Effective date: 29 July 2026
1. Application
This Acceptable Use Policy applies to all users of the websites, Accounts, AI interfaces, APIs, software, portals, evaluation environments and Enterprise Services. It supplements the Terms and Conditions.
2. Lawful authority
You may use security, forensic, evidence, invention, AI and technical features only for systems, data and activities you own or are lawfully authorised to assess. You must comply with law, contractual restrictions, professional obligations and third-party rights.
3. Prohibited activity
You must not use the Services to:
- commit, facilitate, conceal or encourage crime, fraud, deception, extortion or unlawful surveillance;
- access, interfere with, test or control systems without authority;
- create, deliver or operate malware, ransomware, credential theft, destructive payloads, botnets or denial-of-service attacks;
- evade authentication, security controls, usage limits, sanctions screening or safety measures;
- collect, infer, publish, identify or trade personal information unlawfully;
- exploit, sexualise or endanger children or distribute illegal or age-restricted material;
- threaten, harass, stalk, discriminate, defame, impersonate or manipulate people unlawfully;
- create deceptive evidence, false signatures, fabricated timestamps, falsified chain-of-custody records or fraudulent professional documents;
- infringe copyright, trade marks, patents, designs, confidentiality, trade secrets, privacy, publicity or contractual rights;
- send spam, unlawful marketing, phishing or misleading communications;
- produce or facilitate prohibited weapons, biological, chemical, radiological or other severe harm;
- encourage self-harm or provide instructions designed to cause serious injury;
- make high-impact eligibility, employment, credit, insurance, health, legal, policing or safety decisions without lawful governance and human review;
- submit private keys, secrets, regulated data or confidential third-party material without approval;
- scrape, benchmark, extract, train on or replicate protected systems or content without permission;
- resell, sublicense or provide access to unauthorised users; or
- misrepresent affiliation, certification, security, patent status, human authorship or endorsement.
4. Defensive security research
Good-faith defensive research is permitted only within written scope or the Security and Responsible Disclosure Policy. Researchers must minimise access, stop when personal or confidential data is encountered, avoid persistence or exfiltration, preserve evidence responsibly and report promptly.
5. Content and data responsibility
You are responsible for content you submit, publish or distribute. You must have rights and authority to use it and must apply appropriate classification, consent, minimisation and retention.
6. Enforcement
We may investigate suspected breaches using proportionate logs and evidence. We may warn, restrict, quarantine, remove content, suspend, terminate, preserve records or report conduct where reasonably necessary and lawful. Urgent action may be taken to prevent harm or comply with law.
7. Appeals and contact
A user may request review of an enforcement decision by contacting [email protected]. The request should identify the Account, decision and relevant facts. We may require identity and authority verification.