Legal
Acceptable Use Policy
Status of this document
Engineering draft for counsel to review. Not yet a binding policy. Contact mailboxes marked like this still have to be confirmed.
Korps agents can run commands on real servers, call real tools and send real messages. That makes this policy about consequences, not etiquette.
1. Scope
This policy applies to everyone using Korps, to every agent you configure, and to anyone you invite into your workspace. Actions taken by your agents count as your actions.
2. Authorisation is the core rule
- Connect only infrastructure, accounts, repositories and credentials you own or are clearly authorised to use.
- Point agents only at systems you are authorised to touch. Authorisation from the system's owner must be real, current and documented.
- Do not use Korps to reach systems through someone else's credentials, session or network position.
3. Prohibited activity
3.1 Illegal and harmful
- Anything unlawful where you are, where we operate, or where the target system is.
- Child sexual abuse material, or any sexual content involving minors, in any form.
- Content or actions that promote terrorism, or that facilitate violence against people.
- Developing or obtaining weapons, including chemical, biological, radiological, nuclear or high-yield explosive capability.
- Harassment, stalking, doxxing, threats, or targeting of individuals.
3.2 Security abuse
- Unauthorised access, scanning, penetration testing or exploitation of systems you do not own or have written authorisation to test.
- Creating, distributing or operating malware, ransomware, botnets or command-and-control infrastructure.
- Denial-of-service attacks, resource exhaustion or traffic amplification.
- Credential harvesting, phishing pages, or social-engineering campaigns against third parties.
- Techniques whose purpose is to evade another party's security monitoring or detection.
- Attacking Korps itself, other customers, or any shared infrastructure. Coordinated security research is welcome under the process on our Security page.
3.3 Abuse of the platform
- Circumventing usage metering, rate limits, allowances or workspace boundaries.
- Creating accounts in bulk, or automating signup.
- Reselling or sublicensing metered model access, or acting as a proxy that lets others use your allowance.
- Reverse engineering the service to build a competing product, except where that restriction is unenforceable by law.
- Attempting to read another workspace's data, or probing tenancy boundaries outside an authorised test.
3.4 Data and privacy
- Uploading personal data you have no lawful basis to process.
- Uploading special-category data (health, biometric, genetic, precise location of individuals, political or religious belief) into Korps. The platform is not configured for it.
- Scraping personal data at scale, or building profiles of individuals without a lawful basis.
- Uploading payment card data, government identity documents, or credentials belonging to other people.
3.5 Deception
- Presenting agent output as human when the person you are dealing with would reasonably expect a human, where disclosure is required by law.
- Impersonating a real person or organisation.
- Generating disinformation campaigns, fake reviews, coordinated inauthentic behaviour or election interference material.
- Spam, unsolicited bulk messaging, or sending mail in breach of anti-spam law.
3.6 High-consequence automation
Do not let an agent make a final decision without meaningful human review where the decision materially affects a person, including:
- medical diagnosis or treatment;
- legal advice or filings;
- credit, insurance or financial eligibility;
- hiring, promotion or termination;
- housing, education or benefits eligibility;
- safety-critical control of physical systems.
4. Destructive operations
Even inside your own infrastructure, treat destructive actions as requiring explicit human approval: force-pushing or rewriting shared history, deleting backups or production data, rotating or exposing credentials, escalating privilege, and payment actions. Auto-approval settings must not be used to blanket-approve these.
5. Reporting a violation
Report abuse to abuse@korps.ai (mailbox to be confirmed before publication) with enough detail to reproduce or locate it. Report security vulnerabilities through the process on the Security page instead.
6. Enforcement
Depending on severity we may warn you, throttle a workspace, remove content, suspend an account, terminate access, or report to authorities where we are required to. We aim to give notice and a chance to remedy first, except where the violation is severe, ongoing or unlawful.
7. Changes
We will update this policy as the product and the risks change, and will change the version and date at the top.