For the complete documentation index, see llms.txt. This page is also available as Markdown.

Restricted targets

helodata blocks a small set of destinations at the gateway. Requests to a restricted target return 403 Forbidden from the gateway (not the target) with header X-Helodata-Block-Reason.

Permanently blocked

These categories are blocked on every account with no exception path:

  • Child sexual abuse material (CSAM) and any domain on the IWF or NCMEC lists

  • Sanctioned-jurisdiction services as required by US, EU, and UK sanctions law

  • Distribution of malware, ransomware, or exploit kits

  • Phishing kits and credential-harvesting infrastructure

  • DDoS-for-hire services

  • Government identity-fraud services (forged passports, driver's licenses)

If you operate threat-intel research that legitimately needs to fetch from blocked categories, contact security@helodata.com — we can route specific domains through an audited research channel after a compliance review.

Restricted by default (per-account exception possible)

Blocked unless you explicitly request an exception in writing:

  • Major banking and brokerage logins (account-aggregation use cases)

  • Healthcare patient portals (HIPAA scope)

  • Government tax-filing portals

  • Streaming services' premium endpoints (when ToS forbids automated access)

  • Sneaker drops and ticket-resale sites during drop windows on Trial plans

To request an exception:

  1. Email support@helodata.com with subject Restricted-target exception: {your domain list}.

  2. Include your sub-user, the domains, and a brief description of the use case.

  3. Expect a response within 2 business days. Exceptions are scoped to specific sub-users.

Trial-only restrictions

Trial accounts have stricter limits — these additional categories are blocked until you upgrade:

  • All social media DMs and posting endpoints (read-only public pages are fine)

  • Account-creation flows on any major site

  • Payment-processor (Stripe, PayPal, Adyen) test or live endpoints

Operational blocks (temporary)

The gateway also enforces short-lived blocks for operational reasons:

  • A target whose abuse complaints exceed our threshold gets a 24–72h cool-off

  • A target with active legal action against helodata gets a block until resolved

  • A target experiencing an outage that's causing high error rates may get a 5-minute back-off

Operational blocks are listed live in Dashboard → Status → Active blocks.

Detecting a block

Blocked requests do not consume traffic credits.

Reporting abuse

If you receive an abuse complaint involving helodata IPs, forward it to abuse@helodata.com with the offending IP, timestamp (UTC), and full headers. We respond to abuse reports within 1 business day.

Last updated

Was this helpful?