ManySignal is a defensive security platform. This Acceptable Use Policy is the line between the legitimate security operations we were built for and the misuse we are built to prevent. It is short, specific, and enforced.
Purpose and scope
This Acceptable Use Policy ("AUP") defines the conduct standards that apply to all customers, users, and any third parties who access the ManySignal platform (the "Service") or who transmit data through it. The AUP is incorporated by reference into the Terms of Service. Violation of this AUP is a material breach of those Terms and may result in immediate suspension or termination.
"You" means the Customer entity named on the applicable order form and any Authorized User operating under that Customer's tenant. Customer is responsible for ensuring that all Authorized Users are aware of and comply with this AUP.
Prohibited uses — security and hacking
You must not use the Service to: (a) conduct offensive security operations, penetration tests, or red-team exercises against any system, network, or device that you do not own or are not expressly authorised to test by the rightful owner; (b) develop, deploy, or distribute malware, ransomware, exploit kits, or any other malicious code; (c) circumvent, disable, attack, or degrade any security control on any system, including ManySignal's own infrastructure; or (d) use the Service's detection or response capabilities to monitor employees in jurisdictions where such monitoring is prohibited by law without adequate notice and consent.
ManySignal's platform is designed for defensive security operations. Any use that causes harm — actual or potential — to third-party systems is strictly prohibited regardless of your intent.
Prohibited uses — data and privacy
You must not: (a) upload, process, or transmit Customer Data that contains personal data of individuals for whom you lack a valid legal basis under applicable privacy law; (b) use the Service to profile, target, or surveil individuals based on protected characteristics; (c) combine Service outputs with third-party data sets to re-identify individuals who have been anonymised; or (d) use the Service to process data subject to export controls in a manner that violates the US Export Administration Regulations or equivalent regimes.
You must not transmit unsolicited commercial communications through any notification, webhook, or integration channel provided by the Service.
Prohibited uses — system integrity
You must not: (a) reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code or underlying algorithms of the Service; (b) access any API endpoint, internal route, or administrative interface not documented in our public API reference; (c) bypass or manipulate authentication, authorisation, or rate-limiting controls; (d) create multiple accounts to circumvent usage limits; or (e) reproduce or re-sell the Service or its outputs as a stand-alone competing product.
Automated access to the Service is permitted only through documented APIs using valid API keys. Scripted access that mimics human interaction to bypass controls is prohibited.
Prohibited uses — content
You must not use the Service to store, process, or transmit: (a) content that infringes or misappropriates third-party intellectual property rights; (b) content that is defamatory, obscene, or in violation of any applicable law; (c) personal health information unless you have executed a Business Associate Agreement with ManySignal; or (d) payment card data beyond what is strictly necessary for the security monitoring use case, and only where compliant with PCI-DSS requirements.
Resource usage and fair use
You must operate the Service within the resource limits specified in your subscription plan (events per second, retention duration, concurrent API calls). Sustained usage materially above your contracted limits that degrades Service performance for other tenants is a violation of this AUP and may result in throttling or suspension.
If your legitimate workload requires higher limits, contact your account team to discuss an upgrade or a custom plan. We will work with you in good faith to accommodate growing security operations needs.
Abuse detection and reporting
ManySignal monitors the Service for activity that may violate this AUP, including anomalous API call patterns, unusual data volumes, and egress of data inconsistent with detection and response use cases. This monitoring is performed using automated systems and, where flagged, human review.
If you observe or suspect abuse of the Service by another party — including credential stuffing, API abuse, or scraping — please report it to [email protected]. Reports are reviewed within one business day. Your report will be kept confidential.
Response to violations
Upon detecting or receiving credible evidence of an AUP violation, ManySignal may, at its sole discretion and without prior notice where urgency requires: (a) throttle or suspend the offending tenant's access to the Service; (b) terminate the Customer's account and subscriptions under the Terms of Service; (c) preserve and disclose data to law-enforcement authorities as required by applicable law; and (d) pursue all legal and equitable remedies available.
Where the violation is capable of being remedied and does not pose an immediate risk to ManySignal's infrastructure or other customers, ManySignal will provide written notice specifying the violation and a 48-hour cure period before taking further action.
Consequences and liability
You agree to indemnify and hold harmless ManySignal, its officers, directors, and employees from and against any claims, damages, fines, or costs (including reasonable attorneys' fees) arising from your violation of this AUP or your authorised users' violation of this AUP.
Termination of your account for AUP violation does not relieve you of payment obligations for the remainder of any committed subscription term. Prepaid fees are non-refundable in the event of termination for cause.
Changes to this policy
ManySignal may update this AUP from time to time. We will provide at least 30 days' advance notice of material changes via in-product notification and email to the Customer's registered billing address. Continued use of the Service after the effective date of a revised AUP constitutes acceptance of the updated terms. If you do not agree with a material change, you may terminate your subscription without penalty before the effective date of the change.
Questions about this policy should be directed to [email protected].
Questions about this document?
Contact our legal team at [email protected]. For security disclosure, use [email protected].