On Page Navigation
Last updated August 27, 2026
This Acceptable Usage Policy ("AUP") governs the use of all services, products, infrastructure, and systems provided by Cascadia Web Services, LLC, a Delaware limited liability company registered to do business in the State of Oregon ("Cascadia," "Company," "we," "us," or "our").
This AUP is incorporated into and forms part of our Terms and Conditions. Capitalized terms not defined here have the meaning given in the Terms and Conditions. Violation of this AUP is a material breach of the Terms and Conditions.
This AUP applies to you, to everyone you authorize to use the Services, and to your End Users. It applies whether you use the Services directly, through the client portal, through an installed Product, or as a reseller or white-label partner delivering services to your own customers.
We may update this AUP as legal requirements, platform rules, and abuse patterns change. The current version is always posted at cascadiawebservices.com/legal/acceptable-usage-policy.
"Customer Content" means any content, code, data, media, message, record, or material transmitted through, stored on, published via, or generated using the Services, regardless of who created it.
"End User" means any person or entity that accesses or benefits from the Services through you, including your employees, contractors, customers, website visitors, message recipients, and the clients of any reseller or white-label partner.
"Provider Policies" means the acceptable use, anti-spam, and content policies of any Third-Party Platform used to deliver the Services, including hosting infrastructure, email delivery providers, messaging carriers and registries, AI model providers, domain registrars, and marketplaces.
You must not use the Services, or permit the Services to be used, to:
violate any applicable law, regulation, court order, or governmental requirement in any jurisdiction that applies to you, to us, or to your End Users;
infringe or misappropriate any copyright, trademark, patent, trade secret, right of privacy, right of publicity, or other proprietary right;
publish, store, transmit, or link to material that is unlawful, defamatory, fraudulent, deceptive, harassing, threatening, or that incites violence or unlawful discrimination;
publish, store, transmit, or link to any material that sexually exploits or endangers a minor, or any material constituting child sexual abuse material, which will result in immediate termination and referral to law enforcement without notice;
publish, store, transmit, or link to non-consensual intimate imagery, doxxing material, or content that facilitates stalking or harassment of an identifiable individual;
operate a phishing site, credential harvesting page, fraudulent storefront, fake login page, technical support scam, or any other scheme designed to deceive users into providing money, credentials, or personal information;
distribute malware, ransomware, spyware, keyloggers, cryptominers, or any code designed to disrupt, damage, surveil, or gain unauthorized access to any system;
operate or facilitate a pyramid scheme, chain letter, illegal lottery or gambling operation, unlicensed money transmission or financial service, or any unregistered securities or investment offering;
sell or facilitate the sale of controlled substances, prescription pharmaceuticals without lawful authorization, weapons or weapon components where prohibited, counterfeit goods, stolen credentials or data, or any other unlawful goods or services;
violate any applicable export control law or sanctions program, or provide the Services to any restricted party;
misrepresent your identity, affiliation, or authority, including by impersonating Cascadia, any Cascadia employee, or any other person or organization;
violate any applicable Provider Policy.
You must not:
attempt to gain unauthorized access to any system, account, network, or data, whether ours, another client's, or a third party's;
probe, scan, or test the vulnerability of any system or network without our prior written authorization, or breach or circumvent any authentication, authorization, rate limiting, or security measure;
intercept, monitor, or capture data not intended for you, including through packet sniffing, session hijacking, or man-in-the-middle techniques;
launch or participate in any denial-of-service attack, amplification attack, brute-force attack, or credential stuffing campaign;
forge or manipulate headers, identifiers, IP addresses, or routing information to disguise the origin of any content or transmission;
operate an open relay, open proxy, anonymizing service, or Tor exit node on infrastructure we provide;
run cryptocurrency mining, distributed computing, or similar workloads on infrastructure we provide;
consume system resources in a manner that degrades performance for other clients, including through inefficient code, unbounded loops, uncontrolled crawlers, excessive database queries, or unmanaged background processes;
use hosting intended for a website as general-purpose file storage, a backup target, a media distribution network, or a torrent or file-sharing node;
scrape, crawl, or harvest data from any third-party website or service in violation of that service's terms, robots directives, or applicable law.
We may throttle, isolate, rate-limit, or suspend any workload that threatens the stability, security, or performance of shared infrastructure, with or without prior notice.
You are solely responsible for all Customer Content on any environment we host, whether placed there by you, your staff, your other vendors, your End Users, or your site visitors.
You are responsible for obtaining all licenses and permissions required for content you publish, including images, fonts, video, music, and code. You are responsible for the accuracy and legality of your own advertising, pricing, claims, and disclosures.
Where your site accepts user-generated content, comments, uploads, forum posts, or reviews, you are responsible for moderating that content and for responding to complaints about it. You must maintain a means for third parties to contact you regarding unlawful or infringing content.
We may remove, disable access to, or suspend any Customer Content in response to a valid legal demand, a facially valid notice of claimed copyright infringement, a credible report of unlawful content, a security threat, or a violation of this AUP. Our copyright policy and designated agent for notices under the Digital Millennium Copyright Act are published at cascadiawebservices.com/legal.
Repeat infringers will have their accounts terminated.
Email abuse damages sender reputation for every client on shared infrastructure and puts our provider relationships at risk. This section is enforced strictly.
You must have a lawful basis for every message you send. You represent and warrant that each recipient has been obtained lawfully and that you hold the level of consent required in that recipient's jurisdiction, including under the CAN-SPAM Act, Canada's Anti-Spam Legislation, the GDPR and UK GDPR, ePrivacy rules, and equivalent laws.
You must be able to produce, on request and within five (5) business days, evidence of consent for any recipient, including the date, source, method, and IP address of opt-in where applicable.
You must not send to any address obtained by purchase, rental, lease, trade, scraping, harvesting, appending, list brokering, guessing, or enumeration. You must not send to addresses obtained from a third party's list, from a prior business you acquired, or from any source where the recipient did not knowingly provide the address to you for the purpose in question.
Every message you send must accurately identify the sender, use truthful and non-deceptive headers, subject lines, and from-addresses, include a valid physical postal address where required by law, and include a functioning and conspicuous unsubscribe mechanism for all commercial messages.
You must honor unsubscribe and opt-out requests promptly and in all events within the period required by applicable law, and you must maintain and apply suppression lists across all campaigns and all sending domains.
Transactional email infrastructure is provisioned for transactional messages only, meaning messages triggered by and directly relating to a specific transaction or account action initiated by the recipient. Sending marketing, promotional, newsletter, announcement, or bulk content over transactional infrastructure violates our providers' policies and this AUP, and will result in immediate suspension of sending.
Marketing and bulk email must be sent only over infrastructure provisioned for that purpose, and remains subject to the consent requirements of Section 6.1.
Where we provision or support outbound business-to-business outreach, all recipients must have been obtained lawfully and, where the applicable jurisdiction requires prior consent for commercial electronic messages, must have provided it. You must not send unsolicited commercial email to recipients in any jurisdiction where doing so is unlawful, including to individuals in the European Economic Area and the United Kingdom absent a valid lawful basis.
You must not use deceptive sender identities, misleading subject lines, false reply-to addresses, or purpose-built lookalike domains to evade filtering. You must not distribute sending across domains, subdomains, or mailboxes for the purpose of evading volume limits, complaint thresholds, or reputation monitoring.
We may set and adjust sending limits, warm-up schedules, and throughput caps. We may suspend sending immediately, without prior notice, where complaint rates, bounce rates, spam-trap hits, blocklist entries, or provider notices indicate risk to our infrastructure, our sending reputation, or a provider relationship.
You are responsible for all costs and consequences of your sending practices, including damage to domain or IP reputation, blocklist listings, delisting efforts, provider account termination, and any fine or penalty imposed by a regulator.
Nothing in this AUP or elsewhere constitutes a guarantee of delivery or inbox placement. Deliverability depends on recipient mail servers, filtering systems, blocklist operators, engagement, and message content, all of which are outside our control.
Where you use our Products or Services to send SMS, MMS, or other messaging, you are the sender of record and bear full responsibility for compliance.
You must comply with the Telephone Consumer Protection Act, applicable state telemarketing and messaging laws, CTIA messaging principles and best practices, carrier requirements, and the rules of any messaging registry.
You must obtain and be able to evidence the level of consent required for each message category, which for marketing messages means prior express written consent. You must provide required disclosures at the point of opt-in, including the program name, message frequency, applicable message and data rates, and instructions for opting out and obtaining help.
You must honor STOP, UNSUBSCRIBE, CANCEL, END, and QUIT requests immediately, and must not send further messages to a number that has opted out other than a single confirmation.
You must not send messages relating to any category prohibited by carriers or registries, including high-risk financial offers, illegal substances, and other categories designated as prohibited from time to time.
Registration. Registration of a brand and campaign under 10DLC or any equivalent regime is your sole responsibility. We do not register campaigns on your behalf and make no representation to any carrier or registry regarding your consent practices, use case, or message content. Unregistered or misregistered traffic may be filtered, blocked, or subject to carrier violation fees, all of which are your responsibility.
You must not send messages through numbers, campaigns, or registrations belonging to Cascadia.
Where the Services include AI capabilities, automation, agents, or Model Context Protocol connectors, the following applies in addition to the rest of this AUP.
You must not use AI capabilities to:
generate content that violates Section 3, including deceptive, defamatory, harassing, or unlawful material;
generate or assist in generating malware, exploits, phishing content, or other material intended to compromise systems or deceive users;
impersonate a real person or organization, generate synthetic media of an identifiable individual without consent, or produce content designed to be mistaken for a genuine communication from a third party;
produce fabricated reviews, testimonials, endorsements, engagement, or user accounts;
make or materially inform decisions producing legal or similarly significant effects on individuals, including decisions regarding employment, credit, housing, insurance, education, healthcare, or access to essential services, without meaningful human review and any safeguards required by law;
provide medical, legal, financial, or other professional advice to third parties without appropriate qualification, review, and disclosure;
process any special category or sensitive personal data through a model provider without a lawful basis and our prior written agreement;
circumvent, disable, or attempt to defeat any safety system, usage policy, content filter, or rate limit imposed by a model provider, or to extract model weights, system prompts, or training data.
You must comply with the acceptable use policies of any model provider whose services are used to deliver the Services. Those policies apply to you directly and flow through this AUP.
Agent permissions and oversight. Where you authorize an AI system to take actions within your systems, you are responsible for the scope of authority you grant, the permission model applied, and the review of audit logs. You must not grant an agent broader access than the task requires, and you must not connect production systems containing critical or irreplaceable records without tested backups in place.
Automated volume. You must not configure automations, agents, retries, or loops in a way that generates uncontrolled volume against our infrastructure, a Third-Party Platform, or a model provider. You are responsible for all usage and charges generated by automations operating under your account, including charges resulting from misconfiguration or runaway processes.
Where you use the MCP Router or a similar gateway we provide:
credentials must be issued per individual user and must not be shared, embedded in shared configuration files, committed to source control, or distributed to third parties;
you must promptly revoke access for any person whose authorization has ended;
you must not use the gateway to proxy, resell, or provide access to connected tools or provider capacity to any party outside your organization, unless expressly permitted under a reseller or white-label agreement;
you must not attempt to access servers, tools, or provider credentials for which you have not been granted permission, or to enumerate the access held by other users or organizations;
you must not use the gateway to circumvent rate limits, quotas, or usage policies of any connected provider;
you are responsible for all activity conducted through credentials issued under your organization.
Provider credentials you supply are encrypted at rest and cannot be decrypted or retrieved by us. You must retain your own copies and must rotate any credential you believe may have been exposed.
You must not request, and we will not perform, any practice that violates a search engine's, platform's, or marketplace's published guidelines, including:
cloaking, doorway pages, hidden text or links, or serving different content to crawlers than to users;
participation in link schemes, private blog networks, paid links passing ranking signals, or automated link generation;
scraped, spun, or duplicated content published without material added value;
manipulation of business listings, including fake locations, keyword-stuffed business names, or listings for locations you do not operate;
creating, purchasing, incentivizing, exchanging, or soliciting for consideration any review, rating, or testimonial;
suppressing or filtering negative reviews in a manner that misrepresents overall sentiment, or misrepresenting the source or independence of any review;
publishing unsubstantiated performance, earnings, health, or outcome claims.
We will decline any instruction that would violate the Federal Trade Commission's rules on consumer reviews and testimonials, its endorsement guidance, or any platform policy, and doing so is not a failure to perform on our part.
You must not register, request registration of, or use any domain in bad faith, including domains that are confusingly similar to a third party's trademark, typosquatting or homograph variants, or domains registered for the purpose of resale to a rights holder.
You must provide and maintain accurate registrant contact information. Providing false registration data is a violation of ICANN policy and may result in domain suspension by the registry.
You must not use DNS records under your control to facilitate phishing, malware distribution, spam infrastructure, fast-flux hosting, or the impersonation of a third party.
If you resell the Services, deliver them under your own brand, or otherwise provide them to your own customers, you are responsible for the conduct of your End Users as if it were your own.
You must:
impose on every End User contractual obligations at least as protective as this AUP, and retain the contractual right to suspend or terminate an End User for violating them;
maintain a functioning abuse contact and respond to abuse reports we forward to you within twenty-four (24) hours;
monitor End User activity for abuse, including content complaints, spam complaints, malware indicators, and unusual resource or sending patterns;
investigate and remediate any violation we report to you, and confirm remediation to us in writing;
promptly suspend an End User where we require it, and provide End User identity and contact information to us where necessary to respond to a legal demand, abuse complaint, or security incident;
maintain records sufficient to identify which End User is responsible for any given site, mailbox, sending domain, phone number, or workload.
Where you fail to remediate an End User violation within the time we specify, we may suspend the affected service, or the entirety of your account where the violation is severe or systemic. You remain responsible for all fees, costs, and liabilities arising from End User conduct.
We do not routinely monitor Customer Content and have no obligation to do so. We do monitor infrastructure health, security telemetry, sending metrics, and usage patterns, and we may review Customer Content where necessary to investigate a suspected violation, respond to a complaint or legal demand, protect our systems or other clients, or comply with law.
We may preserve and disclose Customer Content and account information where we reasonably believe disclosure is required by law, necessary to respond to legal process, necessary to enforce this AUP or our Terms and Conditions, or necessary to protect the rights, property, or safety of Cascadia, our clients, or the public.
To report suspected abuse of the Services, contact us using the details published at cascadiawebservices.com. Please include the affected URL, domain, message headers, or other identifying detail, and a description of the issue.
We may take any of the following actions in response to a suspected or actual violation, in our sole discretion and in any order:
issue a warning and require remediation within a stated period;
remove, disable, or quarantine the offending Customer Content;
throttle, rate-limit, or isolate the affected workload or sending;
suspend the affected Service or the entire account, with or without prior notice;
terminate the Service or the account for cause without refund;
report the matter to a Third-Party Platform, registry, registrar, or law enforcement.
We will generally provide notice and an opportunity to remediate where the circumstances permit. We may act immediately and without notice where a violation presents an imminent risk to security, legal exposure, infrastructure stability, sending reputation, or the safety of any person, or where required by a Third-Party Platform or applicable law.
Suspension for a violation does not suspend your payment obligations, and no refund or credit is due for any period during which a Service is suspended or terminated for cause.
Responding to abuse consumes engineering time and frequently incurs third-party costs. Where we perform investigation, containment, cleanup, or remediation work arising from a violation of this AUP attributable to you or your End Users, we may charge for that work.
Chargeable remediation work includes, without limitation:
investigation and response to abuse complaints, legal demands, or infringement notices;
malware identification, removal, and hardening of a compromised environment;
restoration of a site or environment from backup following a compromise;
identification and containment of compromised credentials or accounts;
blocklist and reputation remediation, including delisting requests and provider escalations;
suppression list reconstruction, sending audits, and authentication reconfiguration following a spam incident;
response to carrier or registry violations, including messaging campaign remediation;
infrastructure work required to contain resource abuse or an attack originating from your environment;
engagement with a Third-Party Platform to restore a suspended account or service.
Remediation work is billed at our then-current published hourly rate, in minimum increments of one (1) hour, plus any third-party costs incurred, including provider fees, delisting fees, carrier violation fees, forensic tooling, and expedited support charges. Work performed outside standard business hours or on an emergency basis may be billed at our published after-hours rate.
We will notify you before commencing chargeable remediation where circumstances permit. Where immediate action is required to contain an active incident, protect our infrastructure, or comply with a legal or provider requirement, we may act first and invoice afterward.
Remediation fees are in addition to, and not in lieu of, any other remedy available to us, including suspension, termination, and indemnification under the Terms and Conditions.
We may update this AUP from time to time to address new services, legal requirements, provider policies, and abuse patterns. Material changes affecting active clients will be notified in accordance with the Terms and Conditions. Changes required to comply with law or a Third-Party Platform requirement may take effect immediately.
Your continued use of the Services after the effective date of any change constitutes acceptance of the updated AUP.
Cascadia Web Services, LLC
A Delaware limited liability company registered to do business in Oregon
Portland, Oregon, United States
Telephone: +1.800.610.3575
Web: cascadiawebservices.com