KubernoGRC Acceptable Use Policy
1. Purpose
This Acceptable Use Policy (“AUP”) sets forth the rules and guidelines for using KubernoGRC services to ensure lawful, secure, and responsible use. This AUP governs all use of the Services, including use of KubernoGRC’s AI features, and applies alongside the Master Subscription Agreement (“Agreement”).
2. Scope
This AUP applies to all Customers, Authorized Users, and any party accessing or using KubernoGRC services.
3. Authorized Use
Customers and Authorized Users may access and use the Services solely: (a) for their own internal business purposes; (b) in accordance with the Agreement; and (c) within the scope of the applicable Order. Use of the Services on behalf of or for the benefit of third parties, or to provide competing, similar, or derivative services to third parties, is prohibited without KubernoGRC’s express prior written consent.
4. Prohibited Activities
Users must not engage in activities that:
• Violate any applicable laws or regulations.
• Involve unauthorized access, interference, or disruption of services.
• Transmit harmful code, malware, or engage in phishing or spamming.
• Infringe intellectual property rights or privacy rights of others.
In addition, Users must not:
• Submit or process data that violates the privacy rights of individuals without a lawful legal basis.
• Store, process, or transmit payment card data (PCI DSS in-scope data), Social Security numbers, government-issued identification numbers, or biometric data through the Services without KubernoGRC’s specific prior written authorization.
• Conduct or facilitate unauthorized security assessments, penetration testing, or vulnerability scans of KubernoGRC or any third party’s systems or infrastructure.
• Access the Services in a manner that imposes an unreasonable or disproportionately large load on KubernoGRC’s infrastructure, as determined by KubernoGRC in its reasonable judgment.
• Use automated scripts, bots, or crawlers to access the Services except through KubernoGRC’s documented APIs and in strict accordance with applicable rate limits and API terms.
• Attempt to circumvent, disable, or bypass any access controls, security features, usage limits, or technical restrictions built into the Services.
• Impersonate any person or entity, or falsely claim an affiliation with any person or entity in connection with the Services.
5. AI Feature Acceptable Use
The following rules apply to all use of KubernoGRC’s AI Features.
(a) Permitted Inputs Only. Users must not submit to the AI Features: (i) content that violates any applicable law or third-party rights; (ii) Protected Health Information (PHI) under HIPAA, payment card data under PCI DSS, government-issued identification numbers, or other specially regulated data categories, unless a specific written authorization from KubernoGRC is in effect; or (iii) content that is intentionally false, defamatory, discriminatory, or designed to manipulate AI outputs for harmful purposes.
(b) No Circumvention of AI Safeguards. Users must not attempt to circumvent, disable, override, jailbreak, or bypass any safety filters, output guardrails, or access restrictions built into the AI Features. This prohibition applies regardless of whether the attempt is direct (e.g., adversarial prompts) or indirect (e.g., chaining requests to extract prohibited outputs).
(c) Human Review Obligation. Customer acknowledges that AI Customer Output may contain inaccuracies, hallucinations, or incomplete analysis. Customer is solely responsible for reviewing, validating, and verifying AI Customer Output before relying on it for any compliance, legal, regulatory, or business decision. AI Customer Output does not constitute legal, professional, or regulatory advice.
(d) No Automated Decisions on Sensitive Matters. Users must not use AI Customer Output as the sole basis for automated decisions that materially affect individuals’ legal rights, employment, financial situation, or other significant interests, without appropriate human review and oversight.
(e) No Training Extraction. Users must not use the AI Features in an attempt to extract, reconstruct, or copy the underlying AI models, training data, or weights, or to probe for information about third-party AI provider capabilities.
(g) Suspension. KubernoGRC may suspend or limit access to AI Features if it reasonably believes Customer or its Authorized Users have violated this Section. Where practicable, KubernoGRC will provide advance notice and limit any suspension in scope and duration to what is reasonably necessary.
6. Security Obligations
Users must maintain the confidentiality of credentials, implement reasonable security measures, and promptly report any suspected security incidents. Users must promptly report any suspected security incident, unauthorized access, or suspected vulnerability in the Services to security@kubernogrc.com.
7. Intellectual Property
Users must respect KubernoGRC intellectual property rights and not attempt to copy, modify, reverse engineer, or create derivative works of the services.
8. Enforcement and Termination
Violation of this AUP may result in suspension or termination of access to services, and KubernoGRC reserves the right to take legal action where necessary. Violations of this AUP should be reported to security@kubernogrc.com. In response to a violation (or suspected violation), KubernoGRC may, at its sole discretion: (a) issue a warning; (b) temporarily suspend or restrict access; (c) permanently terminate access; or (d) pursue legal remedies. In cases presenting immediate risk to the Services, other customers, or third parties, KubernoGRC may act without prior notice.
9. AUP Governs in Conflicts
In the event of any conflict or inconsistency between this AUP and the Master Subscription Agreement solely with respect to Authorized Users’ conduct and use of the Services, this AUP shall govern and control.
10. Changes to This Policy
We may update this AUP periodically. Changes will be posted on this page and, if material, communicated to Customers.
11. Contact Information
For questions about this AUP, contact security@kubernogrc.com.

