Acceptable Use Policy
This Acceptable Use Policy ("**AUP**") sets out what you may and may not do when you use ACQI websites, applications, APIs, and related services. It is incorporated into the **Terms of Service** and into any signed MSA.
{{EFFECTIVE_DATE}}— to be confirmed before final publication{{LAST_UPDATED}}— to be confirmed before final publication{{LEGAL_EMAIL}}— to be confirmed before final publication{{SECURITY_EMAIL}}— to be confirmed before final publication
Page is published for transparency; founder will fill these before the final version goes out under counsel review.
# Acceptable Use Policy (AUP)
Effective date: {{EFFECTIVE_DATE}} Last updated: {{LAST_UPDATED}} Applies to: All use of ACQI websites, applications, APIs, and related services.
This AUP is incorporated into the Terms of Service and any MSA. Violation may result in suspension or termination and, where appropriate, reporting to authorities.
---
1.Lawful use only
You may use ACQI only for lawful purposes and only with documented authorisation to access the systems and data you target. Buying or installing ACQI is not authorisation to access a third party’s environment (including an M&A target).
Liability context: Product risks & tooling liability.
---
2.Prohibited activities
You must not, and must not allow users to:
2.1 Unauthorised access & scanning
- Scan, probe, or extract data from systems, tenants, or networks without permission of the system owner (and any required deal/protocol authority)
- Use ACQI as a substitute for a contracted penetration test without explicit offensive-security authorisation and rules of engagement
- Use ACQI for credential stuffing, password spraying, exploitation, ransomware enablement, or lateral-movement tooling
- Bypass MFA, conditional access, or security controls except as expressly authorised by the system owner for a legitimate, scoped assessment
- Expand scan scope beyond written approvals (subscriptions, forests, OUs, geo, business units)
- Conceal scanning activity from parties who must approve it under your policies or a clean-team protocol
2.2 Production harm & reckless automation
- Run destructive or write operations (migration, remediation, bulk changes) in production without change control, backups, and a named approver
- Disable safety checks, force retries that thrash production, or ignore provider throttling in a way that degrades third-party services
- Use the Services to intentionally disrupt a target’s operations outside an authorised test window
2.3 Abuse of the platform
- Interfere with or disrupt ACQI infrastructure or other customers
- Introduce malware, ransomware, or destructive code
- Overload APIs or modules beyond contracted limits (denial-of-service)
- Circumvent licence, billing, or feature restrictions
2.4 Data misuse
- Upload or process data you are not legally entitled to process
- Use the Services to dox, harass, or unlawfully surveil individuals
- Exfiltrate personal data for sale, spam, or purposes beyond diligence/integration
- Retain or share target diligence data in breach of NDA, clean-team, or purpose-limitation rules
- Store cardholder data, unrestricted PHI, special-category data at scale, children’s data, or ITAR-controlled technical data in the Platform unless a separate written agreement expressly covers it
- Treat discovery exports as uncontrolled “open files” on unmanaged devices
2.5 AI misuse
- Use ARIA or other AI features to generate illegal content, malware, or phishing
- Paste passwords, tokens, private keys, or full regulated datasets into AI prompts
- Attempt to extract model weights, system prompts, or other customers’ data via AI features
- Rely on AI outputs as sole authority for irreversible production, deal, or employment decisions without human review
2.6 Misrepresentation & IP
- Impersonate ACQI or misrepresent affiliation
- Remove proprietary notices or reverse engineer except as permitted by law
- Publish ACQI non-public documentation or benchmarks in breach of confidentiality
- Represent ACQI outputs as an audit opinion, legal opinion, or ACQI certification of a third party’s estate
2.6 Sanctions & export
- Use the Services in breach of sanctions or export controls
- Provide access to denied parties
---
3.M&A and multi-party contexts
In diligence or integration scenarios involving a target company:
- You must have a lawful basis and contractual/engagement authority (e.g. NDA, LOI, SPA diligence rights, board authority, clean-team protocol). Commercial interest alone is not enough.
- You are responsible for clean-team walls, antitrust / gun-jumping restrictions, and blackout obligations.
- Do not use ACQI to access a target’s environment beyond the scope agreed with the target or your client.
- Do not use target data extracted via ACQI for competitive purposes outside the permitted diligence purpose.
- You remain liable to the target, other bidders, employees, and regulators for misuse of extracted data—even if ACQI software performed the technical collection under your credentials.
---
4.Credential hygiene
- Prefer least-privilege service principals / accounts with time-boxed access
- Do not share credentials in tickets, screenshots, or AI chats
- Rotate secrets after engagements and after operator off-boarding
- Secure endpoints running the desktop client (disk encryption, patching, MFA on the workstation identity)
- Log who ran which discovery/migration job
---
5.Professional use & verification
- Services are for trained IT, security, and M&A technology professionals
- Material findings must be verified before signing, closing, cutover, or public disclosure
- Do not present dashboards as a “clean bill of health” from ACQI
---
6.Reporting abuse
Report suspected abuse or vulnerabilities: {{SECURITY_EMAIL}} Legal: {{LEGAL_EMAIL}}
We may investigate, suspend access, and preserve logs as needed for security and law enforcement cooperation. We may report credible unlawful access to authorities where required or appropriate.
---
7.Changes
We may update this AUP by posting a revised version. Material changes take effect on the date stated.
---
Draft for solicitor review.