Pre-launch counsel-review draft
Acceptable Use Policy
Proposed rules for safe, lawful, and authorized use of NoirGen Agent QA. This policy is a professional-review draft and is not yet effective.
Professional legal review required before publication
This draft is not effective, has not been approved by counsel, and is not legal advice. Bracketed decisions and review markers must be resolved before publication.
- Effective date
- To be set after professional legal approval
- Last revised
- To be set after professional legal approval
- Draft record
- M27 counsel-review draft 1, prepared August 27, 2026
1. Scope and draft status
This proposed Acceptable Use Policy (AUP) would apply to every person or organization that accesses NoirGen Agent QA, an offering of NoirGen LLC. It supplements the Terms of Service and would control if an approved final AUP imposes a more specific restriction on use of the Service.
This pre-launch version is not effective, has not been approved by counsel, and is not legal advice. It describes the intended safety boundary without claiming that every moderation, detection, review, or appeal mechanism has been deployed.
2. Use only systems and data you are authorized to test
You may use the Service only when you have authority to:
- access and test the configured agent endpoint and every redirect destination;
- use the credentials, headers, accounts, models, tools, and connected services involved;
- submit and process the prompts, knowledge, reference facts, responses, personal data, confidential information, and other Customer Content involved;
- send test traffic at the requested volume and receive the resulting responses; and
- act for the organization whose account and plan will be used.
You must honor third-party terms, intellectual-property rights, privacy rights, confidentiality duties, rate limits, robots or access restrictions where legally applicable, and contractual limits governing the tested system.
You may not use the Service to scan, probe, test, monitor, or access a third party’s agent, infrastructure, account, or data without that party’s informed permission or another valid legal authorization.
3. Illegal, abusive, or harmful use
You may not use the Service to create, facilitate, promote, or conceal:
- conduct that violates applicable law, regulation, court order, or third-party rights;
- fraud, phishing, impersonation, deceptive practices, or theft of credentials or data;
- harassment, stalking, threats, exploitation, unlawful discrimination, or targeted abuse;
- malware, ransomware, destructive code, unauthorized persistence, command-and-control, credential stuffing, or other malicious activity;
- sexual exploitation of minors, non-consensual intimate content, trafficking, or content whose possession or distribution is unlawful;
- infringement or misappropriation of intellectual property, privacy, publicity, confidentiality, or contractual rights; or
- evasion of sanctions, export controls, legal process, or legally required restrictions.
The Service may reveal harmful agent behavior during authorized testing. Recording a prohibited behavior for legitimate quality assurance does not by itself violate this AUP; using the Service to deploy, amplify, or operationalize that behavior may.
4. Security and technical abuse
You may not:
- bypass or attempt to bypass authentication, tenant isolation, authorization, encryption, request validation, rate limits, plan limits, usage accounting, or safety controls;
- use endpoint configuration, DNS, redirects, alternate address formats, or encoded input to reach loopback, private, link-local, metadata, internal, reserved, or otherwise protected network destinations;
- interfere with, overload, disrupt, degrade, or test the security of NoirGen systems or a provider without prior written authorization;
- introduce malicious payloads, unsafe files, hidden credentials, excessive traffic, or content designed primarily to consume resources or evade safeguards;
- scrape or extract Service data, other customer data, source material, or nonpublic interfaces except through an expressly supported and authorized method;
- forge billing, subscription, webhook, task, scheduler, evaluation, identity, or usage evidence; or
- sell, transfer, or provide access credentials to an unauthorized person.
If you conduct authorized security research involving the Service itself, obtain written scope and testing permission before sending test traffic. A public vulnerability-disclosure or safe-harbor program is not promised by this draft.
5. Data, credentials, and content restrictions
Submit only data reasonably necessary for authorized quality assurance. Place endpoint authorization values only in the designated encrypted credential fields—not in agent names, descriptions, request templates, prompts, knowledge sources, rubrics, support messages, or other ordinary content fields.
You may not submit or direct processing of:
- payment-card numbers, card security codes, bank credentials, passwords, or private keys;
- protected health information or other data that would require a HIPAA business associate agreement, because no HIPAA compliance or BAA is offered or claimed;
- biometric identifiers, precise geolocation, government identifiers, highly sensitive personal data, or regulated records unless an approved written agreement and supported product scope expressly permit that processing;
- classified information, export-controlled technical data, or information subject to a restriction the Service is not approved to satisfy; or
- content you do not have a lawful right to disclose, transmit, test, or store.
The Privacy Policy and Subprocessors page describe the proposed data flows. A customer needing contractual data-processing terms must complete that review before submitting regulated or restricted data.
6. High-impact and professional decisions
Service output is probabilistic and may be wrong or incomplete. You may not use a score, verdict, alert, or model-assisted finding as the sole basis for a decision that determines a person’s eligibility, access, rights, safety, or material opportunity in areas such as employment, housing, credit, insurance, education, healthcare, legal services, public benefits, or essential services.
You must apply qualified human review, appropriate domain expertise, meaningful appeal or correction processes, and all legally required testing and notices. The Service is not a substitute for legal, regulatory, medical, financial, security, accessibility, fairness, or other professional assessment. See AI evaluation limitations.
You may not represent a Service result as an official certification, audit opinion, regulatory approval, SOC 2 report, HIPAA determination, guaranteed safety finding, or proof that an agent is accurate or compliant.
7. Platform integrity and fair use
You must stay within the plan limits, request sizes, supported file types, retry limits, and concurrency controls presented by the Service. Current fixed monthly plans do not include automatic metered overage billing; that does not authorize attempts to exceed or evade enforced limits.
Do not create multiple accounts or organizations primarily to avoid a restriction, conceal abuse, multiply free allocations, or continue conduct after suspension. Do not manipulate prompts, evaluator instructions, webhook data, browser parameters, or provider responses to manufacture a passing result or falsify evidence.
Reasonable, authorized adversarial testing of your own agent is an intended use. It must remain within the configured customer endpoint, applicable law, your authorization, and Service safety limits.
8. Review and proposed enforcement
A final AUP may permit NoirGen to investigate credible suspected misuse and to limit, suspend, or terminate access when reasonably necessary to protect customers, providers, the Service, or the public; comply with law; prevent material harm; or address a material breach. Where appropriate and legally permitted, the final process should provide notice, a chance to cure, and a support escalation path.
We may preserve and disclose information when required by valid legal process or reasonably necessary to investigate abuse, protect rights or safety, or enforce an approved agreement, subject to the final Privacy Policy and applicable law.
9. Reporting concerns and policy changes
Report suspected abuse, account compromise, unsafe behavior, or security concerns to [email protected]. Do not include passwords, private keys, payment-card data, or unnecessary sensitive content in the message. The Support page lists the available contact paths.
An approved AUP should state how material changes are announced and when they become effective. Effective and revision dates must be set only after owner and professional legal approval.