Acceptable Use Policy
Effective date: September 22, 2026
This Acceptable Use Policy (the "AUP") applies to anyone who uses the Seros website, and to customers and their users who use systems we build, host or operate for them. It is part of the Terms of Service. If you break it, we may suspend access under Section 14 of those Terms.
Seros is a solution development company. Where we build a system for you and hand it over, this AUP governs your use of anything we continue to host or operate, and the AI rules in Section 4 govern deliverables we build that use AI models. Once a deliverable runs entirely on infrastructure you control, you own its acceptable use — but the obligations we owe our own model providers, in Section 4.7, still travel with the software.
The rule underneath all of the rules: do not use what we build or host to harm people, to break the law, to damage our systems or a third party's, or to make a machine decide something about a person that a person should decide.
1. Illegal and harmful use
Do not use anything we build or host for you to:
- Break any applicable law or regulation, or to help someone else do so.
- Infringe intellectual property rights, misappropriate trade secrets, or breach a duty of confidence.
- Defame, harass, threaten, stalk, or intimidate a person, or to organise those acts.
- Produce or distribute child sexual abuse material, non-consensual intimate imagery, or content that sexualises minors. We report such material to the authorities where the law requires it.
- Promote or facilitate violence, terrorism, or the manufacture of weapons, explosives, or controlled substances.
- Run fraud schemes, phishing, impersonation, fake reviews, or deceptive marketing.
- Engage in unlawful discrimination against a person or group.
2. Content restrictions
- Do not upload malware, ransomware, exploit code, or anything designed to disrupt software or hardware.
- Do not upload content you do not have the rights to upload.
- Do not use a system we built or host to send unsolicited bulk email or messages.
3. Regulated and sensitive data
Unless we have agreed otherwise in writing and signed the necessary additional terms:
- No protected health information. Do not submit PHI as defined by HIPAA. We do not currently offer a Business Associate Agreement. If you need one, ask before you send anything: team@seros.dev.
- No payment card data. Do not submit full primary account numbers, magnetic stripe data, card verification values, or anything else within PCI DSS scope. The current product path does not collect payment card data. If we build a system that will handle payments, the applicable payment provider and PCI scope must be documented in the SOW before launch.
- No government classified or export-controlled technical data, including ITAR or EAR controlled material.
- Be careful with special categories. Data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, sex life or sexual orientation, and criminal offence data, is high risk. Do not put it into a system we build or host, or hand it to us, unless you have a lawful basis, have told us in the DPA's Annex I, and have agreed any additional safeguards with us.
- No national identifiers at scale — social security numbers, passport numbers, driver's licence numbers, financial account numbers — unless agreed in writing.
4. AI-specific rules
These exist because the deliverables we build can generate text with probabilistic models, because we use such models in our own work, and because our model providers impose their own restrictions on us.
4.1 Human review of consequential decisions. Do not use a deliverable we built, alone or as the determining factor, to make or automate a decision that produces legal effects or similarly significant effects for a person. That includes decisions about employment, hiring, promotion, discipline or termination; credit, lending or insurance; housing; education admission; access to healthcare or essential services; immigration; and criminal justice outcomes. A qualified person must review and be able to override any output that feeds such a decision, and must be accountable for the result.
4.2 No prohibited high-risk uses. Do not commission or use a deliverable for biometric identification or categorisation of individuals, emotion inference in workplace or education settings, social scoring, predictive policing, or covert manipulation of behaviour. These are prohibited or heavily restricted under laws including the EU AI Act. We will not build them, and a request to do so ends the engagement.
4.3 Disclose AI where it matters. If output is used in communication with a person who would reasonably expect a human author, and law or common decency requires disclosure, make the disclosure. Do not present output as the work of a named person who did not review it.
4.4 Our materials. Do not use our pre-existing materials, tools or templates, or output derived from them, to develop a product or service that competes with us, beyond the licence granted in Section 9.2 of the Terms. This does not restrict your use of the deliverables you paid for and own.
4.5 No prompt attacks. Do not attempt to bypass safety systems, extract system prompts or model weights, inject instructions to make a system we host act outside its intended function, or use anything we built to attack another system's AI.
4.6 No professional advice output. Do not present output as legal, medical, tax, financial, or other professional advice, or use it to give such advice to a third party without a qualified professional reviewing it.
4.7 Provider policies. Our AI model providers publish their own usage policies. Your use must not put us in breach of them. The providers we use are listed in Subprocessors and we will pass through restrictions they require.
5. Scraping, automation and integrations
- Do not scrape, crawl, or harvest data from our website, or from third-party systems through a system we built for you, except as that system documents and within the third party's terms.
- Do not use a system we built to access a third-party system you are not authorised to access, or in a way that breaches that system's terms.
- Do not use automation to evade a suspension or a contractual limit.
- Connectors must be authorised by someone with authority to grant that access in your organisation.
6. Integrity of systems we host
This section applies to anything we host or operate for you, and to the Seros website.
- Do not attempt to discover or use undocumented endpoints, and do not automate, scrape, or load-test our systems without our prior written permission.
- Do not attempt to circumvent quotas, throttling, or billing.
- Do not run load tests, stress tests, or denial-of-service tests without our prior written consent. Where a care plan includes performance testing, the SOW says so and that is your consent.
- Do not use a system we host in a way that degrades it for another customer. We may throttle or suspend abusive traffic without prior notice if it threatens availability.
- Do not resell or provide access to a system we host for you to third parties unless your Statement of Work permits it.
7. Security research and testing
We welcome good-faith security research within these limits:
- Get written permission before any penetration test or automated scanning of our infrastructure. Request it at team@seros.dev with the scope and dates.
- Test only against accounts and data you own. Never access, modify or delete another customer's data.
- Do not perform denial-of-service testing, social engineering of our staff or vendors, or physical testing.
- Stop as soon as you confirm a vulnerability, and report it under the disclosure process in Security.
Research within those limits gets the safe harbour described in SECURITY.md. Research outside them is a breach of this AUP.
8. Reporting and enforcement
Report abuse or suspected violations to team@seros.dev with enough detail to investigate.
We may investigate suspected violations and may remove content or suspend access. Where practical we will notify you first and give you a chance to fix the problem. Where the violation threatens security, availability, or a person's safety, or where law requires it, we may act immediately. Repeated or severe violations can lead to termination without refund. We may report unlawful activity to the authorities.
9. Changes
We may update this AUP as the law, the product, or our providers' requirements change. We will post the updated version and, for material changes, give notice under Section 17.12 of the Terms.