Legal Notice & Acceptable Use
Last updated: 2026-08-10
This notice describes the intended use of TunnelCrib, foreseeable misuse we specifically warn against, safety precautions operators should take, the responsibilities that fall on you as a user or administrator, and the limits of our liability. It is not a substitute for a full Terms of Service or Data Processing Agreement, which govern your contractual relationship with us where applicable.
Intended use
TunnelCrib establishes short-lived, authenticated, encrypted Tunnels between TunnelCrib Client and a specific Service (for example a remote shell, remote desktop, remote management endpoint, or another approved TCP port) on a Device your organization already controls. It is intended to be used by:
- Organizations and individuals who own, administer, or are otherwise authorized to access the Devices and Services they connect to through TunnelCrib.
- Technical operators who understand SSH-based tunneling, key management, and the security implications of exposing a local port to a Service.
- Deployments where the operator retains responsibility for the underlying Devices' patching, hardening, and access policy — TunnelCrib provides the transport path, not the Service's security posture.
Foreseeable misuse (do not use TunnelCrib for this)
- Accessing systems, networks, or accounts you do not own and are not explicitly authorized to access.
- Circumventing network security controls, firewalls, or monitoring that a system owner has put in place, without that owner's consent.
- Using TunnelCrib as a general-purpose VPN or network-wide bridge between untrusted networks; TunnelCrib is designed for scoped, single-Service access, not full network extension.
- Relaying or forwarding traffic on behalf of a third party without verifying that party's own right to access the destination Service.
- Operating a Private Relay (using the current
tunnelcrib-bridge executable) that forwards Tunnels for organizations other than your own, or without properly securing the host it runs on.
- Using TunnelCrib to bypass export controls, sanctions, or other legal restrictions applicable to you or the systems you connect to.
Required safety precautions
- Protect the private keys and registration tokens issued to your organization's TunnelCrib Client, TunnelCrib Agent, and Private Relay; anyone holding a valid token can register a Device against your organization.
- Run TunnelCrib Agent and Private Relay software only on Devices you control, with the local operating system kept patched and access to their configuration directories restricted.
- Limit the protocols and ports a TunnelCrib Agent advertises to the Services genuinely required; do not advertise administrative or unrelated Services "just in case."
- Rotate or revoke Device registrations promptly when a Device is decommissioned, an employee departs, or a key may have been exposed.
- Review your organization's registered Devices and active Tunnels periodically through the admin portal.
Your responsibilities
- You are solely responsible for ensuring you have the legal right and authorization to access every Device and Service you reach through TunnelCrib.
- You are responsible for the security, configuration, and legal compliance of the Devices and Services you expose through a TunnelCrib Tunnel, including any credentials or data accessible through that Tunnel.
- You are responsible for complying with applicable laws and regulations in your jurisdiction and the jurisdiction of the Devices and Services you access, including data protection, export control, and computer-misuse laws.
- You are responsible for the actions of any Device, user, or Private Relay registered under your organization's account.
Limitation of liability
TunnelCrib is provided on an "as is" and "as available" basis. To the maximum extent permitted by applicable law, we disclaim all warranties, express or implied, including any warranty of merchantability, fitness for a particular purpose, and non-infringement, and we do not warrant that the service will be uninterrupted, error-free, or fully secure against every possible threat.
To the maximum extent permitted by applicable law, we are not liable for any indirect, incidental, special, consequential, or punitive damages, or for any loss of data, revenue, or business, arising from or related to your use or misuse of TunnelCrib, including misuse described above. Nothing in this notice is intended to exclude or limit liability that cannot be excluded or limited under applicable law, such as liability for death or personal injury caused by negligence, or fraud.
Contact
Questions about this notice, or to report suspected misuse of TunnelCrib involving your organization, can be sent to support@gaur.is.