Skip to main content

Keeping your server secure

You are. FlashRDP secures the hardware, network and virtualization layer. Inside the server, you’re responsible for updates, passwords, firewall rules and the software you install. See User responsibilities.
Set a long, unique Administrator password, install Windows updates, and change the Remote Desktop port. These steps block most automated attacks. See Secure your Windows RDP.
Update the system, sign in with SSH keys instead of a password, turn on a firewall such as ufw or firewalld, and only open the ports you use. See Connect over SSH.
Turn on two-factor authentication under Settings → Two-factor, use a password you don’t use anywhere else, and review Signed-in devices under Settings → Security from time to time. See Account security and 2FA.
Support never needs your server password, so never send it in a ticket or chat. A password reset in the Billing Portal shows the new password only to you, in your account. To be the only one who knows it, change it inside the server after you sign in.

If something goes wrong

  1. Open the Console from the server’s page and sign in, or reset the password first with Reset on the Overview tab.
  2. Look for unknown users, programs and scheduled tasks, and change all passwords.
  3. If you’re unsure the server is clean, restore a backup from before the problem, or reinstall and restore your data from your own copies.
  4. Open a ticket if you need help or if we contacted you about abuse.
Reply to the ticket quickly and fix the cause. A compromised server that attacks other networks or sends spam can be suspended to protect the network, and serious violations of the Acceptable Use Policy can lead to termination. You’re responsible for activity from your server, even if someone else broke into it.
Email abuse@flashrdp.com with the IP address, the time (in UTC) and evidence such as log lines or email headers. Customers can also open a ticket in the Abuse Desk.

What’s not allowed

The Acceptable Use Policy prohibits, among other things:
  • launching or helping with DDoS attacks, scanning other networks without permission, and running exploit or brute-force tools against others
  • spam, phishing pages and activity that gets our IP addresses blacklisted
  • malware, ransomware, botnet control servers, carding, identity theft and fraud
  • child sexual abuse material, which is reported to the authorities
Breaking these rules can lead to immediate termination without a refund. If an IP address is blacklisted because of your use, a $50.00 cleanup fee applies per address.
Legal business and personal workloads are welcome, including trading terminals and bots, web hosting, development, automation, blockchain nodes and game servers.Some activities are restricted and can get a server suspended or terminated: cryptocurrency mining, P2P sharing of content you don’t have rights to, open proxies, public VPNs and Tor exit nodes, unlicensed IPTV, aggressive scraping, and reselling servers. See Restricted Activities.If you’re unsure about a specific workload, ask the Presale Desk in a ticket before you deploy.
Yes. Scanning your own FlashRDP server is allowed. Scanning other networks needs the explicit written consent of their owner.

Acceptable Use Policy

Trust Center

Last modified on October 11, 2026