Acceptable Use Policy
ApexCorp runs agents that act with some autonomy. This is the line between using that and misusing it.
Last updated 2 August 2026
1. Scope
This policy forms part of the Terms of Service and applies to every deployment of the Service, including any running inside your own environment.
2. Do not use the Service to
- Break the law, or help someone else break it.
- Attack, probe, or degrade systems you do not own or have written permission to test. Agents can run commands and read files; pointing them at someone else’s infrastructure is not a grey area.
- Generate or distribute malware, ransomware, credential harvesters, or tooling whose purpose is unauthorised access.
- Produce material that sexually exploits children, incites violence, or harasses, threatens or defames a person.
- Run bulk unsolicited messaging, or impersonate a person or organisation in a way designed to deceive.
- Generate deliberate disinformation, or content designed to be mistaken for a genuine record — invoices, receipts, reviews, identity documents, official correspondence.
- Make consequential decisions about people — hiring, credit, housing, insurance, medical care, immigration, benefits — using agent output without a competent human deciding.
- Circumvent the safety rails: disabling spend ceilings to run unbounded work on shared infrastructure, or attempting to remove the approval requirement on outward actions.
- Reverse engineer, resell or sublicense the Service, or use it to build a competing service.
3. Your agents are your responsibility
This deserves saying directly, because autonomy invites the assumption that nobody is accountable. You are. Work an agent performs under your account is your work. The brief you wrote, the project root you granted, the ceilings you set and the approvals you gave are all your decisions.
The product is designed to keep that true: outward actions queue for a person, agents are confined to the directory you nominate, and every run is capped. Deliberately weakening those to get an agent to do something this policy forbids is a breach of it.
4. Review before you rely
Agent output can be confidently wrong. Where a mistake would harm someone, cost real money, or be hard to reverse, a person should read it first. The QA review step and the notes queue exist to make that the path of least resistance rather than an extra chore.
5. Provider terms also apply
Your prompts reach your model provider under your own account. Their usage policies apply to you independently of this one, and are often stricter. Breaching them can get your key revoked by them, which we cannot undo.
6. Enforcement
Where we can, we will contact you and ask you to stop before taking action. For severe breaches — anything causing ongoing harm, or clearly criminal — we may suspend access immediately and, where required, report it. Accounts terminated for breach are not refunded.
We do not routinely inspect the content of your company. Enforcement is normally triggered by a report or by abuse signals from our own infrastructure.
7. Reporting abuse
If you believe someone is using ApexCorp in breach of this policy, write to contact@apexcorp.app with enough detail for us to investigate.
Questions about this document go to contact@apexcorp.app, or via the contact page.
Related: Terms · Privacy · Refunds · Acceptable Use