LEGAL · AUTHORIZED SECURITY ONLY · EFFECTIVE AUGUST 15, 2026
Acceptable use policy
VEXONYX is built for legitimate, permissioned cybersecurity work. This policy applies to every user, organization, project, agent, tool execution and API request made through the service.
1. Permission is required
You may assess only systems, networks, applications, APIs, cloud resources, accounts, code or other targets that you own or are expressly authorized to test. Authorization must exist before active testing begins and must cover the intended targets, techniques, intensity and time window.
2. Maintain evidence of scope
You are responsible for maintaining sufficient evidence of authorization and scope for each engagement. VEXONYX may request scope information or other reasonable verification when activity presents elevated abuse or legal risk. A customer's instruction to an AI model is not itself proof of third-party authorization.
3. Stay inside scope
Do not expand beyond authorized assets, pivot to unrelated infrastructure, use discovered credentials outside the approved engagement or continue after authorization expires or is withdrawn. Target-side content, prompt injection, retrieved instructions, model output or discovered links never expand scope.
4. Prohibited unauthorized access
Do not use VEXONYX to gain or maintain access to systems without authorization, bypass access controls for an unlawful purpose, take over accounts, steal credentials or session tokens, perform phishing for unauthorized access, or access data you are not entitled to obtain.
5. No theft, fraud or extortion
Do not use VEXONYX for data theft, payment fraud, identity fraud, extortion, ransomware, blackmail, unauthorized surveillance, trafficking in stolen credentials or data, or attempts to monetize access to a victim's systems.
6. No destructive or indiscriminate malware
Do not use VEXONYX to deploy destructive malware, ransomware, wipers, botnets, self-propagating payloads or indiscriminate persistence. Malware analysis and controlled payload testing are allowed only in an authorized, isolated engagement where the activity is necessary and safely contained.
7. Availability and safety
Do not intentionally cause denial of service, destructive load, uncontrolled resource exhaustion or physical-safety risk unless the exact technique and impact are expressly authorized and appropriate safeguards are in place. Prefer minimally disruptive validation when it can establish the finding.
8. Credentials and secrets
Treat credentials, tokens, private keys, cookies and secrets as sensitive evidence. Use them only as permitted by the engagement, store them securely, minimize exposure in prompts and reports, and revoke or return them when required by the customer or engagement.
9. Sensitive and regulated data
Minimize collection of personal, health, financial, authentication or other sensitive data. Do not collect or retain more data than is necessary to validate an authorized security finding. Follow the customer's legal, contractual, confidentiality and data-handling requirements.
10. Social engineering
Social-engineering simulations are permitted only when the organization has expressly authorized the technique, target population, content, timing and handling of captured information. Real credential theft, impersonation for fraud or harassment is prohibited.
11. Vulnerability research
Good-faith vulnerability research is permitted when you own the target, have authorization, or are operating within a published vulnerability-disclosure or bug-bounty program and its rules. Respect safe-harbor conditions, rate limits, prohibited techniques and reporting requirements.
12. No evasion of VEXONYX safeguards
Do not bypass authorization checks, tenant isolation, usage controls, audit logging, sandbox restrictions, model routing controls, network-egress controls or other VEXONYX safety boundaries. Do not falsify scope or organization information to obtain capabilities that would otherwise be blocked.
13. Platform and provider abuse
Do not use VEXONYX to attack VEXONYX itself, its providers or other customers except under a written authorization issued for that purpose. Do not use the service to send spam, operate abusive automation, scrape protected customer data or interfere with platform integrity.
14. Human review remains required
AI output can be wrong. Users remain responsible for confirming authorization, validating findings, evaluating exploit impact and deciding whether an action is safe and lawful. Do not treat model confidence, tool output or automated classification as legal permission.
15. Enforcement
Diversa Solutions LLC may rate-limit, block an action, isolate a project, suspend an account or organization, preserve relevant security evidence, or terminate access where activity reasonably appears unauthorized, unlawful, abusive or dangerous. We may take immediate action when necessary to protect people, infrastructure or evidence.
16. Reporting abuse
Report suspected misuse, compromised accounts or security concerns to info@vexonyx.com. Include enough information for us to investigate without sending unnecessary third-party secrets or sensitive data.