Pubto is built for temporary, controlled access to user-selected development services and files. Content stays on the publishing computer rather than becoming a permanent Pubto storage copy. Because any public endpoint can be misused, Pubto combines preventive controls, usage limits, reports, and operator action.
Product boundaries
Pubto is not permanent network storage, an anonymous cyberlocker, a mass file-distribution service, a VPN or open proxy, a public content marketplace, or a payment or payout platform. Each publication points to one selected target, has an independent address and lifecycle, and can be stopped or revoked.
Preventive controls
Publication names, descriptions, and normalized public source hostnames are checked before authorization against an operator-managed multilingual moderation dictionary and protected-domain list. Sensitive targets require deliberate selection, and managed AI workflows instruct the operator to seek human approval before publishing databases, LAN targets, admin services, and similar endpoints.
Access controls include short expiry, per-publication revoke and address rotation, browser passwords where enabled, source-service authentication, target-scope restrictions, file-size limits, protocol permissions, and plan-specific quotas.
Usage monitoring and review triggers
Pubto records limited operational totals and security signals such as requests, transferred bytes, visitor counts, duration, active connections, endpoint lifecycle, client IP and User-Agent observations, and command receipts. It does not log request or response bodies by default.
Rate, request-window, traffic-window, monthly, duration, visitor, and connection controls can automatically restrict additional use. Unusual or high traffic, repeated blocked attempts, abrupt usage changes, complaints, protected targets, credential or device anomalies, and attempts to evade limits may trigger operator review or a request for proof of authorization.
AI and automated moderation boundary
The current high-throughput content gate is deterministic dictionary and protected-domain matching, not generative-AI inspection of file contents or encrypted traffic. It checks selected metadata before authorization and can be updated by authorized operators without waiting for a client release.
Pubto may use carefully scoped AI-assisted classification or risk scoring in future or targeted investigations, but will document material changes and apply human review to consequential account-level decisions where reasonably available. Automated tools can miss harmful content or produce false positives; reports and account-holder responsibility remain necessary.
Human investigation
Authorized personnel may review reported public pages, submitted evidence, relevant metadata, account history, and the minimum information reasonably needed to determine whether an endpoint violates policy or law. For encrypted or opaque protocols, Pubto may be unable to inspect content and may instead restrict the endpoint based on credible reports, behavior, authorization evidence, or network risk.
We limit access to personnel with an operational need and may preserve relevant records for abuse response, disputes, provider requirements, or legal obligations.
Enforcement actions
Depending on severity and confidence, Pubto may warn the account holder; require changes or authorization evidence; rate-limit or block traffic; stop, rotate, quarantine, or delete an endpoint; restrict a target or protocol; suspend a device, workspace, or account; preserve evidence; or notify infrastructure providers, payment providers, rights holders, or authorities.
Severe or credible risks such as phishing, malware, credential theft, child sexual abuse material, unauthorized system access, or imminent harm may be acted on without advance notice. When reasonable, Pubto targets the affected publication rather than unrelated local services.
Refunds after enforcement
Fees are not refundable for a service period lost because of the account holder's material or repeated policy violation, except where required by law or where Pubto determines the restriction was imposed in error. Duplicate charges, billing errors, ordinary cancellation, and service failures remain governed by the Billing and Refund Policy.
Report and request review
Report a suspicious Pubto address to [email protected] with the full public address, observed behavior, timestamp and time zone, and supporting evidence. Do not send passwords, access tokens, complete payment-card data, or unrelated personal information. Send urgent platform-security issues to [email protected].
An affected account holder can request review by emailing from the account address and providing the endpoint or workspace, intended use, authorization evidence where relevant, and the reason the decision may be incorrect. A credible restriction may remain in place during review.
