Authfu

Policies

Acceptable Use Policy

What you may not build on Authfu, and what happens when someone does it anyway.

Last updated

01Why this policy exists

An authentication provider is an attractive tool for phishing. A convincing sign-in page under someone else’s brand is exactly what a credential harvester needs, and Authfu makes convincing sign-in pages easy to create. This policy sets the boundary between a legitimate application and abuse of that capability.

The basic rule

Use Authfu to sign people in to a service you operate or are authorized to represent. Do not use it to impersonate another service, collect somebody else’s credentials, or mislead people about who is asking them to sign in.

These rules apply to accounts, organizations, applications, API clients, uploaded content, and any other use of Authfu.

02Prohibited uses

Do not use Authfu for any of the activities below. Examples make the rules concrete, but they do not narrow them.

Impersonation and phishing

  • Do not imitate another company’s sign-in page or user experience.
  • Do not collect passwords, codes, passkeys, recovery information, or other credentials for a service you do not operate.
  • Do not use a name, logo, domain, or other brand asset that you have no right to use.

Illegal activity

  • Do not use Authfu for conduct that is unlawful in the United States or in the jurisdiction of the person using your application.
  • Do not facilitate fraud, theft, deception, or money laundering.
  • Do not evade sanctions, export controls, or other lawful restrictions.

Abuse of other people

  • Do not harass, threaten, stalk, or coordinate abuse against another person.
  • Do not publish private identifying information without permission, including for the purpose of intimidation or harm.
  • Do not distribute non-consensual intimate imagery.
  • Do not create, upload, distribute, solicit, or facilitate child sexual abuse material. We have zero tolerance for it. We will terminate the account immediately and report it to the appropriate authorities as required by law.

Attacking the service

  • Do not bypass or defeat rate limits or other technical safeguards.
  • Do not perform credential stuffing, enumerate accounts, or probe whether particular people have Authfu accounts.
  • Do not create accounts or registrations in automated bulk.
  • Do not attempt to access another account, organization, application, or tenant’s data.

Abuse of email

  • Do not use sign-in emails to deliver marketing, advertisements, or content unrelated to authentication and account security.
  • Do not deliberately trigger sign-in emails to addresses whose owners did not ask to sign in.

Authfu verifies a TOTP code before sending email when an account has two-factor authentication enrolled. That ordering exists in part to make deliberate email triggering harder. It does not make attempts to abuse sign-in email acceptable.

Malware and unlawful content distribution

  • Do not distribute malware, ransomware, spyware, destructive code, or instructions designed to compromise a device or account.
  • Do not use Authfu to gate, coordinate, or support the distribution of unlawful content.

Resale and misrepresentation

  • Do not resell Authfu as your own hosted authentication service.
  • Do not claim that Authfu sponsors, endorses, certifies, or operates your application unless we have agreed to that claim in writing.
  • Do not misrepresent your relationship with Authfu or Conversift, Inc..

03Avatars and uploaded content

Images you upload must not be illegal, hateful, sexually explicit, or infringe another person’s copyright, trademark, privacy, or other rights. You must have the right to upload and use them.

Authfu re-encodes avatars on upload. Re-encoding strips image metadata and defeats payloads hidden in the original image file. It does not excuse prohibited content or transfer responsibility for the image to Authfu.

04Handles

Handles have their own rules for allocation, reserved names, impersonation, and trademark claims. Read the Handle and Brand Policy. This policy still applies to everything you do with a handle.

05Automated and agent access

Automated access is permitted and expected. Applications and agents may use Authfu through supported interfaces with their own API keys.

  • Automated requests must stay within applicable rate limits.
  • Every automation must be attributable to a real Authfu account.
  • Do not share API keys, session tokens, or other credentials between people, accounts, or unrelated services.
  • You are responsible for activity performed with credentials issued to you.

06Security research

Good-faith security research is welcome when it follows the rules in our Vulnerability Disclosure Policy. Testing your own account, organization, and applications is fine. Testing another person’s account or data is not.

We will not threaten or bring legal action against good-faith researchers who follow that policy. Stop if testing could expose personal data, degrade the service, or affect another user, and report what you found through the security channel listed there.

07How this is enforced

We consider what happened, whether it is ongoing, the harm or risk to other people, and whether the account has violated these rules before. Our response may apply to one application or to the whole account.

SeverityTypical response
Low or readily correctedA warning and a reasonable chance to fix the problem.
Abuse limited to one applicationSuspension of that application while we investigate or while you correct it.
Serious, repeated, or account-wide abuseSuspension of the account and its applications while we review the conduct.
Severe or unlawful abusePermanent termination and, where required, a report to the authorities.

No warning for the clearest harms

Child sexual abuse material and active phishing campaigns skip straight to permanent termination without notice. Where required, we will also preserve evidence and report the conduct to the appropriate authorities.

We may use a stronger or narrower response when the facts call for it. A table cannot capture every abuse case, but it describes the enforcement path we expect to use.

08Appeals

If we warn, suspend, or terminate you and you think we got it wrong, email abuse@authfu.com. Include the account or application involved, the decision you are appealing, and any context or evidence we should consider.

A person will review the appeal. We will consider the original evidence, your response, and whether the enforcement action was proportionate. Review does not guarantee that we will reverse the decision.

09Reporting abuse

Tell us when an application appears to be abusing Authfu. Reports from users, brand owners, researchers, and members of the public help us act before more people are harmed.

Email abuse@authfu.com and include the application URL, what you observed, and when you observed it. Screenshots and relevant message headers are useful when available, but do not send passwords, authentication codes, private keys, or other secrets. We will acknowledge your report within one business day.