Acceptable Use Policy (AUP)
Draft — pending legal-counsel review. See
README.md. Entity facts:COMPANY.md. This is the customer-facing AUP (binds users of the Service). The internal staff AUP isdocs/security/acceptable-use-policy-internal.md.
- Owner: byRazLabs Ltd (trading as "Dena")
- Version: 1.0 (draft) — drafted 2026-06-05
- Forms part of: the Terms of Service
This policy sets out what you may and may not do with the Dena Service. It applies to every Customer and Authorised User. Breaching it is a breach of the Terms of Service and may lead to suspension or termination.
You agree not to
- Break the law. Use the Service for anything unlawful, fraudulent, or infringing,
or to store/transmit content you have no right to.
- Harm the Service. Probe, scan, or test the vulnerability of the Service without our
prior written consent (authorised security testing is welcome — see §"Security testing" below); circumvent authentication, rate limits, or tenant isolation; or introduce malware.
- Overload or disrupt. Launch denial-of-service activity, send excessive automated
requests outside documented API limits, or otherwise degrade the Service for others.
- Misuse access. Share credentials, access another tenant's data, or access data you
are not authorised to see. Tenant isolation is enforced technically; attempting to defeat it is a serious breach.
- Scrape or resell. Systematically extract data, or resell or sublicense the Service,
except as the Terms allow.
- Misrepresent AI output. Present AI-generated findings, severity grades, or report
drafts as final engineering conclusions without the review and sign-off of a competent person. The Service is decision-support; professional responsibility remains with the qualified user.
- Upload prohibited content. Submit content you lack the rights/consents for
(including personal data of others without a lawful basis), or content that is malicious, illegal, or unrelated to legitimate inspection use.
- Reverse-engineer. Decompile or reverse-engineer the Service or its AI models except
to the extent the law permits despite this restriction.
Your security responsibilities
- Keep credentials confidential; enable multi-factor authentication where offered.
- Manage your Authorised Users (add/remove promptly, especially on staff changes).
- Report any suspected security issue or unauthorised access promptly to
security@denainfra.com.
Security testing & responsible disclosure
We welcome good-faith security research. If you believe you have found a vulnerability, email security@denainfra.com with details and give us reasonable time to remediate before any disclosure. Do not access, modify, or exfiltrate other parties' data, and do not run disruptive tests (DoS, mass automated scanning) against production. Good-faith research conducted under these terms will not be pursued by us. Full terms are on the Trust page.
Enforcement
We may investigate suspected breaches and may suspend access where necessary to protect the Service or other customers, giving notice where practicable. Serious or repeated breaches may lead to termination per the Terms.
Changes
We may update this AUP; material changes take effect on notice.
Revision history
| Version | Date | Change | Author |
|---|---|---|---|
| 1.0 (draft) | 2026-06-05 | Initial draft | AI session — pending counsel review |