Legal and regulatory framework

Acceptable Use Policy

Effective date: 29 July 2026

1. Application

This Acceptable Use Policy applies to all users of the websites, Accounts, AI interfaces, APIs, software, portals, evaluation environments and Enterprise Services. It supplements the Terms and Conditions.

2. Lawful authority

You may use security, forensic, evidence, invention, AI and technical features only for systems, data and activities you own or are lawfully authorised to assess. You must comply with law, contractual restrictions, professional obligations and third-party rights.

3. Prohibited activity

You must not use the Services to:

4. Defensive security research

Good-faith defensive research is permitted only within written scope or the Security and Responsible Disclosure Policy. Researchers must minimise access, stop when personal or confidential data is encountered, avoid persistence or exfiltration, preserve evidence responsibly and report promptly.

5. Content and data responsibility

You are responsible for content you submit, publish or distribute. You must have rights and authority to use it and must apply appropriate classification, consent, minimisation and retention.

6. Enforcement

We may investigate suspected breaches using proportionate logs and evidence. We may warn, restrict, quarantine, remove content, suspend, terminate, preserve records or report conduct where reasonably necessary and lawful. Urgent action may be taken to prevent harm or comply with law.

7. Appeals and contact

A user may request review of an enforcement decision by contacting [email protected]. The request should identify the Account, decision and relevant facts. We may require identity and authority verification.