LEVIATHAN SOLUTIONS INC.
ACCEPTABLE USE POLICY
Effective Date: [DATE]
This Acceptable Use Policy governs use of the Leviathan platform and services. It is incorporated by reference into the Master Services Agreement, order form, pilot agreement, or platform terms under which a customer receives access. Customers are responsible for their users' compliance with it.
We keep this short deliberately. The rules below are the ones we will actually enforce.
1. Prohibited Uses
You may not use the platform or services to:
Break the law. Violate any applicable law or regulation, including export control, sanctions, anti-corruption, and privacy laws. You may not use the platform in or for the benefit of any country or party subject to comprehensive U.S. sanctions, and you may not permit access by anyone on a U.S. government restricted-party list.
Compromise systems. Gain or attempt to gain unauthorized access to any system, network, or data; probe or test the vulnerability of any system you are not authorized to test; circumvent authentication or access controls; or introduce malicious code.
Connect environments you don't control. Grant Leviathan access to any cloud environment, cluster, or account that you do not own or are not authorized to administer. You are responsible for having the authority to grant the access you grant us.
Interfere with the service. Disrupt or degrade the platform or the infrastructure supporting it; evade usage limits or quotas; or impose an unreasonable load on our systems.
Misuse the technology. Reverse engineer, decompile, or disassemble any part of the platform, or attempt to derive its source code, structure, or underlying algorithms, except to the extent this restriction is unenforceable under applicable law. Access the platform to build or assist in building a competing product or service, or to benchmark it for publication without our prior written consent.
Misuse rights of others. Infringe intellectual property rights, misappropriate trade secrets, or violate anyone's privacy or publicity rights.
Send prohibited data. Submit to the platform, or route through it, any data you are not permitted to disclose to us — including protected health information, payment card data, government-issued identification numbers, or information subject to special regulatory regimes — unless we have agreed in writing to receive it and have the required agreements in place.
Resell without authorization. Sell, resell, sublicense, or make the platform available to any third party, except as your agreement with us expressly permits.
2. Security Obligations
You must:
-
Keep credentials confidential and not share accounts between individuals
-
Grant Leviathan the minimum permissions necessary for the services you have engaged us to provide, and revoke access promptly when it is no longer needed
-
Promptly notify us at [security@leviathaninc.com] of any suspected unauthorized access to your account or to any environment connected to the platform
-
Promptly deactivate access for users who leave your organization or change roles
3. Enforcement
If we determine that a use violates this Policy, we may suspend or restrict access to the affected account or environment. Where practicable, we will notify you first and give you an opportunity to correct the problem. Where a violation presents an immediate risk to the security or integrity of our systems, another customer's environment, or a third party, we may act first and notify you promptly afterward.
Suspension under this Policy does not relieve you of payment obligations for the suspended period, and it does not limit any other remedy available to us. Repeated or uncured violations are grounds for termination under the applicable agreement.
4. Reporting
Report suspected violations, security vulnerabilities, or abuse to [security@leviathaninc.com]. We investigate credible reports and will not pursue legal action against good-faith security researchers who report vulnerabilities responsibly, do not access data beyond what is necessary to demonstrate the issue, and give us reasonable time to remediate before disclosure.
5. Changes
We may update this Policy as the platform and the threat environment change. We will post the current version at [URL] and, where a change materially expands your obligations, give notice through the platform or by email before it takes effect.