Acceptable Use Policy
What these systems are not for.
This policy applies to the marketing inquiry form, tokenized intake, authentication, the invitation-only workspace, and any workflow Xpancom hosts for a client.
01 / Section
Prohibited data classes.
Do not upload or paste passwords, API keys, private cryptographic material, full payment card numbers, bank account numbers, Social Security or national-id numbers, protected health information, or raw employee personnel files into inquiry, intake, email, or the workspace.
You may describe, at an operating level, that an environment includes customer PII, employee records, payments, or health data, so we can plan controls. Description is not the same as depositing the records.
02 / Section
Prohibited uses.
- Attempting unauthorized access, probing, or denial of service.
- Malware, phishing, or using the systems to send unlawful messages.
- Reselling access or sharing an invitation with someone who is not named on a grant.
- Using the workspace or any hosted model to make automated employment decisions, hidden replaceability scores, or covert surveillance of workers.
- Misrepresenting generated output as a signed legal, clinical, or financial opinion.
- Violating export controls or using the services in a way that is unlawful in Florida or in the client's jurisdiction.
03 / Section
Suspension.
We may suspend access immediately if this policy is violated, if a system is at risk, or if law requires it. We will restore access when the risk is contained. Repeated or severe violations are grounds to terminate the engagement under the Professional Services Terms.