Acceptable Use Policy
What you may and may not do with the Platform, and what happens when an account crosses the line.
Incorporated by reference into the Master Subscription Agreement at MSA §1.2.
NECESSITYWORKS, INC. — ACCEPTABLE USE POLICY
Version: 1.0 Published at: https://necessityworks.com/legal/aup Applies to: NecessityWorks, Inc. (Delaware) Governs: All access to and use of the NW security platform
1. Scope
This Acceptable Use Policy (“AUP”) applies to all access to and use of the NecessityWorks security platform and related services (the “Services”) by any customer, Authorized User, or other person (“Users”). Violations of this AUP are grounds for suspension or termination under the applicable agreement.
The AUP is in addition to, and does not replace, obligations under the Agreement, DPA, BAA, AI Services Supplement, applicable Service Descriptions, and applicable law. Where this AUP conflicts with a signed agreement, the signed agreement controls.
2. Prohibited Content
Users will not upload, transmit, store, or Process through the Services any content that:
- is illegal under any law applicable to the User or to NW, including content that infringes intellectual-property rights or violates privacy or export-control laws;
- is child sexual abuse material (CSAM) or otherwise exploits minors;
- is non-consensual intimate imagery;
- promotes, facilitates, or incites violence, terrorism, or self-harm, or provides material support to a designated terrorist organization;
- is defamatory, harassing, threatening, or stalking-oriented toward any identifiable person;
- is obtained through unauthorized access to another person’s systems or information, except where the User has explicit authorization (e.g., as a penetration tester under a written engagement);
- is malware, ransomware, exploit code, or other malicious payload intended to be executed against systems other than the User’s own authorized environment; or
- is confidential information of a third party that the User is not authorized to disclose or Process.
3. Prohibited Uses of the Services
Users will not:
- Resell, sublicense, lease, or otherwise commercially exploit the Services to third parties, except as expressly permitted in the Agreement;
- Use the Services to benchmark or build a competing service, or to develop a service that replicates or substantially imitates the Platform’s material features;
- Interfere with or disrupt the Services, NW’s infrastructure, or other customers’ use of the Services, including by (i) sending excessive traffic, (ii) exploiting or probing for security vulnerabilities, (iii) attempting to bypass rate limits or access controls, (iv) launching denial-of-service attacks, or (v) introducing malicious code into the Services;
- Reverse-engineer, decompile, disassemble, or otherwise attempt to derive the source code, models, weights, system prompts, or trade secrets of the Services, except to the extent this restriction is prohibited by applicable law;
- Circumvent any authentication, authorization, rate-limiting, encryption, or other technical control of the Services;
- Share account credentials, API keys, or other authentication material with unauthorized parties, or allow access to the Services by any person who is not an Authorized User;
- Scrape, mirror, or extract data from the Services in bulk, outside documented export features, without prior written authorization from NW;
- Operate a service that acts as a public gateway to the Services (e.g., exposing the Platform as a public API to unaffiliated parties) without prior written authorization; or
- Misrepresent NW or the Services, including by deceptively labeling AI Output as human-generated or by falsely claiming an affiliation with NW.
4. Prohibited Security-Related Activities
Given the security-sensitive nature of the Platform:
4.1 Testing of NW’s Services. Users will not conduct vulnerability scans, penetration tests, or other security testing against NW’s infrastructure or the Services, except through NW’s published Vulnerability Disclosure Program at https://necessityworks.com/.well-known/security.txt or with NW’s prior written authorization.
4.2 Testing of Third Parties. Users will not use the Services to conduct vulnerability scans, penetration tests, offensive-security tooling, brute-force attacks, credential-stuffing attacks, or other adversarial security activities against systems or accounts that the User is not expressly authorized to test.
4.3 Customer’s Own Assets Only. The Platform’s integrations and scanning capabilities are intended to assess systems, accounts, and data owned or operated by the Customer. Users will not configure the Platform to scan, probe, exfiltrate from, or otherwise interact with third-party assets without the authorization required by applicable law and by the third party.
4.4 Response Authority. Where the Services enable automated containment, blocking, isolation, or other response actions, the User is responsible for ensuring that its use of these capabilities is limited to the User’s own environment and Authorized Users, and does not intentionally disrupt or damage third-party systems.
5. Prohibited AI Misuse
In addition to the Prohibited Uses in §5 of the AI Services Supplement, Users will not:
- Submit as AI Input any authentication credentials, cryptographic secrets, API keys, or similar sensitive access material;
- Use AI Output as the sole basis for any legally regulated high-stakes decision without meaningful human review (see AI Services Supplement §5(a));
- Attempt to extract, infer, or reconstruct the underlying Foundation Model weights, training data, or system prompts;
- Generate or distribute AI Output intended to deceive a person into transferring money, Personal Data, or access credentials; or
- Use AI Services to develop a competing AI model or service.
6. Prohibited Data Practices
Users will not:
- Upload Personal Data beyond what is reasonably necessary for the Services;
- Upload special-category Personal Data (as defined under GDPR Art. 9 or analogous laws) without first confirming with NW in writing that the Platform is configured to Process such data in compliance with applicable law;
- Upload PHI without having an executed BAA on file with NW;
- Upload cardholder data subject to PCI DSS without first confirming with NW in writing that such Processing is permitted and within PCI DSS scope;
- Upload classified information, ITAR-controlled information, or similarly regulated data without prior written authorization from NW; or
- Use the Services in a manner that would cause NW to breach its contractual obligations to any Subprocessor, Model Provider, or data licensor.
7. Enforcement
7.1 Investigation. NW reserves the right (but does not assume the obligation) to investigate any suspected violation of this AUP and to cooperate with law-enforcement authorities where legally required or appropriate.
7.2 Suspension. NW may suspend a User’s or Customer’s access to the Services, in whole or in part, without liability, where NW has a reasonable basis to believe that continued access would (a) cause material harm to the Services, other customers, or third parties; (b) result in legal liability to NW; or (c) violate this AUP. NW will give notice of suspension as promptly as is reasonable under the circumstances.
7.3 Termination. Material or repeated violations of this AUP are grounds for termination of the Agreement under MSA §13.2.
7.4 Remediation Obligations. Following a confirmed AUP violation, Customer is responsible for ceasing the violating activity and, at NW’s reasonable request, for remediating any material harm caused by the violation, including cooperation in any required notifications.
8. Reporting AUP Violations
To report suspected abuse of the Services, violations of this AUP, or security concerns, contact [email protected] with sufficient detail to enable investigation. NW will acknowledge substantive reports within two (2) business days and will investigate in good faith.
For security-research disclosures, use the Vulnerability Disclosure Program at https://necessityworks.com/.well-known/security.txt.
9. Updates
NW may update this AUP from time to time to reflect changes in the Services, changes in law, or newly identified abuse patterns. NW will post the current version at https://necessityworks.com/legal/aup and will provide notice of material adverse changes at least thirty (30) days before they take effect, consistent with MSA §18(m).