Private is not permitted
Outis keeps no activity logs and never asks who you are. None of that makes an illegal use legal. This page is the acceptable use policy: what the service may not be used for, and what happens when it is.
Why this page exists
A service that keeps nothing on file gets asked one question more than any other: so can I do anything with it? The answer is no, and it is worth saying clearly rather than leaving it to be inferred.
Privacy has plenty of ordinary users. Journalists and their sources. People who do not want their home address in a public registry. Companies keeping a launch quiet. Security researchers. Programs that cannot complete an identity check. The design protects who they are. It does not protect what anyone does.
Not keeping a record of you is a promise about your identity. It is not a promise to look away.
What Outis may not be used for
Names, DNS and servers bought here may not be used, directly or as part of something larger, for:
- Child sexual abuse material, in any form, or anything that sexualises minors. There is no second chance on this one.
- Phishing and impersonation: pages built to look like a bank, a wallet, a login screen or a brand in order to take credentials or money.
- Fraud and scams: fake shops, investment and "recovery" schemes, fake support lines, romance and pig-butchering operations, carding.
- Malware: distribution, droppers, ransomware, and command-and-control for machines the operator has no right to control.
- Attacks on other people's systems: denial of service, booter and stresser services, credential stuffing, and scanning or exploitation without authorisation.
- Spam: bulk unsolicited mail, SMS or messaging, and the infrastructure behind it.
- Stolen data: selling or publishing breached databases, credentials, or other people's personal information, including doxxing.
- Illegal markets: trade in illegal drugs, weapons, or people.
- Threats and violence: extortion, harassment campaigns, and incitement to or promotion of violence or terrorism.
- Sanctions evasion and moving the proceeds of any of the above.
Authorised security work is fine: testing your own systems, or systems whose owner has asked you to test them, is not an attack. Neither is running a Tor relay, a VPN for yourself, or a site that says things someone powerful dislikes.
How abuse is found without watching you
We do not monitor accounts, and nothing here changes that. There is no need to. Domains and servers are public by nature. A phishing page has to be seen by its victims to work, a malware host has to be reachable, and a spam source shows up on every blocklist it touches.
Reports come from registries, security teams, brand owners, blocklist operators, law enforcement, and people who landed on the page. When one arrives we look at the public thing reported: the page, the file, the traffic it sends. We do not look through your account for it, because there is nothing there to look through.
What happens when a rule is broken
- The name is suspended or deleted, or its DNS is pulled.
- The server is stopped or removed.
- The account can be closed. Its API keys stop working when it does.
We do not warn first on the clear cases (abuse material, live phishing, malware, active attacks). Because nothing identifies you, we cannot tell a first offence from a tenth, and we will not try.
What exists, and what a legal order can reach
Keeping no logs does not mean holding no data. The account cannot work without some. Here is all of it:
- The email address you signed up with, and a hash of your password.
- The ledger: deposits (with their transaction hashes, which are public on-chain anyway) and purchases.
- The names, DNS records and servers on the account, and the names of its API keys.
What does not exist: your legal name, address, phone number, card, documents, IP addresses, access logs, search history, or a record of what you looked at. A valid legal order can reach what exists. It cannot reach what was never written down, and we will not start writing it down for one account.
For programs and agents
Outis is built to be used by software, so this policy is written for software too. llms.txt, the file agents read before using the API, carries the same list at the top. An agent asked to register a name or order a server for any use on this page should decline the task rather than open an account for it.
A key acts for the account that issued it. Whatever an agent does with it counts as the account holder doing it.
Common questions
If nothing is logged, can I use it for anything?
No. Not logging protects who you are; it does not make anything legal. Phishing, malware, fraud, abuse material, spam, attacks on other people's systems and the rest of the list on the acceptable use page are not allowed, and an account used for them is closed.
Privacy is the product. Cover for crime is not, and it is not what the price pays for.
What happens when a name or server is reported for abuse?
We look at the thing reported, which is public by nature: a phishing page, a malware download or a spam source is visible to anyone. If it breaks the rules, the name or server is suspended or removed and the account can be closed.
We do not need to watch accounts to do this, and we do not. Abuse on the open internet announces itself.
What do you log?
Activity is not recorded. There is no history of what you searched, what you resolved, or what you pointed a record at — which means there is no such history to leak, sell, or be compelled to produce.
What necessarily exists is the account itself: the email it was opened with, the ledger of deposits and purchases that makes up its balance, and the names and servers on it. The legal page lists all of it.
Keep reading
Domains
Register a name without ever stating who you are. No identity check, no card on file, and nothing of yours in the public…
Programs
Issue a key, quote a purchase, spend from credit. Domains, DNS and servers are all reachable by a program acting on your…
The premium
A commodity registrar sells a cheap first year with your identity attached and privacy as an upsell. This is a different…
Nothing on file. Nothing to leak.
An email you invent, a password, and crypto. That is the entire relationship.