Skip to content
Legal

Acceptable Use & Security

This policy sets out what is not permitted when using services provided by Qavex Technologies Private Limited, and how to report abuse or a security issue.

Draft pending legal review

This document is a working draft published for transparency while Qavex builds out its services. It is pending professional legal review and may change. It does not constitute a claim of any licence, certification or regulatory approval, and it does not replace a signed agreement where one exists.

Why this policy exists

Services operated for one client share infrastructure, reputation and network paths with services operated for others. Conduct that harms third parties tends to harm every other client on the same infrastructure, which is why these limits are enforced rather than merely stated.

Hosting services ordered through the HostDex brand are covered by the Acceptable Use Policy published on the HostDex website.

Not permitted

  • Anything unlawful under applicable law.
  • Sending unsolicited bulk email, or operating infrastructure that supports it.
  • Phishing, credential harvesting, fraud, or impersonating another person or organisation.
  • Distributing malware, ransomware or other harmful code.
  • Unauthorised scanning, intrusion attempts or denial-of-service activity against any system.
  • Infringing another party’s intellectual property rights.
  • Publishing or distributing child sexual abuse material — such material is reported to the authorities without notice.
  • Circumventing the access controls, quotas or security measures applying to a service.

Security of the systems we build and operate

Where Qavex builds or operates a system for a client, we apply access controls, patching and operational practices appropriate to that system, and the specifics are agreed in the engagement.

We do not claim any security certification, audit or accreditation that Qavex does not hold. If a certification is required for your procurement process, ask us and we will tell you honestly what we do and do not have.

Reporting abuse

If a service operated by Qavex is being used for spam, phishing, malware, scanning, denial-of-service activity or anything else prohibited by this policy, please report it.

Include as much detail as you can: the address or hostname involved, timestamps with the time zone, log extracts, and a description of what you observed. A report with evidence can be acted on; a report without it usually cannot.

Reporting a security vulnerability

If you believe you have found a vulnerability in a Qavex system or website, report it to the registered email address on the Contact page and give us a reasonable opportunity to fix it before disclosing it publicly.

Please do not access, modify or delete data belonging to anyone else, and do not run tests that degrade a service for its users. Qavex does not currently run a paid bug bounty programme, and we will not claim otherwise.

How we respond

Reports are reviewed and acted on according to what the evidence shows and how serious the issue is. Responses range from notifying the client concerned, to suspending a service, to terminating it and reporting the matter to the authorities.

Where a service is suspended, we tell the client why, except where the law requires otherwise.

Company identification

Legal name
Qavex Technologies Private Limited
CIN
U66190MR2026PTC474640
Registered office
13th Floor, Q2, Innov8Plot No. GEN-4/1, Q ParcGhansoli, Navi MumbaiThane, Maharashtra - 400701