Promigence Acceptable Use Policy
Effective October 4, 2026 · Last updated October 4, 2026
1. Scope#
This Acceptable Use Policy ("Policy") applies to everyone who uses the sandboxes, APIs, SDKs, command-line tools and related services of Promigence AI, Inc. ("Promigence", "we", "us") (the "Services"). It covers you, your organization, and any AI agent, automated system or end user that runs workloads on the Services through your account. You are responsible for all activity under your account, including actions your agents take autonomously. This Policy forms part of the Promigence Terms of Service and is read together with the Responsible AI & Agent Safety Policy.
2. Agents are held to the same rules as people#
An action is prohibited under this Policy whether a human performs it directly or an AI agent performs it, even if the agent acted without your specific instruction. That an agent took the action is not a defense. You must configure your agents, permissions and network access so that they cannot reasonably be used to break this Policy.
3. Prohibited uses#
You may not use the Services, or allow any agent or end user to use them, to:
3.1 Break the law or violate others' rights#
- Engage in, promote or facilitate illegal activity, including trafficking, illegal goods or services, or fraud.
- Infringe, misappropriate or violate intellectual property, privacy or publicity rights.
- Violate U.S. export controls or sanctions, or provide access to the Services to any person or entity in a country or region subject to comprehensive U.S. sanctions, or to any party on a U.S. government restricted-party list.
3.2 Harm children#
- Create, store, process or distribute child sexual abuse material (CSAM), including AI-generated CSAM, or facilitate grooming or exploitation of minors. Promigence reports apparent CSAM to the National Center for Missing & Exploited Children (NCMEC) and other authorities as required by law.
3.3 Compromise computer systems and networks#
- Scan, probe, exploit or attack any system, network or application you do not own or are not explicitly authorized to test.
- Create, host, run or distribute malware, ransomware, worms, credential stealers or other malicious code intended for use against third parties.
- Launch or coordinate denial-of-service attacks, or operate botnets or command-and-control infrastructure.
- Gain unauthorized access to accounts, systems or data, including through credential stuffing, brute force or social engineering.
- Intercept communications or monitor devices without authorization.
3.4 Attack or circumvent the Services#
- Attempt to break out of a sandbox, access other customers' sandboxes or data, or access the underlying platform that runs the Services.
- Probe the Services for vulnerabilities, or perform load or penetration testing on them, except under the Promigence Vulnerability Disclosure Policy or with our written permission.
- Circumvent rate limits, quotas, spend caps, billing, metering, network controls, monitoring or other safeguards.
- Obtain free credits, trials or promotional offers more than once, or by using false or borrowed identities, multiple accounts, automation or any other means the offer's terms do not allow.
- Create accounts through automation, operate multiple accounts to evade limits or enforcement, or return after suspension.
3.5 Abuse compute and network resources#
- Mine cryptocurrency or run any proof-of-work or similar computation for profit, unless a written agreement with Promigence expressly allows it.
- Run sustained, resource-intensive workloads unrelated to the purposes the Services are offered for (AI agents, evaluations, reinforcement learning, CI and software-development workloads) that degrade the Services for other customers.
- Run open proxies, VPN exit nodes, anonymization relays or residential-proxy services.
- Use sandboxes for general file hosting, media streaming, peer-to-peer file sharing or content delivery unrelated to those purposes.
- Resell, sublicense or re-expose raw sandbox capacity to third parties, unless you have a signed platform agreement with Promigence that permits it.
3.6 Send spam or conduct fraud#
- Send unsolicited bulk email, messages or calls, or run automated account creation or fake-engagement campaigns on third-party platforms.
- Run phishing, scams, carding, payment fraud or impersonation schemes.
- Scrape websites or services in violation of their terms or technical access controls, or at a volume that impairs their operation.
3.7 Cause serious real-world harm#
- Develop, design or acquire weapons, including biological, chemical, radiological, nuclear or high-yield explosive weapons.
- Disrupt or gain unauthorized access to critical infrastructure such as power, water, healthcare, financial, telecommunications or transportation systems.
- Promote or facilitate terrorism, violent extremism, targeted harassment or violence.
3.8 Violate privacy or deceive people#
- Collect, process or infer sensitive personal data (health, biometric, financial, precise location) without the legally required notice and consent.
- Track, surveil or profile individuals without their consent.
- Deploy agents that pretend to be human when interacting with people, or that impersonate real people or organizations without authorization.
4. Permitted security research#
Security research is welcome on Promigence. You may run exploit code, fuzzers, malware samples, red-team evaluations and offensive-security tooling inside your sandboxes if all of the following are true:
- The targets are systems you own, systems you have written authorization to test, or deliberately vulnerable test environments.
- Network access for that workload is restricted to those targets.
- Malware samples are not allowed to propagate outside your sandbox.
Research into the Promigence platform itself must follow the Promigence Vulnerability Disclosure Policy.
5. Your responsibilities#
You must:
- Keep API keys and credentials secret, and rotate them if compromised.
- Apply least-privilege permissions and network rules to your agents.
- Pass this Policy through to your own end users if they can direct agents on the Services.
- Tell us promptly at support@promigence.ai if you learn of a violation involving your account.
- Cooperate with reasonable requests for information during an investigation.
6. Enforcement#
If we believe this Policy has been violated, we may, in proportion to the risk:
- Contact you and ask you to fix the issue.
- Throttle, pause or terminate specific sandboxes or workloads.
- Restrict network access or features.
- Suspend or terminate your account.
- Report activity to law enforcement or other authorities where required or appropriate.
We will usually give notice and a chance to fix the issue first. We may act immediately, without notice, if activity threatens the security or availability of the Services, other customers or third parties, or if the law requires it. When deciding what to do, we consider the severity of the violation, whether it was intentional, and the safeguards you had in place. You may appeal an enforcement decision within 30 days by writing to support@promigence.ai with the subject "Appeal".
7. Reporting#
To report abuse originating from Promigence infrastructure, including attacks, spam or phishing traced to our network, write to support@promigence.ai with the subject "Abuse report" and include timestamps, source addresses and supporting evidence. To report a security vulnerability in the Services, follow the Vulnerability Disclosure Policy at www.promigence.ai/legal/vulnerability-disclosure.
8. Responsibility for your agents#
You are solely responsible for the agents, code, prompts, data and workloads you run on the Services, and for every action, decision, output and consequence they produce, whether or not you directed them. Promigence does not control, review or endorse what your agents do, and is not responsible for any loss or harm that results from them, including actions taken against third-party systems, transactions made, communications sent, or data altered or deleted by your agents.
9. Disclaimers, liability, indemnity and security incidents#
The disclaimers of warranties, the limitation of liability, your indemnification obligations and the security-incident terms in the Promigence Terms of Service apply in full to this Policy and to everything done under it. Nothing in this Policy creates any warranty or expands any liability of Promigence.
10. Changes#
We may update this Policy as our Services and the risks change. We will post the updated Policy with a new "last updated" date and, for material changes, notify account owners by email at least 30 days before they take effect, unless a faster change is needed for security or legal reasons. Continued use after the effective date means you accept the updated Policy.