NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

aisecurity.llc

Acceptable Use Policy

aisecurity.llc products and services are for authorized defensive security, AI security engineering, training, assessment, and evidence workflows. This policy prohibits unauthorized testing, harmful activity, misuse of AI or security tooling, and use outside agreed scope.

Authorization boundaryPublic policy summary

Use the platform only for lawful, authorized, defensive, educational, or agreed professional-services purposes. Using aisecurity.llc does not authorize testing any target. Active testing requires explicit authorization and, where applicable, SOW, Assessment Terms, or ROE. Do not submit secrets, regulated data, production credentials, or third-party data through public forms. Do not use our AI or security tools to conduct unauthorized offensive activity.

1. Plain-English Summary

  • Use the platform only for lawful, authorized, defensive, educational, or agreed professional-services purposes.
  • Using aisecurity.llc does not authorize testing any target.
  • Active testing requires explicit authorization and, where applicable, SOW, Assessment Terms, or ROE.
  • Do not submit secrets, regulated data, production credentials, or third-party data through public forms.
  • Do not use our AI or security tools to conduct unauthorized offensive activity.

2. Authorized Uses

  • Browsing public materials.
  • Completing scoping and packet workflows.
  • Using customer workspace and platform features under account permissions.
  • Purchasing or accessing training and LMS content.
  • Authorized code and security review.
  • Authorized AI launch and security assessments.
  • Authorized pentest and red-team readiness.
  • Authorized lab and training exercises.
  • Authorized connector and integration use.
  • Authorized defensive testing under written scope.
  • Customer-owned or explicitly authorized targets only.

3. Security Testing Boundary

  • Use of the website or platform does not authorize testing.
  • Target submission does not authorize testing.
  • Packet generation does not authorize testing.
  • Active testing requires written authorization.
  • Pentest, red-team, cloud, or AI adversarial testing requires SOW, Assessment Terms, or ROE where applicable.
  • Targets must be owned, controlled, or explicitly authorized.
  • Third-party targets require third-party authorization.
  • Cloud and SaaS provider rules may apply.
  • Testing windows, stop conditions, emergency contacts, allowed or prohibited techniques, and evidence rules must be documented before testing.

4. Prohibited Conduct

  • Unauthorized access or testing.
  • Attempting to access other users' or customers' data.
  • Testing third-party or customer systems without authorization.
  • Denial of service or stress testing without approval.
  • Malware, C2, persistence, or destructive activity without explicit authorization.
  • Phishing or social engineering without explicit authorization.
  • Credential stuffing, password spraying, or account abuse.
  • Data exfiltration outside authorized proof boundaries.
  • Production data modification without explicit authorization.
  • Bypassing authentication, billing, entitlements, rate limits, or access controls.
  • Scraping, spam, or platform abuse.
  • Uploading illegal content.
  • Violating privacy or intellectual property rights.
  • Violating third-party terms through integrations.
  • Interfering with platform availability.
  • Attempting to reverse engineer where prohibited by law or agreement.

5. AI and SecEng Copilot Misuse

  • Generating or facilitating unauthorized attacks.
  • Bypassing SOW, ROE, or scope.
  • Creating malware, phishing, credential attacks, or destructive procedures.
  • Fabricating findings, evidence, screenshots, logs, reports, or attestations.
  • Impersonation.
  • Misleading public claims.
  • Using Copilot to access data, tools, integrations, or systems without authorization.
  • Using AI to evade platform controls, billing, entitlements, or audit boundaries.
  • Submitting restricted material into public or unapproved AI channels.

6. Tool-Specific Boundaries

  • Code scanner: authorized repositories and code only.
  • Adversarial range: lab, demo, or explicitly authorized targets only.
  • Model gateway or runtime proxy: authorized traffic only.
  • Browser extension and native app: authorized pages, files, local context, traces, or artifacts only.
  • RAG harness: authorized datasets, documents, and test environments only.
  • Agentic workflow tools: authorized workflows, tools, actions, credentials, and integrations only.
  • LMS and labs: training environments only unless separately authorized.
  • Integrations and connectors: only systems the user or customer is authorized to connect.

7. Integrations

  • Only connect systems you are authorized to administer or use.
  • Do not over-scope OAuth permissions unnecessarily.
  • Comply with third-party terms.
  • Revoke integrations when no longer needed.
  • Do not use integrations to access unrelated data.
  • Do not use integrations to bypass customer or provider controls.

8. Evidence and Data Submission

  • Public forms are for non-sensitive preliminary information.
  • Do not submit secrets, production credentials, regulated data, or unredacted customer records through public forms.
  • Evidence sharing is governed by the Evidence Handling Policy and applicable NDA, SOW, DPA, or ROE.
  • Credential exchange happens only after the right agreement path through an approved secure channel.

9. Claims and Publications

  • Do not claim certification, endorsement, continuous monitoring, or vulnerability-free status unless expressly authorized.
  • Do not publish confidential findings or evidence without approval.
  • Do not misrepresent draft packets as final deliverables.
  • Do not use the aisecurity.llc name, logo, or reference outside approved claim-readiness terms.

10. Enforcement

  • We may suspend, limit, or terminate access for misuse, security risk, nonpayment, legal risk, or policy violations.
  • We may preserve evidence of abuse as needed.
  • Serious abuse may be reported where legally required.
  • Enforcement may vary based on severity and context.

Acceptable Use Policy · aisecurity.llc · Effective June 27, 2026 · Version 1.0

← Back to Legal