Acceptable Use Policy
Effective 11 October 2026 · Last updated 11 October 2026
1. Use accounts and access lawfully
- Use only your own account and the workspaces you are authorized to access.
- Use a valid, one-time invitation intended for your business email; do not transfer, sell, publish or reuse it.
- Keep passwords, authenticator secrets, recovery information, API keys and integration tokens confidential. Do not place secrets in prompts, work items or support messages.
- Use MFA when required, keep your contact details current, and promptly report suspected account compromise.
- Workspace administrators must assign only the access level each person needs, remove access promptly when it is no longer needed, and review administrative access regularly.
2. Protect people and information
- Submit information only when you have authority and an appropriate notice or legal basis.
- Do not upload information that is unlawful, unlawfully obtained, confidential to a third party without permission, or protected by another person’s intellectual-property rights.
- Until Exado confirms production readiness in writing, do not submit production customer data, special-category or sensitive personal information, health or financial records, payment-card data, government identifiers, children’s data, authentication credentials, or information subject to sector-specific restrictions.
- Do not use Exado to profile or make consequential decisions about people without required human review, notice, legal basis and safeguards.
- Do not use generated content as the sole basis for employment, credit, health, legal, safety or other high-impact decisions.
3. Prohibited activity
You may not:
- break or evade authentication, MFA, tenant isolation, rate limits, role controls or other safeguards;
- probe, scan, test or attempt to access another customer’s account, tenant, data or systems without explicit written authorization from the owner and Exado;
- introduce malware, ransomware, malicious code, harmful payloads or content designed to disrupt or damage systems;
- interfere with availability, overload the service, perform denial-of-service activity, scrape at abusive rates or circumvent usage limits;
- reverse engineer or exploit the service except where mandatory law permits, or use Exado to develop a competing product using confidential information;
- send spam, phishing, deceptive messages, unlawful surveillance or unsolicited bulk communications;
- use AI or integrations to execute harmful, deceptive, discriminatory or unauthorized actions, or to bypass a required human approval;
- violate export controls, sanctions, privacy, cybersecurity, consumer-protection, employment, intellectual-property or other applicable laws.
4. AI and integration safeguards
AI suggestions may be inaccurate. Verify facts, check the affected people and systems, and obtain required approvals before relying on or executing a suggestion. Do not provide prompts designed to extract another tenant’s data, secrets, model instructions or provider confidential information. Connect external accounts only with the authorization of the system owner. Review requested scopes and revoke access when no longer needed. Never approve a consequential change solely because an AI assistant suggested it.
5. Reporting and enforcement
Report a suspected vulnerability, security incident or misuse to info@exado.app. Include the affected Exado URL, a concise description and steps to reproduce, but do not include real customer data, passwords, MFA codes or exploit payloads. Do not access or alter data, disrupt services, or publicly disclose a suspected vulnerability before coordinating a reasonable remediation window. Exado may investigate and may restrict or suspend access proportionately to protect users, data, security or legal rights. Where practicable, Exado will contact the relevant administrator and explain the action.
6. Contact and updates
Questions or reports: info@exado.app. Exado may update this policy when products, risks or legal requirements change. The effective date above identifies the current version.