> ## Documentation Index
> Fetch the complete documentation index at: https://flashrdp.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and Acceptable Use FAQ

> How to keep your FlashRDP server and account secure, what to do if your server is compromised, and which activities our Acceptable Use Policy doesn't allow.

## Keeping your server secure

<AccordionGroup>
  <Accordion title="Who is responsible for my server's security?" icon="user-check">
    You are. FlashRDP secures the hardware, network and virtualization layer. Inside the server, you're responsible for updates, passwords, firewall rules and the software you install. See [User responsibilities](/docs/terms/user-responsibilities).
  </Accordion>

  <Accordion title="What should I do first on a new Windows server?" icon="shield-half">
    Set a long, unique `Administrator` password, install Windows updates, and change the Remote Desktop port. These steps block most automated attacks. See [Secure your Windows RDP](/docs/security/rdp-security).
  </Accordion>

  <Accordion title="What should I do first on a new Linux server?" icon="terminal">
    Update the system, sign in with [SSH keys](/docs/control-panel/ssh-keys) instead of a password, turn on a firewall such as `ufw` or `firewalld`, and only open the ports you use. See [Connect over SSH](/docs/linux-vps/ssh-access).
  </Accordion>

  <Accordion title="How do I protect my FlashRDP account?" icon="lock">
    Turn on two-factor authentication under **Settings → Two-factor**, use a password you don't use anywhere else, and review **Signed-in devices** under **Settings → Security** from time to time. See [Account security and 2FA](/docs/account/security-and-2fa).
  </Accordion>

  <Accordion title="Does FlashRDP know my server password?" icon="eye-off">
    Support never needs your server password, so never send it in a ticket or chat. A password reset in the Billing Portal shows the new password only to you, in your account. To be the only one who knows it, change it inside the server after you sign in.
  </Accordion>
</AccordionGroup>

## If something goes wrong

<AccordionGroup>
  <Accordion title="I think my server was hacked. What should I do?" icon="siren">
    1. Open the **Console** from the server's page and sign in, or reset the password first with **Reset** on the **Overview** tab.
    2. Look for unknown users, programs and scheduled tasks, and change all passwords.
    3. If you're unsure the server is clean, [restore a backup](/docs/control-panel/backups#restore-a-backup) from before the problem, or [reinstall](/docs/control-panel/reinstall-server) and restore your data from your own copies.
    4. [Open a ticket](https://new.flashrdp.com/support/new) if you need help or if we contacted you about abuse.
  </Accordion>

  <Accordion title="I got an abuse notice about my server. What happens now?" icon="mail-warning">
    Reply to the ticket quickly and fix the cause. A compromised server that attacks other networks or sends spam can be suspended to protect the network, and serious violations of the [Acceptable Use Policy](/docs/terms/use-of-service) can lead to termination. You're responsible for activity from your server, even if someone else broke into it.
  </Accordion>

  <Accordion title="How do I report abuse coming from a FlashRDP IP address?" icon="flag">
    Email `abuse@flashrdp.com` with the IP address, the time (in UTC) and evidence such as log lines or email headers. Customers can also open a ticket in the Abuse Desk.
  </Accordion>
</AccordionGroup>

## What's not allowed

<AccordionGroup>
  <Accordion title="Which activities are prohibited?" icon="ban">
    The [Acceptable Use Policy](/docs/terms/use-of-service) prohibits, among other things:

    * launching or helping with DDoS attacks, scanning other networks without permission, and running exploit or brute-force tools against others
    * spam, phishing pages and activity that gets our IP addresses blacklisted
    * malware, ransomware, botnet control servers, carding, identity theft and fraud
    * child sexual abuse material, which is reported to the authorities

    Breaking these rules can lead to immediate termination without a refund. If an IP address is blacklisted because of your use, a \$50.00 cleanup fee applies per address.
  </Accordion>

  <Accordion title="Is my use case allowed?" icon="circle-help">
    Legal business and personal workloads are welcome, including trading terminals and bots, web hosting, development, automation, blockchain nodes and game servers.

    Some activities are restricted and can get a server suspended or terminated: cryptocurrency mining, P2P sharing of content you don't have rights to, open proxies, public VPNs and Tor exit nodes, unlicensed IPTV, aggressive scraping, and reselling servers. See [Restricted Activities](/docs/terms/use-of-service#restricted-activities).

    If you're unsure about a specific workload, ask the Presale Desk in a [ticket](https://new.flashrdp.com/support/new) before you deploy.
  </Accordion>

  <Accordion title="Can I scan my own server for vulnerabilities?" icon="scan">
    Yes. Scanning your own FlashRDP server is allowed. Scanning other networks needs the explicit written consent of their owner.
  </Accordion>
</AccordionGroup>

## Related Articles

<CardGroup cols={2}>
  <Card title="Acceptable Use Policy" icon="scale" href="/docs/terms/use-of-service" />

  <Card title="Trust Center" icon="shield-check" href="/docs/security/trust-center" />
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.