Acceptable Use Policy
Last updated: August 19, 2026
1. Purpose
This Acceptable Use Policy ("AUP") governs your use of Cyphrex services. By using Cyphrex, you agree to comply with this policy. Violations may result in suspension or termination of your account.
2. General Principles
You must use Cyphrex:
- In compliance with all applicable laws and regulations
- In a manner that respects the rights of others
- Without interfering with the security or integrity of the Service
- Without attempting to gain unauthorized access to systems or data
- In accordance with our Terms of Service and Privacy Policy
3. Prohibited Uses
You may NOT use Cyphrex to monitor or enable AI agents that:
Illegal Activities
- Engage in or facilitate any illegal activity
- Violate intellectual property rights (piracy, copyright infringement)
- Facilitate fraud, identity theft, or financial crimes
- Distribute malware, ransomware, or malicious code
- Conduct unauthorized penetration testing or hacking
- Violate export control laws or trade sanctions
Harmful Content
- Generate or distribute child sexual abuse material (CSAM)
- Promote violence, terrorism, or extremism
- Facilitate human trafficking or exploitation
- Generate content that incites hatred or discrimination
- Produce deepfakes for harassment or non-consensual purposes
- Create or distribute revenge pornography
Abuse and Harassment
- Harass, threaten, or stalk individuals
- Conduct coordinated harassment campaigns
- Generate spam or unsolicited communications at scale
- Engage in doxxing or privacy violations
- Impersonate others to deceive or defraud
Misinformation and Manipulation
- Generate coordinated inauthentic behavior or bot networks
- Create political disinformation campaigns
- Manipulate financial markets through false information
- Generate fake reviews or testimonials
- Conduct astroturfing or fake grassroots campaigns
Privacy Violations
- Scrape personal data without consent
- Build surveillance tools for stalking or monitoring without consent
- Violate GDPR, CCPA, or other privacy regulations
- Process children's data without proper safeguards
- Collect or infer sensitive attributes without lawful basis
Platform Abuse
- Circumvent rate limits or usage restrictions
- Create multiple accounts to exceed sandbox limits
- Share API keys across organizations without authorization
- Reverse engineer or decompile the Service
- Benchmark the Service against competitors without permission
- Resell or redistribute the Service without authorization
4. Agent Responsibility
Important: You are responsible for your agents' actions.
- Cyphrex provides monitoring and enforcement tools, not liability coverage
- You must configure appropriate behavior profiles to prevent violations
- You must review audit logs regularly
- You must respond to alerts promptly
- You are liable for damages caused by your agents
- Cyphrex may suspend agents that violate this AUP
4.5 Blockchain SSN responsibilities
If you use Blockchain SSN features:
- Self-custody: You are solely responsible for securing private keys. Lost keys cannot be recovered.
- No recovery: Cyphrex cannot reverse blockchain transactions or recover lost self-custody keys.
- Gas fees: You are responsible for ensuring sufficient SOL in your wallet for self-custody transactions you initiate.
- Public data: Blockchain SSN data is public. Do not register agents with sensitive naming or metadata you would not want exposed on-chain.
- No warranty:Blockchain identity services are provided "as-is" with no warranty of uninterrupted access or error-free operation.
5. Security Requirements
You must:
- Keep API keys secure and confidential
- Not expose API keys in client-side code or public repositories
- Use HTTPS/TLS for all API communications
- Implement authentication and authorization for agent access
- Rotate compromised keys immediately
- Report security vulnerabilities to hello@cyphrex.io
- Not attempt to access other customers' data or agents
- Not probe or test security without written authorization
6. Rate Limits and Fair Use
To ensure service availability for all users:
- API rate limits apply per plan tier (see pricing page)
- Excessive burst traffic may be throttled
- Do not attempt to circumvent rate limits
- Do not generate artificial load for testing without approval
- Contact us if you need higher limits (upgrade or custom plan)
Current rate limits:
- Sandbox: 25,000 enforced actions total
- Core: 5M enforced actions per year
- Scale: 25M enforced actions per year
- Enterprise: Custom limits
7. Content Monitoring
Cyphrex logs agent actions for security and compliance:
- We log action types, timestamps, API endpoints, and metadata
- We do NOT log full request/response payloads by default
- We may scan for prohibited content patterns (malware signatures, CSAM hashes)
- Automated systems flag potential violations for review
- We may manually review flagged content to enforce this AUP
- We report illegal content (CSAM, terrorism) to authorities as required by law
8. Enforcement and Consequences
If you violate this AUP, we may:
- Issue a warning for minor or first-time violations
- Suspend specific agents that are causing violations
- Suspend your account temporarily while we investigate
- Terminate your account immediately for severe violations
- Report to authorities for illegal activity
- Pursue legal action for damages caused to Cyphrex or others
Immediate termination (no warning) applies to:
- Child sexual abuse material (CSAM)
- Terrorism or violent extremism
- Large-scale fraud or financial crimes
- Malware distribution or hacking
- Coordinated harassment campaigns
9. Reporting Violations
If you observe violations of this AUP by other users:
- Report to hello@cyphrex.io
- Include details: account email, agent ID, timestamps, evidence
- We investigate all reports and take action as appropriate
- We do not disclose enforcement actions to reporters (privacy)
For security vulnerabilities, report to hello@cyphrex.io.
10. Appeals
If your account is suspended or terminated:
- You may appeal by emailing hello@cyphrex.io
- Include your account email and explanation
- We review appeals within 5 business days
- Decisions are final and at our sole discretion
- No refunds for violations, even if appeal is successful
11. Research and Good Faith Use
We support legitimate research and security testing:
- Academic research on AI safety is permitted with prior approval
- Security researchers may test Cyphrex security with written permission
- Bug bounty program available (see hello@cyphrex.io)
- Contact hello@cyphrex.io for research collaborations
12. Changes to This Policy
We may update this AUP to address new threats or legal requirements. Material changes will be notified via email or dashboard notice 30 days in advance. Continued use after changes constitutes acceptance.
13. Sub-processors and infrastructure
The Service relies on third-party infrastructure listed in our Privacy Policy, including:
| Name | Purpose | Data location | Website |
|---|
| Supabase Inc. | Database and authentication | USA (AWS us-east-1) | supabase.com |
| Railway Corp. | Application hosting | USA (us-west-2) | railway.app |
| Resend Inc. | Transactional email delivery | USA | resend.com |
| Sentry (Functional Software, Inc.) | Error monitoring and performance tracking | USA | sentry.io |
| BetterStack | Uptime monitoring | EU | betterstack.com |
| Solana Foundation | Public blockchain anchoring of audit Merkle roots | Decentralized (global validators) | solana.org |
Only Merkle root hashes are written on chain. No customer content, payload data, or personal data is published to the blockchain.
Blockchain SSN (self-custody)
All Blockchain SSN registrations use self-custody. You own and control your agent's private keys and wallet. Cyphrex never holds, accesses, or manages private keys. Cyphrex may cover Solana gas fees on paid plans as a convenience. Blockchain transactions are irreversible. Cyphrex is not responsible for lost wallet access, network failures, or irreversible transactions.