Acceptable Use Policy
CUBES
Version: 2.0
Effective Date: 29 July 2026
Last Updated: 29 July 2026
1. Purpose and scope
This Acceptable Use Policy (the "Policy") defines permitted and prohibited uses of the CUBES websites, controlled private-beta environment, software-analysis tools, integrations, reports, and related services (collectively, the "Service").
This Policy forms part of the CUBES Terms of Service and applies to each Customer, authorized representative, user, collaborator, and person who accesses or uses the Service on the Customer's behalf.
The Service is intended only for authorized business and professional use.
2. Customer responsibility
The Customer is responsible for all use of the Service through its accounts and integrations and must ensure that its users:
- act within their assigned authority;
- provide accurate information and data classifications;
- protect account and integration credentials;
- follow applicable law, contractual duties, confidentiality obligations, and internal policies; and
- use qualified human review before acting on CUBES Outputs.
The Customer must promptly notify CUBES of suspected unauthorized access, credential exposure, security incidents, or material misuse.
3. Rights, authority, and lawful instructions
You may submit, connect, or process content only where the Customer has the legal right and authority to do so.
You must not use the Service to:
- access or analyze a repository, branch, path, document, system, account, or dataset without authorization;
- infringe intellectual-property, privacy, confidentiality, trade-secret, contractual, database, or other third-party rights;
- violate applicable law, regulation, sanctions, court orders, or binding contractual restrictions; or
- conceal, misrepresent, or falsify the identity, authority, purpose, ownership, or classification associated with submitted content.
GitHub OAuth or another technical connection does not replace the Customer's obligation to obtain the required legal authority and repository authorization.
4. Security and system integrity
You must not use the Service to:
- gain or attempt to gain unauthorized access to any account, system, network, repository, data, or credential;
- steal, solicit, expose, validate, trade, or misuse passwords, tokens, private keys, certificates, session identifiers, or other authentication material;
- probe, scan, exploit, attack, disrupt, overload, degrade, or interfere with systems without the system owner's express authorization;
- bypass or defeat authentication, authorization, rate limits, safety controls, monitoring, logging, tenancy boundaries, or technical restrictions;
- introduce, distribute, execute, or facilitate malware, ransomware, destructive code, credential theft, denial-of-service activity, or unauthorized persistence;
- use the Service to coordinate or automate attacks against information systems; or
- attempt to access another Customer's content, metadata, Outputs, or environment.
Defensive analysis of malware, vulnerabilities, or potentially harmful code is permitted only where the Customer is authorized to perform the analysis, uses an appropriate isolated environment, and complies with any additional CUBES approval or safety requirements.
5. Restricted data and secrets
You must remove or rotate passwords, access tokens, private keys, production credentials, certificates, and unnecessary live customer data before connecting or submitting content.
Unless CUBES has provided prior written approval and all required safeguards and agreements are in place, you must not submit or connect:
- special-category, health, biometric, payment-card, government-identifier, children's, employee-monitoring, or similarly regulated data;
- production secrets or live credentials;
- data subject to professional secrecy or sector-specific processing restrictions;
- personal data where the Customer lacks a lawful basis, required notice, or applicable Data Processing Agreement; or
- content whose processing would conflict with the declared analysis purpose or approved data classification.
You must not deliberately evade data-eligibility questions, manual review, ingestion blocks, or required processing configurations.
6. Prohibited harmful, deceptive, or discriminatory use
You must not use the Service or its Outputs to:
- facilitate unlawful discrimination, harassment, persecution, exploitation, or surveillance;
- manipulate or deceive a person in a manner likely to cause significant harm;
- exploit vulnerabilities associated with age, disability, social condition, or economic condition;
- create or support unlawful social scoring, prohibited biometric categorization, or other prohibited AI practices;
- impersonate another person or organization or falsely attribute an Output;
- fabricate evidence, conceal material limitations, or knowingly present inaccurate findings as verified facts; or
- facilitate fraud, extortion, abuse, or other unlawful or harmful conduct.
7. High-impact and regulated decisions
The Service and its Outputs must not be used as the sole basis for decisions involving:
- production deployment or safety-critical operation;
- cybersecurity certification or final remediation approval;
- legal rights or legal advice;
- employment, worker monitoring, or access to work;
- healthcare or medical treatment;
- credit, lending, insurance, housing, or essential services;
- education admissions or assessment;
- law enforcement, immigration, or public benefits; or
- other regulated or high-impact decisions.
A qualified human must independently review relevant source material, context, risks, and applicable professional or regulatory requirements before action is taken.
8. Accuracy, representation, and Outputs
You must not:
- describe a CUBES Output as a certification, legal opinion, statutory audit, assurance report, penetration-test attestation, or proof of compliance unless CUBES has expressly agreed to provide that specific service in writing;
- remove or conceal warnings, scope limitations, confidence indicators, material assumptions, or known errors;
- knowingly publish or distribute a materially misleading excerpt of an Output;
- use an Output to misrepresent the security, reliability, legal status, ownership, or quality of software or an organization; or
- attribute an Output to CUBES after materially altering it without clearly disclosing the alteration.
9. Service abuse and unauthorized commercialization
You must not:
- scrape, harvest, copy, mirror, or extract the Service or its data except through documented and authorized functionality;
- use automated means in a way that exceeds documented limits or materially burdens the Service;
- circumvent usage, access, account, or beta-participation restrictions;
- resell, sublicense, white-label, or provide the Service to third parties without written authorization;
- reverse engineer, extract, reconstruct, or replicate protected Service components except to the limited extent such restriction is prohibited by applicable law; or
- benchmark or test the Service for publication in a deceptive, unsafe, or unauthorized manner.
10. Beta cooperation
During the controlled private beta, CUBES may impose repository, feature, geography, data, volume, user, or processing restrictions.
The Customer must cooperate with reasonable requests to:
- confirm authority or business identity;
- correct a data classification;
- remove or rotate secrets;
- pause or limit processing;
- investigate a suspected incident or misuse; or
- verify that required agreements and safeguards are in place.
Failure to cooperate may result in the affected repository, integration, analysis, or account being blocked or suspended.
11. Enforcement
CUBES may investigate suspected violations and may restrict, suspend, or terminate access where reasonably necessary to protect Customers, third parties, providers, systems, or legal compliance.
Depending on severity, CUBES may:
- block a repository, integration, upload, analysis, or Output;
- require corrective action or additional verification;
- revoke or limit beta access;
- preserve relevant security and legal evidence;
- notify an affected Customer or provider where appropriate; or
- report conduct to competent authorities where required or legally justified.
Where reasonably practicable and safe, CUBES will provide notice and an opportunity to remedy a curable violation. Immediate action may be taken where delay could create material harm, unlawful processing, data exposure, or system risk.
12. Reporting concerns
Suspected violations, unauthorized access, exposed credentials, or security concerns should be reported using the current contact details published on the CUBES Legal / Contact page.
Do not include passwords, private keys, access tokens, or unnecessary personal data in a report.
13. Changes to this Policy
CUBES may update this Policy to reflect changes in law, the Service, security risks, providers, or the private-beta program.
Each published version will have an identifiable version and effective date. Material changes may require notice or affirmative re-acceptance before continued use. Continued use alone does not replace re-acceptance where CUBES expressly requires it.
End of Acceptable Use Policy