Restricted targets
helodata blocks a small set of destinations at the gateway. Requests to a restricted target return 403 Forbidden from the gateway (not the target) with header X-Helodata-Block-Reason.
Permanently blocked
These categories are blocked on every account with no exception path:
Child sexual abuse material (CSAM) and any domain on the IWF or NCMEC lists
Sanctioned-jurisdiction services as required by US, EU, and UK sanctions law
Distribution of malware, ransomware, or exploit kits
Phishing kits and credential-harvesting infrastructure
DDoS-for-hire services
Government identity-fraud services (forged passports, driver's licenses)
If you operate threat-intel research that legitimately needs to fetch from blocked categories, contact security@helodata.com — we can route specific domains through an audited research channel after a compliance review.
Restricted by default (per-account exception possible)
Blocked unless you explicitly request an exception in writing:
Major banking and brokerage logins (account-aggregation use cases)
Healthcare patient portals (HIPAA scope)
Government tax-filing portals
Streaming services' premium endpoints (when ToS forbids automated access)
Sneaker drops and ticket-resale sites during drop windows on Trial plans
To request an exception:
Email support@helodata.com with subject
Restricted-target exception: {your domain list}.Include your sub-user, the domains, and a brief description of the use case.
Expect a response within 2 business days. Exceptions are scoped to specific sub-users.
Trial-only restrictions
Trial accounts have stricter limits — these additional categories are blocked until you upgrade:
All social media DMs and posting endpoints (read-only public pages are fine)
Account-creation flows on any major site
Payment-processor (Stripe, PayPal, Adyen) test or live endpoints
Operational blocks (temporary)
The gateway also enforces short-lived blocks for operational reasons:
A target whose abuse complaints exceed our threshold gets a 24–72h cool-off
A target with active legal action against helodata gets a block until resolved
A target experiencing an outage that's causing high error rates may get a 5-minute back-off
Operational blocks are listed live in Dashboard → Status → Active blocks.
Detecting a block
Blocked requests do not consume traffic credits.
Reporting abuse
If you receive an abuse complaint involving helodata IPs, forward it to abuse@helodata.com with the offending IP, timestamp (UTC), and full headers. We respond to abuse reports within 1 business day.
Last updated
Was this helpful?