Acceptable Use Policy
Effective September 8, 2026 · Version 2026-09-08
This Acceptable Use Policy ("AUP") is part of the Terms of Service for AI Assurance Hub. It applies to every account, API key, webhook, and integration. AI Assurance Hub LLC may suspend or terminate access for violations.
1. Permitted use
You may use the Service only to inventory, assess, approve, document, and evidence AI use for organizations you are authorized to represent, and only in compliance with law and these Terms.
2. Prohibited conduct
You must not:
- Violate any law, regulation, or third-party right (including privacy, IP, and export controls);
- Attempt to access another tenant’s schema, data, or credentials;
- Probe, scan, or load-test the Service without our prior written consent;
- Circumvent authentication, MFA, SSO, IP allowlisting, rate limits, or audit logging;
- Upload malware, exploit payloads, or content you do not have the right to process;
- Use the Service to provide legal, medical, or compliance certification to third parties as if it were issued by us;
- Misrepresent risk scores, approvals, or exports as a legal determination or certification;
- Resell, sublicense, or white-label the Service except under a consultant/MSP plan and only for isolated client workspaces;
- Share passwords, API keys, or SCIM tokens, or leave privileged sessions unattended;
- Use the public demo workspace for production records or regulated personal data;
- Interfere with other customers or with our infrastructure;
- Scrape, harvest, or bulk-export the Service except through documented export and API features for your own tenant.
3. Customer content
You are solely responsible for Customer Content, including personal data you choose to store in use cases, evidence, and comments. Do not upload data you lack a lawful basis to process. We do not review Customer Content for legality except as required to operate or secure the Service.
4. API, webhooks, and integrations
Keys and webhook URLs must not target private, link-local, or loopback addresses. You must keep secrets confidential, rotate them if exposed, and use integrations (including Jira and Slack) only with accounts you are authorized to connect.
5. Enforcement
We may investigate suspected violations, remove content, revoke keys, suspend tenants, or terminate accounts. We may report unlawful activity to authorities. We are not required to monitor Customer Content.
6. Contact
Report abuse to [email protected].