Acceptable Use Policy
v1.0.1Effective Date: August 14, 2026
This Acceptable Use Policy (the "AUP") describes activities that are prohibited when accessing or using the Unit Oncall service (the "Service") provided by G Y UNIT LIMITED LIABILITY COMPANY ("we", "us", "our", or the "Company"). This AUP is incorporated into, and forms part of, the Terms of Service ("Terms") under §8 (Acceptable Use) of the Terms. Capitalized terms used but not defined in this AUP have the meanings given to them in the Terms.
You are responsible for ensuring that your use of the Service, and the use of the Service by anyone acting under your authority — including members of your organization, users you invite, and any AI agent you configure to act on your behalf — complies with this AUP.
In the event of any conflict between this AUP and the Terms, this AUP shall govern with respect to the acceptable use of the Service.
1. NATURE AND PURPOSE OF THIS AUP
The Service includes features that permit an AI agent to make outbound network requests, to connect to third-party systems using credentials that you supply, and to interact with custom integrations (including custom MCP servers and webhooks) that you configure. These features create categories of risk that ordinary software-as-a-service products do not present. This AUP sets out the minimum standards of conduct that we require in order to provide these features safely to all customers.
This AUP is not a substitute for our technical safeguards, and our technical safeguards are not a substitute for this AUP. The two are complementary. Technical safeguards reduce the likelihood that a user unintentionally causes harm; this AUP defines what conduct is prohibited and reserves our right to take action when it occurs.
2. PROHIBITED ACTIVITIES
You shall not use the Service, and shall not permit any person or AI agent acting under your authority to use the Service, to engage in any of the following activities.
2.1 Attacks on Third Parties
You shall not use the Service to:
- Conduct unauthorized port scanning, vulnerability scanning, network reconnaissance, or fingerprinting of systems that you do not own or that you are not expressly authorized in writing to test;
- Participate in, launch, or facilitate a denial-of-service or distributed denial-of-service ("DDoS") attack against any system;
- Perform password guessing, credential stuffing, brute-force authentication, or any similar activity against systems that you do not own or that you are not expressly authorized in writing to test;
- Operate a command-and-control channel, botnet node, relay, proxy, tunnel, or exit node whose purpose is to obscure the origin of malicious traffic;
- Develop, host, distribute, deliver, or execute an exploit, dropper, loader, rootkit, ransomware, spyware, keylogger, or any other form of malicious software;
- Facilitate the compromise of any system, account, or credential belonging to a third party.
2.2 Resource Abuse
You shall not use the Service to:
- Mine, farm, or otherwise generate cryptocurrency, non-fungible tokens, or comparable digital assets;
- Perform distributed computation for the purpose of financial gain unrelated to the intended operational use of the Service;
- Consume compute, network, storage, or other resources in a manner that is disproportionate to legitimate incident response and operational tasks, or that is designed to circumvent fair-use limits, quotas, rate limits, or plan entitlements;
- Deliberately generate load intended to degrade the Service for other customers.
2.3 Unlawful, Harmful, and Abusive Content
You shall not use the Service to send, store, distribute, or facilitate:
- Unsolicited bulk messages, spam, phishing, or other deceptive communications;
- Malware, viruses, worms, or other malicious code;
- Content that infringes the intellectual property rights of any third party;
- Content that is unlawful under applicable law, including but not limited to child sexual abuse material, content that incites violence, or content that constitutes unlawful harassment;
- Content that violates the privacy rights of any person, including the unlawful collection, disclosure, or sale of personal information.
2.4 Circumvention of Security and Isolation Controls
You shall not, and shall not attempt to:
- Access data, credentials, sessions, or resources belonging to another customer or organization ("tenant") of the Service;
- Escalate privileges beyond those granted to your account or organization;
- Bypass, disable, or circumvent technical controls that we operate;
- Exfiltrate data from systems you access through the Service to destinations not authorized under your organization's configuration;
- Probe, scan, test, or attempt to compromise the security of the Service itself, other than through a security research program that we operate or otherwise expressly authorize in writing (see §7 below).
2.5 Misuse of Credentials and Access
You shall not:
- Share, transfer, sell, or lease your account credentials, session tokens, or API keys;
- Access the Service using credentials that you are not authorized to use;
- Configure the Service to access infrastructure, services, accounts, MCP servers, or webhook endpoints that you do not own or are not authorized to access;
- Use the Service to store, process, or transmit credentials that you have obtained without proper authorization.
2.6 Misuse of AI Features
You shall not use the AI features of the Service, including Buddy Chat and AI-assisted summarization, to:
- Generate, plan, or execute any activity that would violate this AUP if performed directly;
- Attempt to induce the AI to bypass its own safety instructions or the technical controls that we operate;
- Generate content designed to deceive, defraud, or unlawfully manipulate any person;
- Automate decisions that produce legal or similarly significant effects on individuals in a manner that is prohibited by applicable law.
You acknowledge that AI-generated output is probabilistic and may be incorrect. You are responsible for reviewing and validating AI-generated commands, summaries, and recommendations before acting on them, and you shall not treat AI output as a substitute for human judgment in matters that materially affect your systems, your customers, or third parties.
3. YOUR RESPONSIBILITIES
3.1 Credentials, Secrets, and Access Scope
You are responsible for the credentials, tokens, and secrets that you supply to the Service. You are responsible for scoping those credentials to the minimum privileges necessary for the tasks you intend the Service to perform on your behalf, and for rotating or revoking them when appropriate. You are responsible for the actions taken by the Service — including actions taken by an AI agent — using those credentials.
3.2 Configuration of Controls
Where the Service provides configurable controls — including but not limited to per-role permissions and integration scopes — you are responsible for configuring those controls in a manner appropriate to your risk tolerance and your obligations to third parties. Your failure to configure available controls does not shift responsibility for the resulting activity to us.
3.3 Authorization to Connect Third-Party Systems
When you configure the Service to connect to your own infrastructure, to a third-party service, to a custom MCP server, or to a webhook endpoint, you represent and warrant that you have the necessary rights and authorizations to do so, and that such connection does not violate any contract, license, or policy applicable to the target system.
3.4 Supervision of Users and Agents
You are responsible for the conduct of the users you invite to your organization on the Service, and for the conduct of any AI agent that you configure to act on your organization's behalf. Actions taken by users or agents acting under your authority are treated as your actions for the purposes of this AUP.
3.5 Applicable Law
You are responsible for complying with all laws applicable to your use of the Service, including but not limited to laws concerning unauthorized computer access, data protection, export control, and financial services. Where you process personal data through the Service, you are responsible for having a lawful basis for that processing under the law applicable to you.
4. MONITORING AND ENFORCEMENT
4.1 Monitoring
We may, but are not required to, monitor use of the Service for compliance with this AUP. Where we monitor, we do so through operational telemetry, audit logs, egress logs, security event logs, and similar signals collected in the ordinary course of operating the Service, as further described in our Privacy Policy. We do not routinely inspect the substantive content of your data solely to assess compliance with this AUP, but we reserve the right to do so where we have a reasonable basis to believe that a violation has occurred and where such inspection is permitted by applicable law.
4.2 Response to Violations
Where we determine that a violation of this AUP has occurred or is occurring, we may take one or more of the following actions, at our reasonable discretion, taking into account the severity, duration, and impact of the violation:
- Issue a warning to the affected organization or user;
- Require the affected organization to remediate the violation within a stated period;
- Throttle, rate-limit, or degrade specific features of the Service for the affected organization or user;
- Suspend access to specific features, sessions, or resources;
- Suspend or terminate the affected user's account or the affected organization's access to the Service in whole or in part;
- Preserve, disclose, or transmit information about the violation to law enforcement, to affected third parties, or to other parties as required by applicable law or to protect the rights, property, or safety of any person.
4.3 Immediate Action
Where we reasonably believe that a violation presents an imminent risk of material harm — including, without limitation, active attacks on third parties, active exfiltration of data, or active compromise of the Service or another customer — we may take any of the actions described in §4.2 immediately and without prior notice. We will provide notice as soon as reasonably practicable after taking such action.
4.4 Notice and Opportunity to Cure
Except in the circumstances described in §4.3, we will provide the affected organization with notice of the alleged violation and a reasonable opportunity to cure before terminating access. The form and duration of such notice and opportunity to cure will be determined by us in light of the circumstances of the violation.
4.5 No Waiver
Our failure to enforce this AUP in any particular instance does not waive our right to enforce it in any other instance.
5. REPORTING ABUSE AND SECURITY ISSUES
If you become aware of a violation of this AUP, or of a security issue affecting the Service, please contact us at:
- Abuse and AUP violations: legal@unit-oncall.com
- Security vulnerabilities: security@unit-oncall.com
We aim to acknowledge reports concerning active attacks or ongoing abuse promptly during our business hours. Acknowledgment does not itself constitute a determination that a violation has occurred.
When reporting, please provide sufficient detail to allow us to investigate, including timestamps, affected identifiers, and the nature of the observed activity. Do not include unnecessary personal data.
6. LIMITATION ON CUSTOMER-INITIATED INVESTIGATION
You shall not attempt to identify, contact, or take action against another customer of the Service on the basis of activity that you attribute to that customer. If you believe another customer is engaged in a violation of this AUP that affects you, please report it to us under §5 and allow us to investigate.
7. AUTHORIZED SECURITY RESEARCH AND PENETRATION TESTING
Nothing in §2.4 prohibits security research or penetration testing that is:
- Conducted against systems that you own or that you are expressly authorized in writing by the owner to test;
- Conducted under a formal program that we operate or that we have expressly authorized in writing; or
- Otherwise conducted in a manner consistent with a coordinated vulnerability disclosure process that we have expressly agreed to.
Where you wish to conduct security research against the Service itself, please contact us in advance at security@unit-oncall.com. Unauthorized testing of the Service is prohibited and may be treated as a violation of this AUP.
8. CHANGES TO THIS AUP
We may update this AUP from time to time to reflect changes in the Service, in applicable law, or in the categories of misuse that we observe in practice. Where we make a material change, we will provide notice by the means described in the Terms. Your continued use of the Service after the effective date of an update constitutes acceptance of the updated AUP.
9. RELATIONSHIP TO OTHER TERMS
This AUP supplements, and does not replace, the Terms and the Privacy Policy. Nothing in this AUP limits any right or remedy available to us under the Terms, the Privacy Policy, or applicable law.
10. CONTROLLING LANGUAGE
This AUP is drafted in the English language. In the event of any discrepancy between the English version of this AUP and any translation, the English version shall prevail and be controlling.
Questions about this policy? Contact us
