Acceptable Use Policy
This Acceptable Use Policy ("AUP") is incorporated into the Terms of Service. Violations may result in suspension, termination, or legal action.
Prohibited content
You will not use the Service to:
- upload, generate, or distribute content that is unlawful, infringing, defamatory, or obscene;
- upload special-category personal data without a separate written agreement;
- upload content for which you lack rights, including third-party intellectual property;
- distribute malware, ransomware, or content designed to compromise systems;
- process protected health information unless an executed Business Associate Agreement is in place;
- process payment-card data; Stripe Checkout handles all card data and our environment is PCI-out-of-scope.
Prohibited activities
You will not:
- circumvent rate limits, AI-cost caps, or any technical safeguard;
- reverse engineer the Service, model weights, prompts, or eval cases;
- use Service outputs to train, fine-tune, evaluate, or improve a competing AI product;
- resell, sublicense, or repackage the Service except via the licensed licensee tier;
- impersonate another person or organisation, or misrepresent your affiliation;
- attempt to gain unauthorised access to any account, data, or system;
- conduct security testing without our prior written permission and a coordinated disclosure plan;
- introduce excessive load through automated processes outside the documented APIs and limits.
AI-specific prohibitions
You will not use the Service to:
- deliver audit deliverables to your end-clients without auditor review of AI-drafted content; auditors retain professional responsibility for the report;
- attempt prompt injection, jailbreak, or adversarial-input attacks aimed at extracting system prompts, eval cases, or other tenants' data;
- generate content that could reasonably be expected to cause harm: unsafe medical advice, fraudulent representations to regulators, defamatory accusations, or deepfake content;
- use Service outputs to make adverse employment, credit, or housing decisions about natural persons without applying applicable bias-audit and notice obligations (e.g. NYC LL 144, CO AI Act, CPPA ADMT).
Coordinated disclosure
Security testing of the Service requires written authorisation. Report vulnerabilities responsibly via asarewilliam0@gmail.com. We commit to acknowledge within 2 business days, credit researchers in our hall of fame upon their request, and not pursue legal action against good-faith research that complies with the coordinated-disclosure timeline (90 days).
Enforcement
AuditAI may suspend access without notice for AUP violations that pose imminent harm, and otherwise on reasonable notice with an opportunity to cure. Repeated or wilful violations are grounds for termination under the Terms.
Reporting abuse
Email abuse@auditai.example with details and any evidence. We respond within 5 business days.