ClearPoint Logic

Acceptable Use Policy

Effective date: 2026-10-07. Version: aup:studio:2026-10-07.

1. Scope

This Acceptable Use Policy (the "Policy") applies to every use of the ClearPoint Logic services, including Studio and the agents, skills, and apps built, certified, or hosted with it; Meridian, Helm, and Periscope; Docs; the public Demo; the status page; and related APIs. It is part of the Terms of Service and binds the customer organization and each of its users.

ClearPoint Logic is an AI-governance company, and this Policy is enforced in the products as well as on paper: at build time, at certification, and at runtime. Where a connected service's own terms are stricter than this Policy, the stricter rule applies. Where this Policy is stricter, this Policy applies.

2. Prohibited content and conduct

You may not use the services, or build, certify, host, or operate an agent, to do, enable, or materially assist any of the following:

  • child sexual abuse material, or any sexualization or exploitation of minors (zero tolerance; see section 8);
  • clearly illegal activity, including fraud, scams, phishing, identity theft, money laundering, and trafficking in drugs, weapons, wildlife, or people;
  • design, manufacture, or acquisition guidance for illegal firearms, explosives, or chemical, biological, radiological, or nuclear weapons;
  • stalkerware, spyware, or non-consensual tracking or monitoring of individuals;
  • harassment, doxxing, threats, incitement to violence, or non-consensual intimate imagery or sexual deepfakes of real people;
  • terrorism or violent extremism, including promotion, support, or operational help;
  • coordinated disinformation, election or voter manipulation, or mass impersonation;
  • generating, distributing, or facilitating sexual or pornographic content;
  • infringing or misappropriating another party's intellectual property, privacy, or publicity rights; or
  • any use that violates applicable law, export controls, or sanctions.

3. Security abuse

You may not:

  • scan, probe, fuzz, or test the vulnerability of the services or of any system reachable through them, except under a written authorization from ClearPoint Logic;
  • bypass, disable, or interfere with authentication, authorization, certification, egress controls, rate limits, quotas, logging, evidence capture, or any other safety or governance control, including controls that apply to agents you build;
  • share accounts, credentials, API keys, or session tokens, or use another person's credentials;
  • access data, tenants, agents, or evidence that are not yours, or attempt to break tenant isolation;
  • introduce malware, create or distribute exploits, or use the services to gain unauthorized access to any system;
  • run connectors or agents against third-party services in violation of those services' terms, or with deceptive user agents, proxy rotation, or other evasion; or
  • interfere with other customers' use of the services, or with the operation of the services themselves.

Good-faith security research is welcome. Report findings to [email protected] and follow the coordinated-disclosure terms in our security package rather than testing against production tenants.

4. Misuse of AI features

The services generate agents, code, text, and decisions using third-party AI models. You may not use those features, or an agent built with them, to:

  • generate malware, ransomware, exploits, or instructions for intrusion, credential theft, or circumvention of security controls;
  • generate content that is illegal, or that falls under section 2;
  • impersonate a real person, organization, or official body, or present an agent as a human where the law or the context requires disclosure;
  • make automated decisions with legal or similarly significant effects on people, including decisions about credit, lending, insurance, housing, employment, education, healthcare, or access to essential services, without a qualified human reviewing the decision before it takes effect;
  • provide medical, legal, financial, investment, or tax advice as if from a licensed professional, without the required disclaimers, human oversight, and licensure;
  • perform biometric identification or facial recognition without consent and without the controls the applicable jurisdiction requires;
  • run covert political campaigning, lobbying, or astroturfing, or operate gambling or betting without jurisdictional licensing and age controls;
  • execute autonomous, irreversible financial transactions without an approved budget envelope and human approval;
  • attempt to extract, replicate, or reverse engineer the models, system prompts, or safety systems behind the services; or
  • misrepresent generated output as human-authored where that matters, or as verified fact.

Uses in these categories that are lawful may be permitted only after review by ClearPoint Logic and with the required controls and disclosures in place. Studio classifies each agent's declared purpose and generated behavior against this Policy; an agent that violates it cannot be certified, deployed, or hosted. A false purpose attestation is itself a violation.

5. Protected health information

Protected health information ("PHI") under HIPAA may be processed in the services only under a signed Business Associate Agreement with ClearPoint Logic, and only in the products and configurations that agreement covers. You must not upload, connect, or otherwise process PHI without a signed Business Associate Agreement in place. PHI may never be entered into the public Demo or into a Beta feature.

Agents that handle PHI, children's data, or other sensitive personal data must declare the data class they process and must apply data minimization and the retention limits the customer's agreement requires.

6. Resource abuse

You may not:

  • build or run agents for bulk or cold outbound messaging, including mass email, SMS, voice, social, chat, CRM, or webhook campaigns, unsolicited prospecting sequences, or imported or enriched lead-list sends (an agent sending an individual or transactional message on its owner's behalf is normal use);
  • perform bulk or large-scale scraping or data collection without ClearPoint Logic review, and in any case not where it bypasses access controls, ignores a source's explicit prohibitions, harvests contact or personal data, or supports spam or fraud;
  • use the services for cryptocurrency mining, proof-of-work computation, denial of service, or load that is unrelated to the agents and work the services are designed for;
  • exceed, or build agents designed to evade, the complexity, concurrency, delegation depth, connector, scheduling, or cost-envelope bounds the services enforce; or
  • create multiple accounts or tenants to evade limits, suspensions, or fees.

The thresholds that separate ordinary use from bulk use are enforced by the certification classifier. We may throttle, pause, or de-certify an agent that exceeds them.

7. Reporting violations

To report a security vulnerability, suspected account compromise, or abuse of the services, email [email protected]. To report other violations of this Policy, including an agent you believe is misusing the services, email [email protected]. Include the agent, URL, or tenant involved, what you observed, and when. Do not include raw illegal content, secrets, or other people's personal data in a report; a description and identifiers are enough.

Customers must tell us promptly if they learn that their own users or agents have violated this Policy, and must cooperate with our investigation.

8. Enforcement

We investigate reports and classifier findings and respond in proportion to the severity of the violation. Responses include:

  • blocking an agent at build time;
  • holding an agent for review before certification;
  • revoking certification and suspending hosting for an agent;
  • throttling, pausing, or disabling a connector, feature, or user;
  • suspending or limiting a tenant or account; and
  • terminating the customer's agreement.

Violations under section 2, and any matter involving child sexual abuse material or clearly illegal content, result in immediate action. Runtime monitoring that detects an agent drifting into prohibited behavior triggers re-review and may revoke its certification. We may preserve relevant records under legal hold, and we report to law enforcement and to the authorities the law requires, including the National Center for Missing and Exploited Children where applicable.

Appeals

A customer may ask us to review an enforcement decision by emailing [email protected] with the agent or account involved and the grounds for the appeal. Appeals are decided by ClearPoint Logic management, with counsel involved where legal questions arise.

9. Changes to this Policy

We may update this Policy as the services, the law, and the threats we see change. The current version is always published at this page with its effective date and version identifier. Material changes are announced through the services or by email to customer administrators before they take effect, except where a change is needed sooner for safety or legal reasons. Questions about this Policy: [email protected].