MantisOps
MANTISOPS Managed IT Operations
Home

Abuse & Restricted Use Policy

Effective: June 22, 2026 · Last updated: June 22, 2026

MantisOps builds tools for IT and security teams to manage and protect the environments they are responsible for. We take seriously our role in keeping those tools from being used to harm others.

This policy describes specific uses that are prohibited on our platform. It supplements our Acceptable Use Policy and is incorporated by reference into our Terms of Service.

1. Unauthorized remote access

The MantisRMM remote desktop, terminal, scripting, and file management features must only be used on devices you own or have explicit authorization from the device owner to access. Using these features to:

  • Access an employee's personal device without their knowledge or consent
  • Access systems belonging to a former employer after your authorization has ended
  • Access any system for which you do not have documented, current authorization
...is a violation of this policy and likely a violation of applicable computer fraud laws, including the Computer Fraud and Abuse Act (18 U.S.C. § 1030) and equivalent statutes in your jurisdiction.

2. Unauthorized network scanning

The Mantis360 probe performs active network scanning. Scans must only target IP ranges, hosts, and networks you own or have written authorization to assess. The following are prohibited:

  • Scanning IP addresses belonging to third parties, hosting providers, or cloud services you do not control
  • Scanning a customer's or business partner's network without a signed engagement agreement authorizing the activity
  • Using Mantis360 as a reconnaissance tool against targets you intend to attack

Active scanning of networks you do not own or are not authorized to test may violate the Computer Fraud and Abuse Act and equivalent laws. We cooperate with law enforcement investigations involving unauthorized scanning.

3. Deploying agents without consent

The MantisRMM agent is a legitimate, consent-based remote management tool. Installing the agent covertly — without the device owner's knowledge — to conduct surveillance, exfiltrate data, or maintain unauthorized access is prohibited and will result in immediate account termination and referral to law enforcement.

Prohibited activity of this type includes:

  • Distributing the agent through deceptive download links or social engineering
  • Installing the agent on devices owned by individuals who have not consented
  • Using the platform to harvest credentials, monitor personal communications, or surveil individuals without lawful authority

4. Prohibited scripting activity

Scripts deployed through MantisRMM's scripting features may not:

  • Install unauthorized software or modify device configuration without appropriate end-user notice
  • Harvest credentials, personal data, or sensitive files for purposes unrelated to legitimate IT management
  • Disable security software, endpoint protection, or audit logging without the device owner's knowledge
  • Conduct lateral movement, privilege escalation, or persistence in environments you are not authorized to manage

5. Platform and API abuse

You may not abuse MantisOps infrastructure by:

  • Sending API requests at a volume or rate intended to degrade service for other customers
  • Attempting to enumerate, scrape, or extract data belonging to other tenants
  • Bypassing authentication, authorization controls, or tenant isolation mechanisms
  • Creating accounts for the purpose of testing exploitation techniques against the platform itself

6. Enforcement

We investigate all abuse reports. We reserve the right to:

  • Suspend or terminate accounts involved in violations — immediately and without prior notice when necessary to protect the platform or third parties
  • Preserve account data, logs, and communications and provide them to law enforcement when required by law or court order
  • Permanently ban individuals and organizations from the Services

7. Reporting abuse

If you believe someone is misusing MantisOps to target your systems or devices, email abuse@mantisops.net. Include as much detail as possible: IP addresses, timestamps, and a description of the activity. We respond within 1 business day.

To report a security vulnerability in MantisOps software or infrastructure, email security@mantisops.net.

← Back to MantisOps