Abuse and Acceptable Use Policy
In this document
Introduction
SorviAI is shared infrastructure. Thousands of businesses keep their accounts, stock and payroll on it, so what one account does affects everyone else. This policy sets the line.
The rules are close to what you would guess: do not use the platform to break the law, do not publish things on our infrastructure that we would be liable for, do not attack the platform or other customers, and do not try to get around technical limits.
We investigate every abuse report we receive. Where we can, we talk to you before we act. Where the harm is immediate, we act first and explain afterwards. The section on enforcement and appeals covers how to challenge a decision.
Scope
This policy applies to everyone who uses SorviAI: customers, their users, people accessing a Portal, visitors to a storefront built on the platform, and anyone opening a shared link we host. It forms part of our Terms of Service.
Where the other policies take over
| Topic | Covered by |
|---|---|
| Sending unsolicited email, list practices, opt-outs, sender authentication | Anti-spam Policy |
| Misuse of our name and logo | Trademark Policy |
| What we do with personal information | Privacy Policy |
| Billing, cancellation, suspension for non-payment | Refund Policy |
| Everything else: content, conduct, security and resource use | This policy |
The principle
Do not use SorviAI to do something unlawful, to harm another person, to damage the platform, or to interfere with anyone else’s use of it.
The lists that follow are examples, not an exhaustive catalogue. Something is not permitted merely because it is not listed. If a use is obviously harmful and obviously not what business software is for, treat it as prohibited and ask us if you are unsure.
Prohibited content
Do not store, upload, publish or transmit through SorviAI any material that:
- Is unlawful, or promotes or facilitates unlawful activity.
- Sexually exploits or abuses children, or sexualises a minor in any way. We report this to the authorities in every case, without warning and without exception.
- Depicts or incites terrorism, extreme violence, or violence against a person or group.
- Harasses, threatens, bullies, defames or incites hatred against a person or group.
- Infringes copyright, trademark, patent, trade secret or any other intellectual property right.
- Is malware, ransomware, spyware, a virus, or code designed to damage or gain unauthorised access to a system.
- Is designed to deceive: forged documents, counterfeit listings, fake credentials or fraudulent invoices.
- Contains someone’s personal information published without a lawful basis, including doxxing.
- You do not have the right to store or share.
Prohibited activities
Do not use SorviAI to:
- Operate a fraudulent business, a pyramid or Ponzi scheme, or an advance-fee scam.
- Launder money, evade sanctions, or process transactions for a business you have concealed from us.
- Sell counterfeit, stolen or illegally imported goods, or goods you are not licensed to sell.
- Falsify accounting records to deceive an auditor, a tax authority, a lender or an investor.
- Impersonate another business or person, or misrepresent your affiliation with one.
- Collect or process personal data unlawfully, including employee data in the Worklink module.
- Evade a suspension or termination we have applied, including by opening a new account.
Publishing on our infrastructure
Some features let you make content publicly reachable without a login: a storefront, a shared file link, a quote or invoice preview sent to a customer, and self check-in or kiosk links for attendance. These carry extra responsibility, because the content is served from our systems to the open internet.
Rules for anything you publish publicly
- Everything in prohibited content and prohibited activities applies, and we enforce it more actively here because the exposure is public.
- Do not build a page designed to collect credentials, card details or bank details under false pretences. Phishing pages hosted on our infrastructure are removed immediately and reported.
- Do not use public links as general file hosting or a content delivery network. They exist to share a document with a counterparty, not to distribute media at scale.
- Do not publish a storefront selling anything you are not lawfully entitled to sell in the territories you ship to.
- Keep shared links current. Revoke a link when the person no longer needs it, and do not share a link to data you would not hand over on paper.
- You are responsible for what your own users publish, including anyone you invite into your workspace.
Security abuse
SorviAI keeps every customer’s data in a separate database schema. Attempting to cross that boundary is the most serious thing you can do on this platform, and we treat it accordingly.
| Activity | Permitted |
|---|---|
| Attempting to access another customer’s workspace, schema or data by any means | Never |
| Attempting to access an account, record or file you have not been granted permission to | Never |
| Probing, scanning or penetration testing the platform without our written consent | Never see security research below |
| Credential stuffing, brute forcing, or testing stolen credentials against our sign-in | Never |
| Interfering with authentication, tokens, session handling or two-factor verification | Never |
| Reverse engineering, decompiling or attempting to derive our source code | Never |
| Introducing malware, or using the platform to stage an attack on a third party | Never |
| Denial of service, amplification or any deliberate attempt to degrade availability | Never |
| Circumventing rate limits, quotas, access controls or app permissions | Never |
| Removing or altering audit records to conceal activity | Never |
Resource abuse
The platform applies rate limits and size limits so that one account cannot degrade the service for others. Uploads are capped at [UPLOAD LIMIT PER FILE], and public endpoints such as storefronts, kiosk and self check-in links, and shared uploads are rate limited per IP address.
Do not:
- Work around a rate limit by rotating IP addresses, accounts, workspaces or API credentials.
- Automate the interface to place load a human user could not generate, other than through our documented API within its limits.
- Scrape or bulk-extract data from the platform, from a storefront, or from another customer’s public pages.
- Use the platform for cryptocurrency mining, distributed computing or any workload unrelated to running your business.
- Use storage as a general file archive or backup target unrelated to your records in the product.
- Generate artificial load, including load testing, without our written agreement.
Account abuse
- A single account per person. Do not share a login between people. Seats exist so that each person has their own identity, and the audit log is worthless if three people share a sign-in.
- Do not create accounts to extend free trials or to avoid seat charges.
- Do not register accounts using false details or someone else’s identity.
- Do not resell or sublicense access to your workspace unless your agreement with us permits it.
- Keep credentials secure. Enable two-factor authentication, do not share codes, and tell us promptly if you believe an account has been compromised.
- Remove access when someone leaves. Deactivating a departing user is your responsibility, not ours.
Security research
The section on security abuse bans probing the platform. That ban is not aimed at people trying to help us, and we do not want it to stop you reporting a genuine flaw.
If you find a vulnerability, tell us at [SECURITY CONTACT EMAIL]. We will not pursue legal action against you, provided you:
- Report it to us promptly and give us a reasonable chance to fix it before telling anyone else.
- Only test against your own account or an account whose owner has permitted it. Never against another customer’s data.
- Stop as soon as you confirm a vulnerability exists. Do not pivot further into the system, and do not access, copy, modify or delete data that is not yours.
- Do not degrade the service, and do not run automated scanning that generates significant load.
- Do not extort us. A report conditioned on payment is not a disclosure.
[BUG BOUNTY POSITION, AND WHAT A REPORTER CAN EXPECT]
Reporting abuse
Report abuse to [ABUSE CONTACT EMAIL]. Tell us what you saw, where, and when. A link and a screenshot help enormously.
| What you are reporting | Where to send it |
|---|---|
| Illegal content, fraud, harassment, a phishing page | [ABUSE CONTACT EMAIL] |
| A security vulnerability | [SECURITY CONTACT EMAIL] |
| Unsolicited email sent through the platform | [ABUSE CONTACT EMAIL], and see the Anti-spam Policy |
| Copyright or trademark infringement | [LEGAL CONTACT EMAIL] |
| Misuse of our own brand | See the Trademark Policy |
We aim to acknowledge reports within [ACKNOWLEDGEMENT TIME] working days, and faster where the report involves child safety, an active phishing page or an imminent security risk. Reports involving child sexual abuse material are escalated immediately.
We do not usually tell a reporter what action we took against a specific account, because that is confidential to that customer. We will confirm that the report was investigated and closed.
How we investigate
We aim to be proportionate. Most reports turn out to be a misunderstanding, a misconfiguration or a dispute between two businesses that is not ours to settle.
- We look at what we can see without opening your records: public pages, audit metadata, delivery and error logs, and the report itself.
- We access workspace content only where it is necessary to investigate a credible report, or where the law requires it, and we limit that access to what is needed. Staff reach a customer workspace through an impersonation route that records who did it, when and against which workspace, and the record is a condition of the access rather than a by-product of it.
- We will normally contact you and give you a chance to explain or fix the issue before acting.
- We act first and explain afterwards only where the harm is immediate: child safety, an active phishing page, malware distribution, or an attack in progress.
Enforcement and appeals
Depending on what we find, and how serious it is, we may:
- Contact you and ask you to fix it.
- Remove or disable specific content or a specific public link.
- Restrict a feature, such as public sharing or sending, while leaving the rest of the workspace working.
- Suspend the account, temporarily, pending resolution.
- Terminate the account for serious or repeated breaches.
- Report to the authorities where we are required to, or where the conduct is criminal.
We aim to use the least disruptive measure that resolves the problem. Removing one link is better than suspending a company’s accounting system.
Your data during and after enforcement
Appealing
If you think we got it wrong, reply to the notice we sent, or write to [ABUSE CONTACT EMAIL] with the reasons. A person who was not involved in the original decision will review it, and we aim to respond within [APPEAL RESPONSE TIME] working days. If we made a mistake we will reverse it and say so.
Termination for breach of this policy is not refundable. That is set out in our Refund Policy.
Law enforcement and legal requests
We comply with valid legal process. We also check that it is valid, and we do not hand over customer data on an informal request.
- Requests must come through proper legal channels and be addressed to [LEGAL CONTACT EMAIL].
- We disclose only what the request actually compels, not everything we hold.
- Where we are legally permitted to, we notify the affected customer before disclosing, so they have an opportunity to challenge it.
- Where a request looks overbroad or improper, we push back.
- Because we are usually the processor rather than the controller, we will normally direct a request for a customer’s business records to that customer.
Changes to this policy
We may update this policy as the platform and the threat landscape change. The version and effective date at the top tell you which one you are reading, and previous versions remain available at [ARCHIVE URL].
We will give workspace owners at least [POLICY CHANGE NOTICE PERIOD] notice of material changes, except where an immediate change is needed to address active abuse or to meet a legal requirement.
How to contact us
If you are not sure whether something is allowed, ask before you do it. That is always easier than unwinding an enforcement action afterwards.