Version: 1.0 Effective date: 2026-05-22
This Acceptable Use Policy (the "AUP") governs how customers and authorised users may use the Penaxtra LLM Security Posture Management platform (the "Service"). It is incorporated into the Terms of Service at /legal/terms by reference. Violation of this AUP is grounds for suspension or termination.
1. Authorisation to test
The Service performs adversarial security testing of LLM systems. You may use the Service only against:
- LLM systems and endpoints owned by you or your organisation; or
- LLM systems and endpoints for which you have explicit written authorisation from the system owner to perform security testing.
Unauthorised scanning of third-party systems is prohibited and may violate computer-misuse legislation in your jurisdiction.
2. Prohibited content and conduct
You may not use the Service to:
- Generate, distribute, or store malware, exploit code intended for unauthorised use, or weaponised payloads designed to bypass security controls outside of authorised research.
- Engage in mass credential harvesting, account enumeration, or unsolicited credential testing against third-party services.
- Process child sexual abuse material, content depicting non-consensual intimate imagery, or other content that is illegal under applicable law.
- Conduct denial-of-service attacks, send unsolicited bulk communications, or otherwise disrupt third-party infrastructure.
- Misrepresent your identity or the source of communications produced through the Service.
- Violate any person's intellectual property, privacy, or publicity rights.
3. Fair use limits
Subscription tiers come with documented scan, endpoint, and storage allowances. Sustained usage materially in excess of those allowances may result in throttling, tier upgrade prompts, or for repeated violations, suspension. Enterprise contracts may negotiate alternative limits.
4. Probe authoring
Customers may author custom adversarial probes. Custom probes must:
- Target only systems the customer is authorised to test under section 1.
- Comply with applicable law in the jurisdiction of the customer, the target system, and any data subjects whose personal data appears in the probe.
- Not embed live credentials or production secrets except where required for an authorised test and removed before publication.
5. Runtime gateway
The runtime gateway agent inspects traffic from agents to LLM providers. Customers may not use the gateway to:
- Filter, modify, or block traffic that the customer does not have the legal right to inspect (for example, employee communications outside an authorised monitoring policy).
- Strip or forge security headers, signatures, or audit metadata produced by upstream services.
- Re-export the gateway binary or rule blob outside the customer's organisation without separate written agreement.
6. Reporting violations
If you become aware of a violation of this AUP by another user, please report it to [email protected]. We treat reports confidentially.
7. Enforcement
We may, at our discretion, suspend or terminate access in response to violations of this AUP, with notice where the circumstances allow. For severe or repeated violations, suspension may be immediate. The procedural details are set out in the Terms of Service at /legal/terms.
8. Updates
We may update this AUP from time to time. Material changes will be communicated at least 30 days in advance.
9. Contact
[email protected] for AUP reports; [email protected] for questions about the policy itself.