1. Scope
This Acceptable Use Policy ("AUP") applies to everyone who accesses MaxorConnect, our APIs, Early Access environments and related services. It forms part of our Terms of Service. You are responsible for your Users' and your AI agents' compliance, including actions taken with your API keys.
2. Prohibited uses
You may not use the Service to:
- Violate any applicable law or regulation, or encourage others to do so.
- Infringe intellectual-property, privacy, publicity or other rights of any person.
- Upload, store or transmit malware, ransomware, spyware or other harmful code.
- Distribute content that is unlawful, defamatory, harassing, hateful, or that exploits minors.
- Send spam or unsolicited bulk messages, or use contact data in violation of anti-spam or data-protection laws (including CASL, CAN-SPAM, GDPR marketing rules where they apply).
- Process special categories of data or regulated data (e.g. PHI under HIPAA, cardholder data in scope of PCI beyond our payment processor flows) unless we have agreed in a written contract that covers that use.
- Misrepresent your identity or affiliation, phish, or use the Service to deceive or defraud.
- Build a competing product by systematically scraping, harvesting or bulk-exporting non-Customer Data (our UI copy, docs, engine outputs that are Maxor IP) beyond ordinary use.
- Resell, sublicense, timeshare or provide the Service to third parties except as an authorized partner under a separate agreement.
- Use the Service in a way that creates risk of death, personal injury or severe environmental damage (e.g. safety-critical control without human oversight where required).
3. Security & integrity
You may not:
- Probe, scan or test the vulnerability of the Service, or breach security or authentication measures, without our prior written permission (coordinated vulnerability disclosure via ${EMAIL} is welcome).
- Access data that is not yours, or attempt to defeat organization isolation, ABAC or tenancy controls.
- Interfere with or disrupt the Service, place undue load on it, or circumvent rate limits, quotas or billing metering.
- Reverse engineer the Service or its engines except to the limited extent non-waivable law permits.
- Share passwords or API keys, or fail to rotate credentials after a suspected compromise.
- Mine cryptocurrency or run unrelated high-compute workloads on our infrastructure.
4. API, automation & rate limits
- API keys (including production keys) are secrets; store them in a secrets manager, never in public repos.
- Respect documented rate limits and fair-use thresholds; we may throttle or revoke keys that harm platform stability.
- Do not use the API to bypass product security, seating or feature packaging.
- Webhooks and outbound integrations must target endpoints you control or are authorized to use; do not use our platform to attack third parties.
5. AI & automated-agent use
MaxorConnect is built for the agentic era — automated agents are welcome within guardrails:
- Agents must operate through governed product surfaces or APIs, honor approval tiers (autonomous → supervised → sign-off) and ABAC policies you configure.
- Maintain the audit trail; do not strip logging or spoof actor identity.
- Do not use agents to evade this AUP, generate unlawful content at scale, scrape third parties in violation of their terms, or conduct credential stuffing / abuse.
- You remain accountable for every action agents take under your tenancy.
- AI outputs require human judgment for high-stakes decisions (legal, medical, credit, employment, safety).
6. Your data responsibilities
You are responsible for having the rights and any consents needed to put data into the Service, for lawful marketing and outreach conducted through the Service, and for configuring retention and access appropriately. Do not upload data you are not permitted to process. You must respond to data-subject requests that concern Customer Data you control; we assist under the DPA.
7. Enforcement
If we reasonably believe you have violated this AUP, we may investigate and take proportionate action, including removing content, throttling or suspending access, rotating credentials, or terminating the account. Where safe and lawful, we will try to give notice first. We may report serious or unlawful abuse to authorities and cooperate with lawful investigations. Repeated or severe violations may result in permanent exclusion from Early Access or paid plans.
8. Reporting abuse & security issues
To report a violation, vulnerability or security concern, email [email protected] with enough detail for us to reproduce and prioritize the issue. Please do not access others' data while testing. We appreciate responsible disclosure.