drift Docs
Start
What is Drift?
The tour, if you are new here.
Use cases
Whether Drift does your thing.
Getting started
Nothing to deployed, in one command.
Architecture
How a slice is put together.
What it costs
The free grant, four unit prices, two rules.
Build
Canvas
Static sites, same origin as your API.
Tools
Operate
Auth
Accounts, tokens and scopes.
Security
Boundaries, sandboxing and hardening.
Troubleshooting
Error codes
What went wrong, and what to do about it.
Legal
Acceptable use
What a slice may not be used for.
Data processing
The DPA, and every sub-processor.

Acceptable use

Every Drift account gets a slice that runs code, serves a website, makes outbound network calls, and can carry your own domain with a valid certificate on it. That is a useful thing to hand somebody. It is also a useful thing to hand an abuser, so this page says plainly what the platform may not be used for, and what happens when it is.

This is the whole policy. There is no second document somewhere with the real rules in it.

What you may not do

Deception. No phishing. No page impersonating another person, company or public body. No fake login screens, no fraudulent shops, no payment forms collecting details for someone other than the party named on them. This is the one we act on fastest, because a custom hostname with valid TLS in front of a copied login page is precisely the thing Drift makes easy.

Unsolicited mail. No bulk unsolicited email, no spam relay, no list-washing, and no sending on behalf of someone who did not ask you to.

Traffic laundering. No open proxy, no open relay, no anonymising service carrying other people's traffic, and no using a slice as an exit node for traffic you cannot account for.

Attacking other people. No denial of service, port scanning, credential stuffing, vulnerability scanning or intrusion attempt aimed at any host you do not own. Testing against your own slice is a different thing and it is welcome; it is covered by the disclosure policy.

Malware. No distribution, staging or command-and-control of malware, ransomware or botnets.

Unlawful content. Nothing unlawful under EU or Dutch law. Child sexual abuse material is reported to the authorities and the account is terminated immediately, with no notice period and no grace window.

Mining. No cryptocurrency mining, and no workload whose principal output is heat. This is not a moral position. A slice books a fixed amount of memory and shares a machine with other tenants, and a miner is a workload deliberately trying to consume everything within reach.

Working around the platform's limits. No attempting to escape the sandbox, reach another tenant, or evade your slice's quotas, except where the disclosure policy authorises it.

Farming the free tier. One free slice per account, and that is enforced in the database. Registering many accounts to collect many free slices is not a clever trick. It is the thing that ends the free tier for everybody.

Outbound traffic is open by default

A slice can currently call any public host. That is a deliberate default and the security page explains it, but it means the rules above about proxying, scanning and spam are the boundary rather than a firewall rule. Declaring an egress allowlist is good practice and it is not what we enforce this policy with.

What happens when we find something

We would rather fix a problem than end an account, and most reports are a misconfiguration rather than an intent. So, in order:

Situation What we do
Something looks wrong and you are reachableWe email you and ask, with a window to answer
Active harm to others, or no answerThe slice is suspended: it stops serving, and stops sending
Unlawful content, or repeat abuse after a suspensionThe account is terminated
Child sexual abuse materialReported and terminated immediately, no notice

A suspended slice keeps its exit

Suspension stops the slice serving traffic. It does not delete your data and it does not take away drift slice snapshot download. Whatever you built is still yours to take, including in the case where we have decided we do not want to host it. That holds until the account is terminated for unlawful content, which is the one case where we are not able to hand it back.

If you think a suspension was wrong, reply to the notice. One person reads that mailbox and a mistake on our side is worth a sentence to fix.

Reporting abuse

If something on ondrift.eu or a domain pointed at a Drift slice is doing any of the above, send it to info@ondrift.eu with ABUSE in the subject line. There is no dedicated abuse@ alias yet, so the subject line is what pulls it out of an ordinary inbox.

Include the URL or hostname, what you saw, and roughly when. A screenshot or the raw headers help. You do not need a Drift account to report anything, and you do not need to be the affected party.

Security vulnerabilities in Drift itself go somewhere different and get a different process: see reporting a vulnerability.

Changes to this policy

We will change this page as the platform changes, and the version in force is whichever one is published here. If a change narrows what is permitted in a way that affects something you are already running, existing accounts get notice by email before it applies to them.

Last updated 11 August 2026.

Data processing → · Security & trust →