This Acceptable Use Policy (the “AUP”) explains the minimum rules for using KEYVERA websites, accounts, APIs, model access, and related services. It forms part of the KEYVERA Terms of Service.
The examples below are not exhaustive. You remain responsible for your Customer Content, applications, end users, Output, and compliance with applicable law and provider-specific restrictions.
Core expectations
- Use the Services lawfully and respect the rights and safety of others.
- Do not facilitate exploitation, fraud, violence, malware, unlawful surveillance, or other serious harm.
- Protect API Keys and do not bypass safeguards, usage limits, or access controls.
- Apply appropriate human oversight to high-impact or regulated uses.
- Follow restrictions disclosed for the provider and model you select.
- Report suspected compromise or abuse promptly.
1. Scope and responsibility
This AUP applies to anyone who accesses or uses the Services, including Account owners, authorised users, developers, contractors, applications, and end users acting through a customer implementation.
Business Customers must take reasonable steps to communicate and enforce these requirements for their authorised users and end users. Access to a model does not mean a proposed use is lawful or permitted.
2. Illegal activity and serious harm
You must not use the Services to create, facilitate, coordinate, encourage, or materially assist:
- activity that violates applicable law, sanctions, export controls, court orders, or regulatory requirements;
- child sexual abuse material, sexual exploitation, trafficking, grooming, or abuse of a minor;
- unlawful violence, terrorism, weapon acquisition or deployment, or instructions intended to cause serious physical harm;
- non-consensual intimate content, sexual extortion, stalking, targeted harassment, or credible threats;
- suicide or self-harm encouragement or instructions designed to increase the likelihood of immediate harm; or
- any other conduct whose purpose is to cause unlawful death, injury, exploitation, or severe property damage.
3. Fraud, deception, and manipulation
You must not use the Services for fraud, scams, phishing, impersonation, credential theft, spam, deceptive commercial practices, fake reviews, forged evidence, or manipulation that unlawfully deprives another person of money, property, rights, or informed choice.
Synthetic or AI-generated content must be disclosed where required by law or where omission would make the content materially deceptive.
4. Cybersecurity and platform abuse
You must not use the Services to:
- develop, deploy, or improve malware, ransomware, destructive payloads, credential-stealing tools, or unauthorised intrusion capabilities;
- gain or maintain access to systems, networks, accounts, or data without permission;
- probe, scan, stress, disrupt, overload, or test KEYVERA or third-party infrastructure without written authorisation;
- bypass safety controls, rate limits, model restrictions, geographic restrictions, billing controls, or access controls;
- scrape or extract non-public parts of the Services other than through documented interfaces; or
- share, publish, sell, lease, or transfer API Keys or Accounts except as expressly permitted by the Terms.
Good-faith defensive security work must be authorised, appropriately scoped, and performed in a way that avoids harm to third parties.
5. Privacy, surveillance, and personal data
You must not unlawfully collect, infer, expose, identify, track, monitor, or make decisions about a person using personal data. You must have a valid lawful basis and all required notices, permissions, and safeguards before submitting personal data to the Services.
Do not submit highly sensitive, regulated, confidential, biometric, health, financial, or government-identification data unless you have confirmed that the selected model, provider, configuration, contract, and security measures are appropriate.
6. High-impact and regulated decisions
You must not use Output as the sole basis for decisions that produce legal or similarly significant effects in employment, credit, housing, education, healthcare, insurance, essential services, law enforcement, migration, or another regulated field where applicable law requires human review, explanation, testing, or other safeguards.
You are responsible for bias testing, accuracy review, transparency, recordkeeping, appeal mechanisms, professional oversight, and compliance appropriate to the context.
7. Rights and protected information
You must not submit or generate material in a way that infringes intellectual property, privacy, publicity, confidentiality, trade-secret, database, or other rights. Do not submit data or content you are not authorised to process.
Output may be inaccurate, non-unique, or contain third-party material. You must review Output and obtain any required permissions before using or publishing it.
8. Provider and model restrictions
Different models may have additional restrictions concerning content, safety, geography, rate limits, data handling, or permitted applications. You must comply with the restrictions identified for the selected model in the Provider and Model Terms, Documentation, Account, or purchase flow.
If two applicable restrictions differ, comply with the stricter requirement unless KEYVERA confirms otherwise in writing or mandatory law requires a different result.
9. Enforcement
KEYVERA may investigate suspected violations and may warn, rate-limit, filter, block a request, revoke a credential, restrict a model, suspend an Account, or terminate access where reasonably necessary to protect users, providers, KEYVERA, or the public.
We will consider the nature, severity, frequency, intent, potential harm, and whether the issue can reasonably be corrected. Where appropriate and legally permitted, we may provide notice and an opportunity to respond. Immediate action may be taken for urgent security, legal, fraud, or safety risks.
10. Reporting and changes
Report suspected API Key compromise, platform abuse, or a serious policy violation to legal@keyvera.cloud. Do not include unnecessary sensitive personal data in the first report.
KEYVERA may update this AUP as laws, model capabilities, provider requirements, and risks change. Material changes affecting existing customers will be communicated where required by the Terms or applicable law.