Abuse policy
Last updated: 2026-09-01
## Position
HiddenIO indexes public information for transparency and research. We do not operate any of the
listed servers. Nevertheless, we do not want the index to be a vector for harm, and we act on
credible reports.
## What counts as abuse
Examples of reportable content include: configurations that appear designed to intercept or tamper
with traffic (e.g. hostile TLS setups); entries distributing malware; pages or sources hosting
non-consensual or illegal content; and any record whose publication infringes someone's rights.
## How to report
Use the [report form](/report) and choose the matching type (for example "abuse",
"malformed_config" or "source_issue"). Include the record link or ID and a factual description of
the problem. If you prefer email, see the [security page](/security) for contact channels.
## What happens next
Reports enter a moderation queue and are reviewed in order. Outcomes may include: deactivating the
record, retiring the source, or marking entries as suspicious. We may not be able to share detailed
conclusions, but every report is processed and audited.
## Boundaries
We cannot take down servers we do not operate, and we cannot verify every claim. For incidents that
require the operator of an actual server, contact that server's network provider — our index merely
records what was already public.