You cannot use AWS to hack into systems, scan networks without permission, or disrupt internet services — even if you are doing security research without explicit authorization.
This analysis describes what Amazon's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes AWS's security requirements as a contractual obligation, creating a baseline standard that protects AWS infrastructure and other customers' systems from exploitation or disruption through the AWS platform.
Security professionals and researchers using AWS for testing must ensure they have explicit written authorization for every target system they test; unauthorized scanning or probing — even for defensive purposes — violates the AUP and can result in immediate account termination and potential referral to law enforcement.
How other platforms handle this
TINDER ASSUMES NO RESPONSIBILITY FOR ANY CONTENT THAT YOU OR ANOTHER USER OR THIRD PARTY POSTS, SENDS, RECEIVES, AND/OR ACTS ON THROUGH OUR SERVICES, NOR DOES TINDER ASSUME ANY RESPONSIBILITY FOR THE IDENTITY, INTENTIONS...
we do not warrant that Offering descriptions are accurate, complete, reliable, current, or error-free.
Please note that these third parties are responsible for their own privacy practices.
"No Security Violations. You may not use the Services to violate the security or integrity of any network, computer or communications system, software application, or network or computing device. Prohibited activities include: unauthorized access to or use of data, systems or networks; attempting to probe, scan or test the vulnerability of a system, network or account; interference with service to any user, host or network.Excerpt from Amazon's AWS Acceptable Use Policy
(1) REGULATORY FRAMEWORK: This provision mirrors prohibitions in the Computer Fraud and Abuse Act (18 U.S.C.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes AWS's security requirements as a contractual obligation, creating a baseline standard that protects AWS infrastructure and other customers' systems from exploitation or disruption through the AWS platform.
Security professionals and researchers using AWS for testing must ensure they have explicit written authorization for every target system they test; unauthorized scanning or probing — even for defensive purposes — violates the AUP and can result in immediate account termination and potential referral to law enforcement.
ConductAtlas has identified this type of provision across 287 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Amazon.