Acceptable use policy
- Last updated
- 2026-04-19
- Effective
- 2026-04-19
This Acceptable Use Policy (the “AUP”) describes the conduct we require of every Osyra customer (each a “Customer”) and their end-users (the “Users”). The AUP is incorporated by reference into the Terms of Service. Breach of this AUP is a material breach of the Terms and may result in suspension, termination, refund forfeiture, or referral to law enforcement.
01Lawful use
You may use the Service only for lawful purposes. You may not use it to:
- plan, facilitate, or carry out any illegal activity;
- infringe any third party's intellectual-property, privacy, or other right;
- violate any applicable export-control, sanctions, anti-bribery, or anti-money-laundering law;
- process data of natural persons under the age of 16 except where you have a lawful basis to do so;
- misrepresent yourself, your organisation, or the source of your content.
[Placeholder — counsel to add: jurisdiction-specific prohibitions, OFAC SDN screening commitments, dual-use export carve-outs.]
02Prohibited content and use cases
You may not use the Service — directly or as part of an automated workflow — to generate, host, store, transmit, or disseminate any of the following:
- Child sexual abuse material (CSAM) or any content that sexually exploits or endangers minors. Zero tolerance. We report apparent CSAM to the National Center for Missing & Exploited Children (NCMEC) and equivalent authorities and preserve evidence as required by law.
- Non-consensual intimate imagery, including AI-generated or synthesised imagery depicting real people without their consent.
- Content that promotes terrorism, mass violence, or genocide, or that incites imminent lawless action against identifiable persons or groups.
- Operational instructions for weapons of mass destruction — chemical, biological, radiological, or nuclear — including synthesis pathways, delivery mechanisms, or evasion of detection.
- Cyber-attack preparation in violation of applicable law, including malware authoring, ransomware operation, exploit development for unauthorised systems, credential stuffing, or evasion of CISA-listed defensive measures (where applicable to the Customer).
- Content that targets individuals for harassment, doxing, or swatting.
- Fraudulent or deceptive content, including phishing kits, scam-bait scripts, fabricated identity documents, or synthesised media intended to deceive (e.g. deepfakes for fraud or election interference).
- Content that depicts gratuitous, real-world violence or torturefor entertainment.
- Hate content that promotes discrimination or violence against protected groups (race, ethnicity, religion, gender, sexual orientation, disability, etc.).
High-stakes domains.Without a separate written agreement, you may not rely on the Service for legally-binding decisions in healthcare, criminal justice, employment, immigration, education, social benefits, or insurance. The Service's outputs are model-generated and may be incorrect, biased, or unsuitable for these contexts.
[Placeholder — counsel to confirm: enforceable definitions per item, the Trust & Safety adjudication ladder, NCMEC reporting workflow, EU AI Act prohibited-use article (Art. 5) overlay, and content-policy version history.]
03Security and integrity
You may not:
- probe, scan, or test the vulnerability of the Service or any system or network connected to it, except under the safe-harbour terms of our responsible-disclosure programme;
- attempt to bypass authentication, access controls, rate limits, quotas, or billing mechanisms;
- introduce malware, viruses, or other malicious code into the Service;
- interfere with or disrupt the Service or any User's use of it (e.g. DoS, DDoS, resource exhaustion);
- scrape, crawl, or use any non-public interface in a manner inconsistent with documented usage;
- reverse-engineer, decompile, or otherwise attempt to extract the source code, models, or weights underlying the Service.
[Placeholder — counsel to add: explicit list of prohibited security actions, bot-mitigation controls reference, fraud-prevention provisions.]
04Service abuse
You may not:
- resell, sublicense, or rent the Service except under an authorised reseller agreement;
- use the Service to develop, train, or fine-tune a model or product that competes with Osyra;
- send unsolicited bulk communications (spam) or content that violates the CAN-SPAM Act, CASL, or equivalent laws;
- create accounts by automated means or use false identities to circumvent enforcement;
- share credentials, API keys, or tokens across organisational boundaries;
- generate synthetic engagement (fake reviews, follower counts, etc.).
Rate limits and quotas. The Service enforces rate limits and Plan-level quotas. Repeated attempts to circumvent or exceed limits without authorisation may result in throttling, suspension, or termination. Where you exceed soft limits on Enterprise Plans, we will reach out to align on capacity — we do not silently block.
[Placeholder — counsel to add anti-circumvention and reseller carve-outs.]
05Model-provider terms
Each upstream model provider (OpenAI, Anthropic, Google, Mistral, Cohere, etc.) has its own usage policy. Your use of a model via Osyra is also governed by the provider's policy, which may be more restrictive than this AUP for certain use cases. The provider's terms are available in our Model Provider Catalogue and on each provider's website. [Placeholder — counsel to confirm flow-down language and disclosure of any provider-specific carve-outs.]
06Enforcement
If we identify or are notified of a suspected breach, our enforcement ladder is:
- Warning.For first-time, low-severity breaches we contact the Customer's administrator with notice and an opportunity to remediate.
- Suspension. For repeated, ongoing, or higher-severity breaches we may suspend the affected workspace or feature with notice and a remediation window.
- Termination. For material, uncured, or egregious breaches we may terminate the account in accordance with the Terms.
For breaches involving CSAM, imminent threat of physical harm, or active cyber-attack, we may suspend or terminate without prior notice and report to law enforcement as required.
Appeals. Customers may appeal an enforcement action by emailing appeals@osyra.ai with the workspace identifier and a written statement. We respond within five business days.
[Placeholder — counsel to confirm: full appeal procedure, timing of refunds on termination, retention of evidence for legal proceedings, third-party-notice obligations under EU DSA where applicable.]
07Reporting violations
Report suspected AUP violations to abuse@osyra.ai. When possible, include:
- the workspace identifier (if known);
- the relevant request identifier(s) or receipt ID(s) from the dashboard or our receipts feed;
- a description of the suspected violation and any supporting evidence.
Reports of CSAM should be sent immediately to abuse@osyra.ai with subject “CSAM report”. Do not include sample content; describe the location only.
We acknowledge AUP reports within one business day and complete triage within five business days. We do not disclose the identity of the reporter to the affected Customer except where required by law.
[Placeholder — counsel to confirm reporter-protection commitments, EU DSA trusted-flagger procedures, retention of report evidence.]
08Changes to this AUP
We may update this AUP. Material changes are notified to the primary account contact at least 30 days before they take effect, and posted here with a new “Last updated” date. Where a change is required to comply with new law or to address an imminent harm, we may update on shorter notice. [Placeholder — counsel to confirm version-archive policy.]