Acceptable Use Policy
Version 1.0.0 · last reviewed 2026-09-19. Structure fixed by legal review; wording subject to final review before launch.
Every rule below is enforced by the product; this document describes that enforcement rather than adding new obligations.
1. Only your own releases
Runs may be requested only on repositories of an organisation the user belongs to. A deploy URL is never probed until ownership is proved by a DNS TXT record or the well-known file.
2. No cardholder data, no personal data in artefacts
No cardholder data is ever submitted to or processed by the auditor, and the evidence never contains personal data.
3. Tokens and secrets
CI tokens are personal to the organisation, scoped, expiring and revocable; webhook secrets are shown once. Sharing a token outside the organisation is a breach of this policy.
4. Limits
Tier caps (size, tokens, minutes, files, runs per day) and rate limits on the public and CI endpoints are enforced automatically. Exceeding them refuses the request; it does not open a dispute.
5. Attestations, badges and Trust pages
An Attestation may be shown only for the exact build it names. A revoked or expired Attestation is served with its status and may not be presented as valid. Badges must embed the live SVG, never a copy.
6. Script disclosure
Full script source is available to identified subscribers within a per-user hourly limit, and each disclosure is logged. Redistribution is not permitted.
Final text pending legal review.
7. Consequences
Suspension of runs and, for persistent abuse, closure of the organisation following the published deletion schedule (30-day grace period).
Final text pending legal review (notice procedure before suspension).