Effective: on publication
Last updated: 2026-05-18
Document key: aup
Plain-English summary
This is the short list of things customers must not do with the GAEZLA service. If a customer uses GAEZLA to attack other systems, send spam, host illegal content, evade security controls, or interfere with other customers, we can suspend the account immediately and terminate the contract. Customers are responsible for what their own users do. This policy is incorporated by reference into the Master Subscription Agreement.
1. Scope
This Acceptable Use Policy (the “AUP”) governs use of the GAEZLA IT operations platform and any associated APIs, command-line tools, agents, integrations, and websites (collectively the “Service”) provided by T1P5M4RK, LLC, a Delaware limited liability company (“Company”). It is incorporated by reference into the Master Subscription Agreement (the “MSA”) and any Order Form between Company and a customer (“Customer”). Capitalised terms not defined here have the meanings in the MSA.
2. Responsibility for Authorized Users
Customer is responsible for the acts and omissions of every individual or system it permits to use the Service under its account (“Authorized Users”), including employees, contractors, agents, and end-users. A breach of this AUP by an Authorized User is a breach by Customer.
3. Prohibited content
Customer and its Authorized Users will not upload to, store on, transmit through, or generate via the Service any content that:
(a) is unlawful, defamatory, fraudulent, obscene, infringing of any intellectual property or privacy right, or that breaches export-control, sanctions, or trade laws; (b) contains malware, ransomware, time bombs, logic bombs, or any other code designed to disrupt, damage, or gain unauthorized access to a system or network; (c) is child sexual abuse material or any other content that exploits minors; or (d) is designed to harass, threaten, or incite violence against any person or group.
4. Prohibited activities
Customer and its Authorized Users will not use the Service to:
(a) interfere with, disrupt, or attack any network, server, application, or device (including DoS / DDoS attacks, port scanning of third-party infrastructure without permission, or credential-stuffing); (b) send bulk unsolicited messages (spam), or violate the US CAN-SPAM Act, the Telephone Consumer Protection Act (TCPA), or any other anti-spam or e-marketing law applicable to Customer; (c) probe, scan, or test the vulnerability of the Service or circumvent any authentication, rate-limit, billing, or access-control mechanism, except under a written agreement with Company (e.g. a GAEZLA-issued penetration-testing authorisation); (d) reverse-engineer, decompile, or attempt to derive the source code or underlying algorithms of the Service, except to the limited extent expressly permitted by applicable law; (e) use the Service to build a competing product or for benchmarking that is published without Company’s prior written consent; (f) collect or harvest information about other users, or impersonate any person or entity; (g) use the Service in any safety-critical context where failure would foreseeably cause death, personal injury, or environmental damage (e.g. operation of nuclear facilities, life-support, weapons, or air-traffic control); (h) use the Service in a way that exceeds documented rate limits, fair-use quotas, or scope of the subscription tier; (i) use the Service in violation of US export-control laws (including the Export Administration Regulations administered by the US Bureau of Industry and Security, and sanctions administered by the US Office of Foreign Assets Control), or any other anti-corruption or sanctions laws applicable to Customer, including supplying the Service to any person or entity on a US denied-parties list or in a US-embargoed jurisdiction; or (j) facilitate any of the above by a third party.
5. Security obligations of Customer
Customer will:
(a) keep its account credentials, API keys, and agent credentials secret and rotate them on suspected compromise; (b) configure least-privilege access for its Authorized Users; (c) promptly notify Company at legal@t1p5m4rk.com of any actual or suspected security incident affecting the Service or Customer Data; and (d) cooperate in good faith with any incident investigation initiated by Company.
6. Customer Estate access and Customer-Authorized Actions
The Service is an IT operations orchestration tool that, on Customer’s authorisation, ingests data from and executes actions across systems in Customer’s IT estate (“Customer Estate”). Customer’s use of the Service to access or act on the Customer Estate is subject to the following rules:
(a) Right to grant access. Customer must hold all rights, licences, and authorisations necessary to grant the Service access to each system in the Customer Estate, including any rights or consents required under third-party software licences, employer-employee policies, or applicable law.
(b) Scoping. Customer is solely responsible for the credentials, permissions, and access scope of every connector, agent, and integration through which the Service reaches the Customer Estate. Customer should apply least-privilege access and read-only scoping wherever feasible.
(c) Customer-Authorized Actions. Where Customer configures the Service (manually, by automation rule, or by agent policy) to execute an action in the Customer Estate, Customer authorises that action and is solely responsible for its consequences — including any change, deletion, outage, financial cost, or third-party liability — even where the action was triggered automatically by an agent operating within parameters Customer set.
(d) No backup or DR substitute. The Service is not a backup, disaster-recovery, or business-continuity solution. Customer must maintain its own backups and rollback procedures for the Customer Estate. Company makes no warranty that any Customer-Authorized Action is reversible.
(e) No moderation. Company has no obligation to monitor, moderate, or pre-approve the actions of Customer-controlled agents, and is not a party to or guarantor of any action Customer executes via the Service.
(f) Prohibited targets. Customer must not configure the Service to access or execute actions on any system Customer does not own or have explicit authorisation to control, or to ingest Sensitive Personal Information (as defined under the California Consumer Privacy Act) without additional written safeguards agreed with Company.
7. Suspension and enforcement
Company may suspend Customer’s access to the Service, in whole or in part, immediately and without prior notice if Company reasonably believes that:
(a) Customer or an Authorized User is in material breach of this AUP; (b) continued use poses a security, legal, or operational risk to Company, other customers, or third parties; or (c) suspension is required by law, regulation, or order of a competent authority.
Where practical, Company will give Customer prompt notice of the suspension and a reasonable opportunity to cure non-emergency breaches. Repeated or material breach is grounds for termination of the MSA for cause without refund of fees already due.
8. Reporting abuse
Reports of suspected abuse of the Service should be sent to legal@t1p5m4rk.com. Company will investigate credible reports promptly but does not guarantee a public response.
9. Updates to this AUP
Company may update this AUP from time to time to reflect new threats, regulatory changes, or operational learnings. Material changes will be communicated by email to Customer’s account-administrator contacts at least thirty (30) days before they take effect, except where a shorter period is required by law or to address an emergency security or legal risk.
10. Contact
Questions about this AUP: legal@t1p5m4rk.com.