Reporting illegal content and abuse of Shipvise
Version: 1.0
Effective: upon publication of this version
Last updated: 21 August 2026
Stable URL: https://shipvise.com/en/abuse/
Translation notice: This English version is a machine-assisted translation provided for convenience. The original Czech version is the authoritative version. Where mandatory law requires otherwise, rights granted by mandatory law remain unaffected.
Shipvise hosts Customer applications and accepts reports concerning illegal content, phishing, malware, attacks, fraud and other abuse.
A report can be submitted through the form on this page or to abuse@shipvise.com.
1. Two types of report
A. Formal notice of illegal content under the DSA
Use this mode if you wish to report specific information or content hosted through Shipvise that you consider to constitute illegal content.
As a standard, the form requests the details required under Article 16 of the Digital Services Act.
B. General abuse/security report
Use this mode for example for:
- phishing;
- malware, ransomware or C2;
- suspicious scanning/exploitation activity;
- fraud or impersonation;
- spam;
- an attempt to abuse the platform;
- a security problem;
- other inappropriate or suspicious use.
A general report may also be accepted anonymously where the reporter's identity is not necessary in order to handle it. An anonymous report may not, however, satisfy all the requirements of a formal DSA notice.
2. Recommended form categories
The form is to contain at least the following categories:
- phishing / theft of access credentials;
- malware / ransomware / command-and-control;
- attack / exploitation / unauthorised scanning;
- fraud / impersonation;
- spam / unsolicited bulk communication;
- illegal content or service;
- infringement of intellectual property rights;
- child sexual abuse / CSAM;
- other.
3. Requirements of a formal DSA notice
In order for a submission to be processed as a formal notice of illegal content, the form as a standard requires:
- a sufficiently substantiated explanation of why the reporter considers the information to be illegal;
- the exact electronic location, in particular the specific URL and, where necessary, other details enabling the content to be found;
- the reporter's name and e-mail address, except where applicable law permits or requires that they not be provided, in particular for certain reports concerning child sexual abuse;
- a statement confirming that the reporter is acting in good faith and that the information and allegations in the notice are, to the best of their knowledge, accurate and complete.
Recommended wording of the active checkbox:
I declare in good faith that the information and statements in this notice are accurate and complete.
The checkbox must not be pre-ticked.
4. Exact URL
For a formal DSA notice, the specific URL is mandatory where the illegal information is available at a URL.
The form is to validate only safely acceptable http:// or https:// addresses and must make it possible to add several relevant URLs or further location details where needed.
5. Evidence
The reporter may provide further context or evidence in text form.
If the website does not yet have a securely implemented attachment upload, the implementation is not to add a general file upload hastily merely for the abuse form. In the first version, attachments can be handled through subsequent communication with the abuse team.
6. Protecting the form against abuse
The Provider may process and store the technical data needed to protect the abuse mechanism, in particular:
- IP address;
- timestamp;
- user-agent;
- locale;
- the ALTCHA result;
- rate-limit/security metadata.
The standard retention of IP and anti-abuse metadata is 90 days. In the event of an incident, suspected abuse, a dispute or a need to protect rights, the relevant records may be kept longer for the duration of the handling.
7. ALTCHA and rate limiting
The form uses self-hosted ALTCHA or an equivalent privacy-friendly anti-bot protection.
The Provider may use server-side rate limiting, a honeypot and other proportionate measures against automated flooding. These measures must not make it impossible for an ordinary reporter to submit a legitimate notice.
8. Acknowledgment of receipt
Where the reporter provides a working e-mail address, Shipvise will acknowledge receipt without undue delay, where this is appropriate or required for the given type of report.
An acknowledgment of receipt does not mean that Shipvise has already decided that the content is illegal or that the Terms have been breached.
9. Assessment
The Provider will assess in particular:
- whether the content or workload identified is in fact hosted or controlled through Shipvise;
- the specificity and completeness of the notice;
- the grounds of illegality or of the AUP breach;
- the credibility of the available evidence;
- the urgency and the risk of continuing harm;
- any statement from the Customer, where it can be obtained safely and lawfully before the decision.
The decision is not based merely on the fact that someone has submitted a report.
10. Urgent temporary measure
Where there is reasonable suspicion of serious abuse, a credible report or an acute threat, the Provider may temporarily restrict or suspend Preview, Production, build or another feature even before the investigation is fully completed.
This concerns in particular:
- active phishing;
- malware/ransomware/C2;
- an ongoing attack;
- CSAM;
- a significant threat to other Customers or to the infrastructure.
Where the nature of the risk permits, the Provider will carry out a basic verification before intervening. In an urgent situation, "suspend first, investigate immediately after" may apply.
11. Possible measures
Depending on the outcome, the Provider may:
- close the report without intervention;
- request additional information;
- contact the Customer;
- request a remedy;
- restrict a specific URL or service;
- suspend Preview/Production;
- isolate the workload;
- restrict the Account or Project;
- remove/disable the content where legally and technically appropriate;
- terminate the service in the event of a serious or repeated breach;
- preserve the relevant evidence;
- comply with a legally binding order of an authority or cooperate to the extent required by law.
12. Statement of reasons
Where the Provider imposes a restriction on a recipient of the service on grounds of illegality or non-compliance with the Terms and Article 17 DSA applies, it will give the affected recipient a clear and specific statement of reasons to the extent required by law.
The statement of reasons may include in particular:
- the nature of the restriction;
- the facts and circumstances on which the decision is based;
- any role played by a notice;
- the contractual or legal basis applied;
- the options for review or remedy.
The statement of reasons may be limited where a full disclosure would breach a legal obligation or disproportionately jeopardise security or an investigation.
13. Review
The Customer may request human review of the decision through the contact stated in the notification or at support@shipvise.com.
Abuse/recipient communication must not be based exclusively on an automated tool.
14. Knowingly false or abusive reports
The abuse mechanism must not be used for harassment, flooding, extortion of Customers or knowingly false allegations.
The Provider may apply rate limiting or otherwise protect the system against repeated misuse; this is without prejudice to the possibility of submitting a legitimate notice.
15. DSA contacts
Contact point for Member State authorities, the European Commission and the European Board for Digital Services: abuse@shipvise.com
Languages supported for this contact: Czech and English.
Contact point for recipients of the service: support@shipvise.com and the public abuse form.
Further identification details are available at /en/legal/contact/.

