Customer content is delivered as supplied. We do not host origin content and we do not modify payloads in transit beyond compression and protocol negotiation. Accounts used for network abuse, credential stuffing or malware distribution are suspended without notice.
Edge access logs contain request metadata: timestamp, method, path, status, byte counts, TLS version and negotiated cipher, cache disposition and a truncated client address. Logs are retained for 30 days and then deleted. Request bodies are never written to disk.
Leaf certificates for customer hostnames are issued by a public CA and rotated automatically before expiry. Private keys are generated on the node that uses them and are not exported.
Send reports to the role account published for this network in PeeringDB. Include timestamps in UTC, the affected hostname and the PoP code from the x-halcyon-pop response header — for this node, sg01. Security findings are acknowledged before triage.
Material changes to these terms are published on this page. The version in force is the one served here at the time of the request.