Legal

Abuse & DMCA

How to report abuse originating from our network, what to include, our response targets, and the process for copyright notices and counter-notices.

Version 2.1 Operator Squid Ventures LLC Jurisdiction State of Nevada, United States

We take reports seriously and we act on them. This page explains where to send a report, what we need in order to act, and what happens next.

1. Where to send a report

Report type Address Acknowledgment
Network abuse, spam, attack traffic [email protected] 1 business day
Copyright infringement [email protected] 2 business days
Security vulnerability in our systems [email protected] 2 business days
Child sexual abuse material [email protected] marked urgent Immediate
Law enforcement requests [email protected] 2 business days

Reports of child sexual abuse material are treated as the highest priority and are acted on without waiting for a customer response. Please also report such material to the National Center for Missing & Exploited Children or to the appropriate authority in your jurisdiction.

Our machine-readable security contact is published at /.well-known/security.txt in accordance with RFC 9116.

2. What to include

We can only act on reports that let us identify the traffic or the customer. Please include:

  • The IP address or prefix involved, and the destination address if relevant.
  • Timestamps including the timezone, ideally in UTC. This is the single most common omission, and without it we usually cannot correlate the report.
  • The protocol and port, where applicable.
  • Log extracts, headers, or packet captures that evidence the activity.
  • A description of the harm and, for ongoing activity, whether it is continuing.
  • Your contact details so we can ask follow-up questions.

Automated reports are welcome provided they contain the above. Please do not send reports that consist only of a summary count with no timestamps or addresses.

3. What happens next

  1. We acknowledge the report within the target above.
  2. We identify which customer is responsible for the address concerned.
  3. Where the activity originates with that customer directly, we require them to remedy it within a stated period, which is short for active attacks.
  4. Where the activity originates with one of their customers, we forward the report and require them to act, and we follow up if they do not.
  5. For ongoing attack traffic, we may filter or blackhole immediately while the report is investigated.
  6. We close the report and, where you have asked, tell you the outcome in general terms.

We do not disclose customer identities to reporting parties. We will confirm that a report has been actioned, and we will pass your contact details to the customer only with your agreement.

4. Why some reports take longer

We are a wholesale provider. Much of the address space we announce is assigned to customers who in turn serve their own customers, so resolving a report can require two or three hops through that chain. We push those escalations, and we suspend customers who do not respond, but the first response you receive may be an acknowledgment rather than a resolution.

If a report has not progressed within five business days, reply to the acknowledgment and ask for it to be escalated. Escalations are reviewed by a senior engineer.

5. Copyright notices

We respond to notices that comply with the Digital Millennium Copyright Act. Send notices to [email protected] or by post to our designated agent:

DMCA Designated Agent
Squid Ventures LLC
3960 Howard Hughes Parkway Paradise, #500
Las Vegas, NV 89169
United States

A compliant notice must include:

  1. A physical or electronic signature of the copyright owner or a person authorized to act for them.
  2. Identification of the copyrighted work claimed to have been infringed.
  3. Identification of the material claimed to be infringing, with enough detail for us to locate it, including a URL or IP address.
  4. Your name, address, telephone number, and email address.
  5. A statement that you have a good faith belief that the use is not authorized by the copyright owner, its agent, or the law.
  6. A statement that the information in the notice is accurate and, under penalty of perjury, that you are authorized to act on behalf of the copyright owner.

Because we operate at the network layer, we generally do not host the material identified in a notice and cannot remove individual files. What we can do is require the customer responsible to act, and suspend them if they do not. Where the material is hosted by a customer of a customer, we forward the notice down that chain.

6. Counter-notices

If material of yours was removed or disabled as a result of a notice and you believe it was removed in error or that the use is authorized, you may send a counter-notice to [email protected] containing:

  1. Your physical or electronic signature.
  2. Identification of the material and its location before removal.
  3. A statement under penalty of perjury that you have a good faith belief the material was removed as a result of mistake or misidentification.
  4. Your name, address, and telephone number.
  5. A statement consenting to the jurisdiction of the federal court for the district in which your address is located, or if outside the United States, of any district in which we may be found, and that you will accept service of process from the party who submitted the original notice.

We will forward a compliant counter-notice to the original complainant. Material may be restored after ten business days unless the complainant notifies us that they have sought a court order.

7. Repeat infringers

We maintain a repeat infringer policy. Customers who receive repeated well-founded notices and fail to address the underlying cause will have services suspended and, on continued failure, terminated. We expect our customers to operate an equivalent policy for their own users, and to be able to evidence it on request.

8. Law enforcement requests

Requests should be sent to [email protected] on official letterhead and should identify the legal authority relied on. We respond to valid legal process issued by a court or authority with jurisdiction over us.

We disclose only what the request lawfully requires. Where we are permitted to notify the affected customer, we do so, unless notification is prohibited or would risk harm. We do not provide access to customer traffic in the absence of valid legal process.

Emergency requests involving a risk to life may be made by telephone to our NOC on +1 (725) 444-8264 and should be followed in writing.

9. Security vulnerability reports

We welcome reports of vulnerabilities in our own systems and network. Send them to [email protected] with enough detail to reproduce the issue.

  • We acknowledge within two business days and aim to give an initial assessment within ten.
  • Please give us reasonable time to remediate before disclosing publicly.
  • Do not access, modify, or exfiltrate data belonging to us or our customers, and do not degrade service while testing.
  • Do not test customer infrastructure. Their systems are not ours to authorize testing against.
  • We will not pursue action against researchers who follow these guidelines in good faith.

We do not currently operate a paid bug bounty. We do acknowledge researchers who ask to be credited.

10. Reports made in bad faith

Submitting a knowingly false report, or using this process to harass a customer or to gain commercial advantage, is an abuse of it. We may decline to process reports from a party who has repeatedly submitted false reports, and knowingly material misrepresentation in a DMCA notice carries liability for damages under section 512(f) of that Act.

Contacting us about this document

Questions about this document should go to [email protected]. Written notice under it may be sent to that address or by post to:

Squid Ventures LLC
3960 Howard Hughes Parkway Paradise, #500
Las Vegas, NV 89169
United States

Questions before you sign?

Our team can walk your counsel or procurement team through any of these documents before a service order is raised.