Legal

Acceptable Use Policy

What you may and may not do with VibeLock. Read the authorisation section carefully.

Effective 17 August 2026Updated 17 August 2026

VibeLock produces security guidance and techniques. Applied to a system you do not own or are not authorised to test, that guidance can constitute a criminal offence. This policy is not a formality.

1. Authorisation is your responsibility

You may use the Service only in respect of systems you own or are expressly authorised in writing to assess. Written authorisation should identify the systems in scope, the permitted activities, and the period covered.

Unauthorised access to or testing of a computer system may violate the Computer Fraud and Abuse Act (18 U.S.C. § 1030) in the United States, the Computer Misuse Act 1990 in the United Kingdom, Directive 2013/40/EU in the European Union, and comparable laws elsewhere. Penalties include criminal liability.

If you are an employee or contractor, your employer or client must authorise the assessment. Your personal access to a system does not by itself constitute authorisation to test it.

2. Prohibited activities

  • Assessing, probing or attacking any system without authorisation.
  • Using the Service to plan, facilitate or conceal unlawful activity.
  • Uploading malware, or content that infringes intellectual property or violates law.
  • Harassment, threats, or content that is unlawful, defamatory or hateful.
  • Copying, redistributing, reselling or publishing the prompt library, checklist content, threat templates or policy templates.
  • Automated scraping or bulk extraction beyond our provided export functions.
  • Circumventing plan limits, rate limits or access controls.
  • Sharing account credentials, or allowing multiple individuals to use a single seat.
  • Misrepresenting what the Service reported as a certification, audit or third-party verification.
  • Interfering with the Service, including denial of service, or testing our own infrastructure outside our disclosure policy.

3. Testing VibeLock itself

We welcome good-faith security research into our own platform. Do it under our Responsible Disclosure Policy, report findings to security@vibelock.ai, do not access data that is not yours, do not degrade the service, and give us reasonable time to remediate before disclosure. Research conducted within that policy will not be treated as a breach of this one.

4. Enforcement

We may investigate suspected violations and may suspend or terminate access immediately, without refund, where we reasonably believe this policy has been breached. Where required, we will report unlawful activity to the relevant authorities.

Report abuse to legal@vibelock.ai.

Acceptable Use Policy · Effective 17 August 2026 · All legal documents