Acceptable Use Policy
The IT Dept Pty Ltd, trading as Underlay Networks. ABN 12 665 405 505
Why this exists
Underlay is built for networks, so we expect customers to run real infrastructure and generate real traffic. This policy is not an excuse to police ordinary network use. It exists so one customer cannot use the platform in a way that harms other networks, people or the service itself.
Use the service lawfully
You must not knowingly use an Underlay service to commit or facilitate unlawful activity. You are responsible for having the rights and permissions needed for traffic, content, addresses and routes you place on the service.
Do not attack networks
Do not use the service to deliberately compromise systems, distribute malware, run denial-of-service attacks, perform unauthorised access, or coordinate abusive scanning. Legitimate security testing is fine when you have authority to test the target and operate within any agreed network constraints.
Do not abuse addressing or routing
Do not knowingly advertise prefixes you are not authorised to originate, forge routing information to misdirect traffic, or use addressing supplied by Underlay outside the agreed service. We may apply route filters, RPKI-based policy, prefix limits or other controls that are reasonably necessary to protect network stability.
Messaging and unsolicited traffic
Do not use the service for unlawful spam, fraudulent messaging or other unsolicited communications that breach applicable law or repeatedly generate substantiated abuse reports. A compromised customer system is not automatically treated as intentional abuse, but we expect the customer to act when notified.
Voice
Do not present caller ID you are not entitled to use. Do not use voice services for autodiallers, telemarketing, call-centre or other high-volume outbound calling, or to generate artificially inflated traffic. Do not use voice services to make scam, nuisance or harassing calls.
Protect shared infrastructure
Do not deliberately interfere with Underlay equipment, facilities, monitoring, authentication, testing tools or other customers. Colocation customers must follow the relevant facility's safety, access and operational rules.
What happens when there is an abuse report
We will assess the report rather than automatically disconnecting a service because somebody sent an email. Where practical, we will give you enough information to investigate and a reasonable opportunity to address the issue.
Subject to mandatory emergency-calling, customer-safety, payment-assistance and complaint protections, for urgent threats, active attacks, legal obligations or serious risk to network stability, we may filter, rate-limit, isolate or suspend affected traffic or services first and contact you as soon as reasonably practical afterwards.
Repeated or serious abuse
If harmful conduct continues after reasonable notice, or if the conduct is deliberate and serious, we may suspend or terminate the affected service. We prefer the narrowest action that fixes the problem; taking down unrelated services is not the goal.
Security incidents
Tell us promptly if credentials, routing authority, customer portals or equipment relevant to an Underlay service are compromised. We will work with your technical contact on containment where our network is involved.
Fair use is not a hidden quota
Unless your order says otherwise, this policy does not create an undisclosed data cap or a vague right to punish a customer for using the capacity they bought. Capacity limits, shaping and committed rates belong in the service design and quote.
Reporting abuse
Send abuse or security concerns to hello@underlay.au with enough detail to identify the traffic or service. Time stamps, source and destination addresses, ports and logs are useful where applicable.
We may update this policy as threats, law and network practice change. Material changes will not be used as a backdoor to rewrite an agreed commercial capacity commitment.
Last updated 1 October 2026 · Version 2026-10-01.1