Acceptable Use Policy
Version 1.0 · Effective 2026-09-07
This policy forms part of our terms of service. It applies to everyone who uses PlatformSmith.
Most of it is what you would expect. The parts that are specific to us exist because PlatformSmith runs autonomous agents that execute code and reach the network using credentials you supply — a capability that is genuinely useful and genuinely open to misuse.
You must not
Use the Service to attack or interfere with anyone. No scanning, probing, or penetration testing of systems you do not own or have written permission to test. No denial-of-service activity. No attempts to gain unauthorised access to any system, account, or data — including other PlatformSmith customers’ data, and including our own control plane.
Use the Service for uncontracted compute. No cryptocurrency mining, no distributed computing for third parties, and no using agent sessions as a general-purpose compute or model-inference proxy unrelated to your own development work.
Use the Service to send unsolicited messages. No spam, no bulk unsolicited email or messaging, and no using connected integrations to distribute unsolicited content.
Use the Service for unlawful or harmful material. No content that is illegal where you or we operate, that infringes someone else’s rights, that sexually exploits children, or that is designed to harass or endanger a specific person.
Circumvent limits or protections. No evading storage or usage limits, no creating accounts to get around a suspension, and no interfering with the Service’s security controls or with other customers’ use of it.
Resell or repackage the Service without our written agreement.
Misrepresent your authority over what you connect. Only connect credentials, repositories, and infrastructure you are authorised to connect. Connecting an employer’s or client’s systems without their permission is a breach of this policy.
You are responsible for what your agents do
Actions taken by an agent using your credentials are your actions for the purposes of this policy. “The agent did it” is not a defence — you chose to connect the credential and you chose its scope.
That cuts both ways, and we think it is worth being direct about it: because agents can be manipulated by content they read, an account can breach this policy without its owner intending to. If that happens, tell us. We would far rather work with you on a compromised session than discover it ourselves.
Reporting
Report abuse, or a security problem in the Service, to security@platformsmith.com. If you are reporting a vulnerability, please give us a reasonable opportunity to fix it before disclosing it publicly. We will not pursue action against good-faith security research that respects other customers’ data and does not degrade the Service.
Enforcement
We may investigate suspected breaches and may suspend or terminate access. For serious or ongoing breaches — anything actively harming another party — we may act without notice. Otherwise we will normally contact you first.
We may also be required to report unlawful activity to the relevant authorities.
Changes
We may update this policy; the version and effective date above identify the current version.