# Acceptable use policy

> What you may not do with AgentGate, what the people who visit your protected pages are entitled to, when security testing is allowed, and how to report abuse.

> [!IMPORTANT]
> **Draft for review:** these terms are not in force until [LEGAL ENTITY NAME] publishes them; placeholders in [brackets] must be filled in. This draft was written without legal advice. [LEGAL ENTITY NAME] must review it, with a lawyer where needed, before it applies to anyone.

This policy is part of the [Early access terms of service](/docs/terms). It applies to every account on the hosted pilot. Breaking it can lead to suspension (sign-in, the console and the API are closed; the account's sites keep protecting) or to the account being ended, as the terms describe.

## 1. What you may not do

- **Attack, scan or probe other systems.** Do not use AgentGate, its demo, its console or its API to attack, scan, probe or gain access to systems, accounts or data that are not yours, and do not try to reach other customers' sites, decisions or data.
- **Circumvent the detection or build evasion tooling.** Do not use what you learn from the widget, the proof of work, the instrumentation challenge, the rules or the decision labels to build, sell or share tools whose purpose is to get automation past AgentGate on sites you do not operate. Reading the SDK, testing your own site in monitor mode and the [security testing brief](/hack) are fine; bypass kits are not.
- **Put the gateway in front of abuse.** Do not use the gateway or the widget to front a service that sends spam or phishing, distributes malware, scrapes other people's sites against their terms, or launders abusive traffic. Do not sign requests as an agent you do not operate, and do not use the human handoff to trick a person into approving something.
- **Break the law.** Follow the laws that apply to you and to your visitors: data protection, anti-spam, computer misuse, consumer protection and sanctions. Do not process data through AgentGate that you may not lawfully collect, and do not use it for illegal content or services.
- **Deliberately exceed limits.** Account limits (by default 5 sites, 3 live backend secrets per site, 10 members and 25 live API tokens) and rate budgets exist so that the shared hosted pilot stays up for everyone. Ask us if you need more instead of creating extra accounts to get around them. Do not run load tests or benchmarks against the hosted pilot without our written agreement.
- **Resell it without agreement.** Do not resell, sublicense or offer AgentGate as a service to third parties, and do not share your account or site keys with people outside your organisation, without our written agreement. If you are an agency protecting clients' sites, ask us.
- **Misrepresent it.** Do not tell your visitors or customers that AgentGate proves someone is human; it raises the cost of automation.

## 2. What your visitors are entitled to

- **Not to be excluded because of who they are.** Rules, agent policies and prices must not be used to block, challenge or charge people on the basis of race, ethnicity, religion, sex, sexual orientation, gender identity, disability, age, nationality or any other characteristic that is protected where you or they are. The rule language can match on country, language, network and address reputation for abuse control; do not use those, or the analytics, as a proxy for a protected characteristic. Blocking a country because the law requires it is fine; blocking people because of who they are is not.
- **The accessible alternatives stay enabled.** The step-up check can be completed with a mouse, touch, or Space / Enter held on the focused button, and **"Verify another way"** needs no pointer, timing or puzzle ([how the check works](/docs/how-it-works#the-step-up-check), [widget accessibility](/docs/widget-reference#accessibility)). Do not hide, disable, cover or restyle them so that they cannot be used, and do not wrap the widget in a way that removes them. Every new site starts in [monitor mode](/docs/monitor-and-enforce): look at the would-have decisions before you enforce, so that people are asked, not blocked.
- **To know.** Tell your visitors in your privacy notice that AgentGate is in use and what it collects; you can link to [ours](/docs/privacy). Answer their access and deletion requests; we help you find the records by site and time.
- **Their data is used for protection only.** The decisions, labels and analytics you get are for protecting your site. Do not use them to profile or track people across sites, for advertising, or to identify individuals beyond what handling abuse needs.

## 3. Security testing

Security testing of AgentGate is allowed **only on the terms of the public defense challenge** at [/hack](/hack) (raw at `/agent.md`). In summary, as the brief stands today:

- Test only the public demo: the form at `/demo` (it posts to `POST /submit`), the brief at `GET /agent.md`, and one or two unauthenticated requests to `POST /agent/submit`. Not the console, sign-in, `/admin/`, other customers' sites, other subdomains or IPs, SSH or neighbouring services, and no guessing credentials.
- No scanners, high-volume fuzzing or denial-of-service tests. One request at a time, at most one request every two seconds and 30 requests per 15-minute run.
- Synthetic text only: no real personal data and no secrets.
- Make attempts traceable with the `X-AgentGate-Test-Run` header, and report as the brief says: your run ID, the time window in UTC, each case label and request ID, the exact request sequence, what you observed and what you expected.

Testing within the brief is authorised; testing outside it is not. Give us a reasonable time to fix what you find before you publish it. Keep tests of your own sites within the brief's rates and your account's limits, and tell us first at [SUPPORT EMAIL] if you plan anything beyond normal use.

## 4. Reporting abuse

Report abuse of AgentGate, or a site that you believe is breaking section 2, to **[ABUSE EMAIL]**. Include the site or URL, what happened, the time window in UTC, any `X-AgentGate-Request-ID` or decision ID values you have, and whether you are the site's operator, a visitor or a third party. A person reads every report.

- If a site protected by AgentGate blocks you and you think that is wrong, contact the site first: it controls its own rules and can see why it decided as it did.
- Security vulnerabilities go to the contact in `/.well-known/security.txt` and follow the [security testing brief](/hack), not to the abuse address.
- Where a report is upheld we may ask the account owner to fix the problem, suspend the account, or end it under the [terms](/docs/terms#9-suspension-and-termination).

## 5. Changes to this policy

We may change this policy as the terms describe: account owners are told by email before a change takes effect, and the date at the top of this page is updated.
