Acceptable Use Policy
Rules that protect EmailGuard, our customers, and the broader internet from abusive, unsafe, or unlawful use.
Purpose
This Acceptable Use Policy ("AUP") describes activity that is not allowed when using EmailGuard, our websites, APIs, mobile applications, and related services. It applies to customers, users, guests, API clients, and anyone acting on their behalf.
This is example policy text for an enterprise SaaS deployment. Review and adapt it with counsel before using it in production.
General obligations
You are responsible for your users, accounts, credentials, integrations, automations, and content. You must use EmailGuard only in compliance with applicable law, your agreements with us, third-party rights, and this AUP.
You must not encourage, enable, assist, or attempt to hide prohibited activity. If you become aware of misuse connected to your account or workspace, you must promptly stop it and notify us if the activity may affect the service or other customers.
Prohibited activity
You may not use the service to:
- Violate laws, regulations, sanctions, export controls, or third-party rights.
- Upload, transmit, host, or execute malware, ransomware, credential theft, phishing material, exploit code, botnet activity, or deceptive content.
- Attempt unauthorized access to accounts, systems, networks, APIs, data, or infrastructure.
- Probe, scan, or test the vulnerability of systems without written authorization, except as allowed by our Security reporting guidance.
- Interfere with service availability through denial-of-service activity, abusive automation, scraping, load testing, spam, or excessive requests.
- Send unsolicited, misleading, fraudulent, or unlawful messages.
- Harass, threaten, exploit, abuse, dox, or harm individuals or groups.
- Process regulated or highly sensitive data unless your agreement with us expressly allows it and appropriate safeguards are in place.
- Infringe intellectual property, privacy, publicity, confidentiality, or contractual rights.
- Circumvent product limits, usage limits, billing controls, security controls, audit logging, or access restrictions.
- Use the service to build, train, or improve a competing product in violation of your agreement with us.
Regulated and sensitive data
Unless expressly agreed in writing, EmailGuard is not intended to process:
- Protected health information subject to HIPAA.
- Payment card data that should be entered only into PCI-compliant payment provider fields.
- Government classified information.
- Children's data requiring verifiable parental consent.
- Biometric identifiers, precise geolocation, or special category data at scale.
If your use case involves regulated or sensitive data, contact [email protected] before using the service for that data.
Security testing
You may not run load tests, denial-of-service tests, automated vulnerability scans, or intrusive tests against production systems without prior written approval. Good-faith vulnerability reports should follow our Security page and be sent to [email protected].
Enforcement
We may investigate suspected violations and take action to protect the service, customers, and third parties. Actions may include warnings, rate limits, content removal, feature restrictions, suspension, termination, or legal reporting when appropriate.
We try to tailor enforcement to the severity and urgency of the risk. Emergency action may be taken without prior notice if needed to prevent harm, preserve service integrity, or comply with law.
Reporting abuse
To report abuse, contact [email protected]. Include the relevant URL, account, workspace, API endpoint, evidence, and your contact information when possible.
Looking for another policy?
Browse privacy, security, subprocessors, and other legal documents.