Outis
Legal

Private is not permitted

Outis keeps no activity logs and never asks who you are. None of that makes an illegal use legal. This page is the acceptable use policy: what the service may not be used for, and what happens when it is.

Why this page exists

A service that keeps nothing on file gets asked one question more than any other: so can I do anything with it? The answer is no, and it is worth saying clearly rather than leaving it to be inferred.

Privacy has plenty of ordinary users. Journalists and their sources. People who do not want their home address in a public registry. Companies keeping a launch quiet. Security researchers. Programs that cannot complete an identity check. The design protects who they are. It does not protect what anyone does.

Not keeping a record of you is a promise about your identity. It is not a promise to look away.

What Outis may not be used for

Names, DNS and servers bought here may not be used, directly or as part of something larger, for:

Authorised security work is fine: testing your own systems, or systems whose owner has asked you to test them, is not an attack. Neither is running a Tor relay, a VPN for yourself, or a site that says things someone powerful dislikes.

The registry rules still apply. A name held in our name is still subject to its registry's policies, including trademark disputes under UDRP. Registering someone else's brand to trade on it can lose you the name no matter who is in the record.

How abuse is found without watching you

We do not monitor accounts, and nothing here changes that. There is no need to. Domains and servers are public by nature. A phishing page has to be seen by its victims to work, a malware host has to be reachable, and a spam source shows up on every blocklist it touches.

Reports come from registries, security teams, brand owners, blocklist operators, law enforcement, and people who landed on the page. When one arrives we look at the public thing reported: the page, the file, the traffic it sends. We do not look through your account for it, because there is nothing there to look through.

What happens when a rule is broken

We do not warn first on the clear cases (abuse material, live phishing, malware, active attacks). Because nothing identifies you, we cannot tell a first offence from a tenth, and we will not try.

Keeping no logs does not mean holding no data. The account cannot work without some. Here is all of it:

What does not exist: your legal name, address, phone number, card, documents, IP addresses, access logs, search history, or a record of what you looked at. A valid legal order can reach what exists. It cannot reach what was never written down, and we will not start writing it down for one account.

For programs and agents

Outis is built to be used by software, so this policy is written for software too. llms.txt, the file agents read before using the API, carries the same list at the top. An agent asked to register a name or order a server for any use on this page should decline the task rather than open an account for it.

A key acts for the account that issued it. Whatever an agent does with it counts as the account holder doing it.

Common questions

If nothing is logged, can I use it for anything?

No. Not logging protects who you are; it does not make anything legal. Phishing, malware, fraud, abuse material, spam, attacks on other people's systems and the rest of the list on the acceptable use page are not allowed, and an account used for them is closed.

Privacy is the product. Cover for crime is not, and it is not what the price pays for.

What happens when a name or server is reported for abuse?

We look at the thing reported, which is public by nature: a phishing page, a malware download or a spam source is visible to anyone. If it breaks the rules, the name or server is suspended or removed and the account can be closed.

We do not need to watch accounts to do this, and we do not. Abuse on the open internet announces itself.

What do you log?

Activity is not recorded. There is no history of what you searched, what you resolved, or what you pointed a record at — which means there is no such history to leak, sell, or be compelled to produce.

What necessarily exists is the account itself: the email it was opened with, the ledger of deposits and purchases that makes up its balance, and the names and servers on it. The legal page lists all of it.

Keep reading

Nothing on file. Nothing to leak.

An email you invent, a password, and crypto. That is the entire relationship.

Get started → Quickstart No invite, no waitlist. Acceptable use applies.