Legal
Guardyx AI Acceptable Use Policy
Version 1.0
Effective May 14, 2026 · Last updated May 14, 2026
This Acceptable Use Policy (“AUP”) governs Customer’s access to and use of the Guardyx AI platform, APIs, SDKs, hosted services, customer portal, integrations, and related services (collectively, the “Services”) operated by Code Above Lab, Inc. d/b/a Guardyx AI (“Guardyx”).
This AUP is incorporated by reference into the Guardyx AI Terms of Service.
Capitalized terms not defined in this AUP have the meanings set forth in the Guardyx AI Terms of Service.
Contents
- Purpose
- Prohibited Conduct
- AI and Agent Restrictions
- Security Responsibilities
- Regulated Data
- Enforcement
- Reporting Violations
- Changes to this Policy
1. Purpose
Guardyx AI provides governance infrastructure for AI agents, workflows, approvals, policy enforcement, execution gateways, observability, audit logging, and tool integrations.
Because the Services may enable autonomous or semi-autonomous execution against third-party systems, Guardyx requires Customers to use the Services responsibly and lawfully.
Customers are responsible for ensuring that all Authorized Users, Agents, workflows, integrations, and third-party systems comply with this AUP.
2. Prohibited Conduct
Customer may not use the Services to:
- use the Services in a manner that violates applicable laws, regulations, sanctions, or export controls, including through Agent or Tool configurations that result in such violations;
- engage in fraud, phishing, impersonation, credential theft, or identity deception, except where Customer has documented written authorization from the targeted party or, in the case of internal security testing, from authorized personnel of the targeted organization, and the activity complies with applicable law;
- deploy malware, ransomware, spyware, cryptominers, or malicious code;
- interfere with the integrity, security, or availability of the Services;
- conduct denial-of-service attacks or resource exhaustion attacks;
- gain unauthorized access to systems, networks, tenants, or data;
- scrape, exfiltrate, or harvest data in material violation of applicable law or the target system’s terms of service, as reasonably determined by Guardyx;
- violate intellectual property, privacy, confidentiality, or publicity rights;
- facilitate human trafficking, terrorism, violent extremism, or organized crime;
- distribute child sexual abuse material or non-consensual intimate imagery;
- engage in unlawful surveillance, stalking, or harassment;
- publish misleading competitive benchmarks or performance evaluations that are not based on then-current versions of the Services and that do not include sufficient methodology to permit independent reproduction;
- register Tools with misleading schemas, deceptive descriptions, manipulated risk classifications, or intentionally incomplete metadata designed to evade approval workflows, policy enforcement, audit logging, or governance controls;
- use the Services or tool gateway infrastructure to circumvent third-party API restrictions, geographic restrictions, access controls, or contractual usage limitations;
- manipulate idempotency keys, retry controls, request identifiers, or audit correlation identifiers to obscure activity, evade rate limits, bypass policy enforcement, or impair auditability;
- probe, test, or attempt to bypass tenant isolation boundaries or multi-tenant controls without prior written authorization from Guardyx;
- register or operate Tools designed to exfiltrate data from third-party systems, harvest data from competitor services, move data across tenant boundaries without authorization, or circumvent data access restrictions;
- interfere with the generation, integrity, or completeness of audit logs, telemetry, canonical events, metering, or observability records, including through SDK manipulation, agent configuration, or workflow design intended to suppress, distort, or falsify such records;
- configure Agents, SDKs, workflows, or Tools to suppress required event emission or generate false or misleading audit records;
- circumvent or interfere with usage metering, billing systems, quota enforcement, or rate limiting.
3. AI and Agent Restrictions
Customer may not use the Services to:
- deploy autonomous weapons systems;
- perform fully automated high-risk legal, medical, employment, financial, insurance, housing, or educational decision-making without qualified human oversight;
- conduct automated exploitation, penetration testing, or vulnerability discovery against systems without authorization;
- deploy self-propagating or self-replicating autonomous systems;
- configure or operate Agents that recursively spawn unbounded sub-agents, recursive workflows, or approval requests in a manner that causes resource exhaustion, queue exhaustion, or denial-of-service conditions;
- use low-privilege Agents to invoke higher-privilege Agents, Tools, or workflows in order to bypass governance policies, approval requirements, or access controls;
- use Guardyx-hosted Agents, workflows, or Tools to attack, interfere with, or exploit other Guardyx-hosted Agents, workloads, tenants, or systems;
- bypass configured approval workflows or governance controls;
- configure approval workflows in bad faith, including self-approving Sensitive Actions, designating fictitious approvers, creating rubber-stamp approval chains intended to defeat substantive review, or retroactively modifying approval policies to legitimize previously executed actions;
- generate excessive or intentionally overwhelming approval requests designed to fatigue, confuse, or manipulate reviewers into inadvertent approval decisions;
- disable or interfere with logging, observability, or audit features associated with approvals, governance decisions, or Sensitive Actions;
- configure or operate Agents in a manner that performs destructive or irreversible actions while bypassing approval workflows, review safeguards, or governance controls that Guardyx makes available, or that Customer’s own policies or applicable law require;
- generate deceptive synthetic identities or impersonation systems intended to defraud, deceive, or harm;
- conduct coordinated disinformation campaigns or social engineering attacks.
Customer is responsible for validating Agent actions before production deployment.
Customer may not use the Services to train, improve, benchmark, or evaluate competing AI agent infrastructure platforms through unauthorized extraction or replication of the Services, use of Guardyx-generated telemetry for competitive evaluation purposes, or systematic comparative analysis intended for publication or competitive product development.
4. Security Responsibilities
Customer must:
- maintain appropriate credential and secret management practices;
- rotate API keys and authentication tokens appropriately;
- implement least-privilege access controls;
- monitor audit logs and telemetry for suspicious activity;
- configure approvals appropriately for Sensitive Actions;
- ensure approver configurations comply with Customer’s own internal governance, compliance, and separation-of-duties requirements;
- promptly revoke compromised credentials;
- notify Guardyx promptly of security incidents involving the Services.
5. Regulated Data
Customer may not process regulated data through the Services unless:
- legally required safeguards are implemented;
- Customer has executed any required agreements with Guardyx;
- Customer independently verifies suitability of the Services for the applicable regulatory regime.
Examples may include:
- protected health information (PHI);
- payment card data subject to PCI DSS;
- government classified information;
- export-controlled technical data;
- highly sensitive biometric or genetic data;
- biometric data subject to laws such as BIPA;
- children’s data subject to COPPA or GDPR Article 8.
6. Enforcement
Guardyx may investigate suspected violations of this AUP in accordance with the Guardyx Privacy Policy, the applicable Data Processing Addendum, and Section 17 and Section 18 of the Guardyx AI Terms of Service.
Guardyx may access audit logs, telemetry, approval records, tool invocation records, and related operational metadata reasonably necessary to investigate suspected violations. Any access to Customer Data during investigations will remain subject to the applicable DPA and Privacy Policy.
Customers agree to reasonably cooperate with Guardyx investigations relating to suspected violations of this AUP.
Guardyx will use commercially reasonable efforts to conduct investigations in a proportionate and appropriately documented manner.
Enforcement actions may include:
- warnings or requests to cure minor or first-time violations;
- temporary suspension of specific workloads, Agents, Tools, or integrations during investigation;
- immediate suspension for violations creating security, operational, or legal risk;
- immediate termination without cure period for severe violations involving malware, fraud, active attacks, child sexual abuse material, non-consensual intimate imagery, autonomous weapons systems, or other unlawful conduct.
Guardyx will generally seek to apply enforcement measures proportionate to the nature and severity of the violation, but reserves the right to take immediate action where reasonably necessary to protect the Services, Customers, third parties, or the public.
Guardyx may cooperate with law enforcement or regulatory authorities where required by law.
Guardyx reserves the right to remove or restrict access to workloads, integrations, Agents, or activities that create security, operational, legal, or material reputational risk to Guardyx arising from Customer’s violation of this AUP or applicable law.
7. Reporting Violations
Suspected violations may be reported to:
8. Changes to this Policy
Guardyx may update this AUP from time to time.
Material changes that adversely affect Customer’s rights or obligations will be communicated at least thirty (30) days in advance through the Services, email, or other reasonable means, consistent with Section 30 of the Guardyx AI Terms of Service.
See also: Terms of Service · Data Processing Addendum · Privacy Policy · Cookie Policy.