Zero-Tolerance Policy on Cybercrime

At 3NT, we enforce a strict zero-tolerance policy toward cybercrime, malicious activity, and any abuse of our infrastructure.

Abuse Prevention and Legal Cooperation


3NT Solutions LLP provides connectivity, dedicated servers, virtual
servers and colocation. Services are customer-managed. This page sets
out what we prohibit, how to report misuse of our infrastructure, and
how competent authorities should address legal process to us.

ACCEPTABLE USE


We do not permit our infrastructure to be used for:

  • Distribution of malware, or operation of command-and-control servers
  • Ransomware, phishing kits, spyware and trojans
  • Botnets and unauthorised remote access tooling
  • Hosting of stolen data, credentials or personal data obtained
unlawfully
  • Spam, mail bombing and unsolicited bulk messaging
  • DDoS attacks and stress-testing services
  • Cryptocurrency mining without prior written permission
  • Illegal content, including child sexual abuse material and material
connected to human trafficking
  • Any arrangement intended to frustrate detection or takedown
  • Any operation designed to evade detection or takedown, including so-called “bulletproof” hosting schemes

Confirmed violations result in suspension of the service concerned and,
where applicable, notification of the competent authorities.

HOW WE DETECT ABUSE


  • Behavioural scanning developed and maintained in-house
  • Integration with threat intelligence feeds, including OTX,
  • Abuse.ch and ThreatFox
  • Continuous network monitoring and anomaly detection
  • Manual triage by our Abuse and Compliance team
  • Regular updates of signatures and indicators of compromise from
  • public and commercial sources

REPORTING ABUSE


Send abuse reports to abuse@3nt.com.

To allow us to act, a report should contain:
  • The IP address concerned, and the port where relevant
  • Date and time of the activity, with the time zone stated explicitly (UTC preferred)
  • Log excerpts, headers or other evidence in plain text
  • A description of the activity observed

Reports without a timestamp and time zone frequently cannot be matched
to a customer and will be returned to the sender for clarification.

How the abuse channel works:

Messages to abuse@3nt.com are processed in real time and passed to the
customer responsible for the resource concerned, so that remediation
begins without waiting for a manual review cycle. Our Abuse and
Compliance team reviews the same reports in parallel.

One consequence of this design should be understood before you write to
us. Your report, including the address you send it from, reaches the
operator of the system you are reporting. If you need your identity
withheld from that operator, write to security@3nt.com instead and say
so, and we will pass on the substance of the report without your
details. For the same reason, legal process must never be sent to this
address. See the section on law enforcement below.

What happens next:

  • Reports are triaged within 24 hours.
  • Where a report is confirmed, we require the customer to remediate within 24 hours, or we suspend the service. For malware distribution, command-and-control activity and phishing, the remediation window is 3 hours.
  • Where the activity involves child sexual abuse material, we act immediately and without prior notice to the customer.
If a report has not been resolved and you wish to escalate, reply to the original message keeping the subject line intact, and ask for escalation to the Abuse and Compliance team lead.


COPYRIGHT AND TRADEMARK


Copyright complaints should be sent to abuse@3nt.com with the subject
line COPYRIGHT and must identify:

  • The work said to be infringed
  • The precise location of the material said to be infringing
  • Your contact details
  • A statement that you hold the rights concerned or are authorised to act on behalf of the rights holder
  • A statement, made in good faith, that the use is not authorised by the rights holder, its agent or the law

We forward valid complaints to the customer responsible and require
remediation. Where we act as a mere conduit for the traffic concerned
and do not host the material, we will say so and identify the correct
route where we are able to.

Where a customer submits a counter-notice, we will forward it to the
complainant.

Trademark complaints follow the same route and should carry the subject
line TRADEMARK, together with the registration number and jurisdiction
of the mark relied on.

THREAT INTELLIGENCE AND CERT COOPERATION


We work with threat intelligence organisations, national and sectoral
CERTs, and industry takedown coalitions. Notifications from recognised
organisations are acted on without requiring formal process.

We consume and act on notifications from, among others, Shadowserver, Spamhaus, abuse.ch and ThreatFox, and our network is registered for reporting with these organisations where registration is offered.

For organisations working an incident that touches our address space,
we can:

  • Confirm whether an address falls within our ranges, the service typ it belongs to, and whether it remains under the same assignment
  • Accept bulk and machine-readable notifications in the formats you already produce, rather than requiring your data to be reformatte for us
  • Act on a notification without waiting for legal process, where the finding is technical and the evidence is sufficient
  • Preserve material relevant to an investigation on request, before any order exists
  • Hold off suspension where premature action would compromise an operation already under way, and coordinate timing with you instead
  • Support sinkholing and coordinated takedown, including where the timing is set by another party
  • Act as a point of contact for a CERT or a competent authority working the same incident

Write to security@3nt.com. This address is read by a person, is not
processed automatically, and is not passed to customers. Use it where
the matter is sensitive, where timing matters, or where your findings
should not reach the operator concerned before you are ready.

Routine reporting can continue to go to abuse@3nt.com,
which is the faster path to remediation for ordinary cases.

If your organisation requires a named contact, a standing arrangement
or a non-disclosure agreement before sharing pre-publication findings,
write to security@3nt.com and we will put that in place.

LAW ENFORCEMENT AND JUDICIAL AUTHORITIES


Address all legal process to legal@3nt.com. This is the only channel
designated for legal process.

Do not send legal process to abuse@3nt.com. Messages to that address
are processed in real time and passed to the customer responsible for
the resource concerned. Correspondence sent there is not treated as
legal process, does not reach the legal team, and cannot be handled
with the confidentiality that legal process requires.

We accept requests by email. Where service by post is required by the
law of the requesting jurisdiction, please send a copy by email at the
same time so that preservation can be actioned without waiting for the
post.

Requests should be in English. Requests in other languages will be accepted where
accompanied by an English translation.

Required contents of a request:

  • The issuing authority, jurisdiction and the legal basis relied on Case or file reference
  • Signature of the issuing officer and, where the measure requires it, the judicial authorisation
  • The specific identifiers concerned: IP address, port where relevant, and date and time with the time zone stated explicitly
  • The categories of data sought, stated specifically
  • Whether the request is subject to a non-disclosure obligation, and the duration of that obligation
  • A return email address that we may reply to
Requests that identify only an IP address without a timestamp cannot be
executed, because addresses within our ranges are reassigned over time.

Preservation

Preservation requests are actioned on receipt, ahead of any substantive
review of the underlying order. Mark the subject line PRESERVATION. We
will preserve for 90 days and confirm by return. A single extension of
a further 90 days is available on request made before expiry.

Emergency requests

Where there is an immediate risk to life or serious physical harm, mark
the subject line EMERGENCY. Emergency requests are handled on a 24/7
basis, with a target response of 4 hours. State the nature of the
emergency in the body of the request. We may disclose limited data in
response to an emergency request where the law applicable to us permits
it, and we will require follow-up legal process afterwards.

What we can provide

On valid legal process from a competent authority, and to the extent
the data exists, is within our control and disclosure is permitted by
the law applicable to us, we may provide:

  • Subscriber information held on the account concerned
  • Records of the assignment of an IP address at a stated time
  • Preservation and, where separately ordered, imaging of a server

We do not operate traffic capture or flow collection on customer
traffic. Netflow, packet captures and similar traffic records do not
exist and cannot be produced under any order.

We are not able to provide the content of customer systems in response
to an informal request. Access to customer data at rest requires an
order that specifically authorises it.

Customer notification

We notify the customer concerned of a request relating to their
account, unless notification is prohibited by the order, by the law
applicable to us, or would create a risk of destruction of evidence or
harm to a person. Where notification is prohibited, state this in the
request and give the duration of the prohibition.

Response times

  • Acknowledgement of receipt: within 8 business hours
  • Preservation confirmed: within 24 hours
  • Substantive response: within 10 business days of a complete request

Every request is reviewed by a person, and every request is answered.
This includes cases where we hold no responsive data and cases where a
request cannot be executed as submitted. Where we cannot execute a
request, we say why and, where possible, explain what would allow us to
execute it.

DATA RETENTION


We can only disclose data that exists. The following applies to
services provided by 3NT Solutions LLP:

  • Customer account and identity records: retained for the duration of the contract and for 7 years afterwards, as required by accounting and tax law
  • IP address assignment records: 12 months
  • Authentication and access logs for our own management systems: 12 months
  • Traffic data: not collected. We do not operate netflow collection, packet capture or deep packet inspection on customer traffic.
  • Customer server content: not accessed or retained by us in the ordinary course. Customers manage their own systems.

Data outside these periods is not available, and a request for it will
be answered to that effect.

COMPLIANCE

We operate in accordance with the law applicable to us, including the
UK Computer Misuse Act 1990, the UK Data Protection Act 2018 and UK
GDPR, and, where applicable to the services concerned, Regulation (EU)
2016/679, Regulation (EU) 2022/2065 and Directive (EU) 2022/2555. We
also operate in accordance with the acceptable use policies of our
upstream providers and the data centres we occupy.

Last updated: July 16, 2026