infrastructure, or botnet nodes, or routing any such traffic through our network.
  • Denial-of-service attacks, including DoS, DDoS, amplification, and any traffic intended to disrupt, degrade, or overload a third-party system, service, or network.
  • Intrusion and exploitation— vulnerability exploitation, unauthorized penetration testing, port or network scanning of systems you do not own or have written permission to test, or any attempt to circumvent another party's security controls.
  • Interference with our infrastructure, including attempts to overload, reverse engineer, or defeat the technical or abuse-prevention measures protecting the Services.

3.5 Unlawful or Rights-Infringing Data Collection

  • Scraping that violates the law or others' rights— automated collection that breaches applicable law, a site's enforceable terms, technical access controls, or data-protection and privacy rules, or that harvests personal data without a lawful basis.
  • Circumventing access controls such as authentication, paywalls, rate limits, or anti-bot measures on systems you are not authorized to access in that manner.
  • Building profiles of individuals or aggregating personal data in ways that violate privacy laws or the rights of the people concerned.

3.6 Child Sexual Abuse Material (CSAM) — Zero Tolerance

We have absolute zero tolerance for child sexual abuse material. The creation, possession, distribution, advertisement, solicitation, or accessing of CSAM, or any sexual exploitation of a minor, is strictly and unconditionally prohibited. Any Account implicated in such activity is terminated immediately and permanently, without notice and without refund. We report CSAM and related conduct to the National Center for Missing & Exploited Children (NCMEC) and/or the appropriate law-enforcement authority, and we preserve and provide relevant records as permitted or required by law. This is not subject to any warning, cure period, or discretionary review.

3.7 Hate, Violent Extremism, and Harm to Others

  • Hate and harassment— content or conduct that incites or promotes violence, hatred, or discrimination against individuals or groups on the basis of protected characteristics, or that targets, stalks, or harasses any person.
  • Violent extremism and terrorism— promoting, supporting, financing, or coordinating terrorist or violent-extremist organizations or acts.
  • Threats and exploitation— content that threatens, glorifies, or facilitates serious harm to people, including trafficking, exploitation, or non-consensual intimate imagery.

3.8 Intellectual-Property Infringement

  • Copyright and trademark infringement, including the distribution of pirated software, media, or counterfeit goods.
  • Theft of trade secrets or other proprietary or confidential information belonging to third parties.
  • Circumventing technical protection measures that safeguard copyrighted works, where doing so is unlawful.

4. Reseller and Downstream Responsibility

If you resell, sub-license, or otherwise provide access to the Services to your own customers, you are responsible for their conduct as if it were your own. You must:

  • impose acceptable-use terms on your customers that are at least as protective as this Policy;
  • maintain the ability to identify, contact, and suspend an offending downstream user promptly on our request;
  • cooperate with us on abuse investigations, including by relaying takedown or preservation requests without undue delay.

We may hold a reseller Account accountable for downstream abuse and, where necessary, suspend or terminate the entire reseller relationship to stop ongoing harm.

5. How We Detect and Enforce

5.1 Detection and Risk Controls

To keep the network safe without unnecessarily inspecting lawful traffic, we rely on a layered set of controls, which may include:

  • Identity and risk checks (KYC where applicable): at sign-up, top-up, or when risk signals warrant it, we may verify identity, payment, and business information and decline or limit high-risk Accounts.
  • Rate, volume, and abuse monitoring:automated systems watch for traffic patterns consistent with attacks, credential abuse, spam, or scanning — for example anomalous request rates, target concentration, or destinations known for abuse.
  • Abuse reports and upstream signals: complaints from third parties, our upstream proxy networks, hosting/CDN and anti-abuse partners, and our own tooling feed our review queue.
  • Payment and anti-fraud screening, including checks applied by our payment processor and anti-abuse/CAPTCHA providers.

We handle any personal data used for these purposes in accordance with our Privacy Policy and applicable law, and we design our controls to be proportionate to the risk being managed.

5.2 Enforcement Actions

When we identify a violation, we may take any one or more of the following actions, at our discretion and in proportion to the severity, intent, and recurrence of the conduct:

  1. Warning or request to cure— for lower-severity, apparently unintentional issues, we may notify you and ask you to stop and remediate.
  2. Rate limiting or blocking of specific traffic, targets, or destinations.
  3. Suspension of the Account, an affected product, or specific endpoints while we investigate.
  4. Termination of the Account and all Services for serious or repeated violations.
  5. Preservation and disclosure of relevant records where permitted or required by law, and referral to law enforcement.

For the gravest categories of abuse — including CSAM, live attacks, and serious criminal activity — we may skip warnings entirely and move directly to termination and reporting.

5.3 No Refunds for Abuse

Where an Account is suspended or terminated for violating this Policy or our Terms of Service, no refund or credit is due for any unused balance, traffic, or plan time, and any outstanding fees remain payable. This is consistent with the non-refundable nature of our prepaid balances and plans.

6. How to Report Abuse

If you believe our network is being used to harm you, your systems, or others, please tell us. Send abuse reports to [email protected]. To help us act quickly and accurately, please include as much of the following as you can:

  • the source IP address(es) you observed and the destination (domain, IP, or URL) that was targeted;
  • timestamps with the time zone or UTC offset, and the approximate duration of the activity;
  • the type of abuse (e.g., credential stuffing, scraping, spam, DDoS, phishing);
  • supporting evidence— relevant log excerpts, request headers, sample payloads, screenshots, or email headers;
  • the impact on you or your systems, and any request or reference number if this relates to an earlier report;
  • a way for us to contact you for clarification.

We review credible reports promptly and take proportionate action. Because of privacy and legal constraints, we may not be able to share the details or outcome of an investigation, but we do act on what we find. Please do not include unnecessary sensitive personal data in your report, and never send actual CSAM — describe it and report it directly to the appropriate authority (for example, NCMEC's CyberTipline in the United States, or your local law-enforcement or hotline) in addition to notifying us.

To report a security vulnerability in our own systems, contact [email protected] (see our Vulnerability Disclosure information).

7. Cooperation with Law Enforcement and Legal Process

We cooperate with law enforcement and respond to valid legal process. In particular:

  • We disclose account or usage information in response to a valid subpoena, court order, warrant, or equivalent legal demand, or where disclosure is otherwise permitted or required by applicable law.
  • We may preserve relevant records when we reasonably anticipate a lawful request or an ongoing investigation.
  • Where we have a good-faith belief that doing so is necessary to prevent imminent harm— such as a serious risk to a person's life or safety, or an active attack — we may proactively report information to the appropriate authorities.
  • For CSAM, we report to NCMEC and/or the relevant authority as described in Section 3.6, regardless of any other provision.

We evaluate each request against applicable law and, where appropriate, narrow overbroad demands and object to invalid ones. Nothing in this Policy requires us to take any action that would itself be unlawful. Law-enforcement and legal-process requests should be directed to [email protected].

8. Your Responsibilities

By using the Services, you agree that you will:

  • use the Services only for lawful purposes and in compliance with this Policy;
  • comply with all applicable local, national, and international laws, and with the terms and access controls of any system you connect to;
  • keep your Account credentials secure and promptly report any suspected compromise or unauthorized use;
  • respect the privacy, security, and intellectual-property rights of others; and
  • if you resell the Services, hold your downstream customers to standards at least as protective as this Policy (see Section 4).

9. Changes to This Policy

We may revise this Policy to reflect changes in our Services, the law, or the threats we face. We will post the updated version here and refresh the “Last Updated” date, and we will provide additional notice of material changes where appropriate. Continued use of the Services after an update means you accept the revised Policy.

10. Contact

Use the address that best fits your need:


By using Bypass.ioServices, you acknowledge that you have read and understood this Trust & Safety Policy and agree to abide by it in full.