Acceptable Use Policy
Last updated: 25 August 2026
1. Purpose
This Acceptable Use Policy ("AUP") defines the boundaries for using the Wytness platform. It supplements our Terms of Service and applies to all users, including individuals and organisations accessing the Service through SDKs, APIs, or the dashboard.
2. Permitted Use
The Service is intended for:
- Logging and auditing AI agent actions for compliance, governance, and operational visibility
- Verifying the integrity of audit trails through cryptographic signatures and hash chains
- Monitoring agent behaviour through anomaly detection and alerting
- Producing evidence packs for regulatory frameworks such as SOC 2, ISO 27001, and the EU AI Act
- Exporting audit data for regulatory reporting or internal review
3. Prohibited Activities
You may not use the Service to:
- Submit data that you do not have the right to collect, process, or store
- Transmit malware, viruses, or any code designed to harm or disrupt
- Attempt to bypass authentication, access controls, rate limits, or quota enforcement
- Probe, scan, or test the vulnerability of the Service or its infrastructure outside of responsible disclosure — report vulnerabilities as described on our Security page
- Impersonate another user, organisation, or agent
- Use the Service for any activity that violates applicable law or regulation
- Submit audit events containing unprotected personal data in violation of privacy laws (use the SDK's PII protection features to redact sensitive fields)
- Submit special category personal data, biometric identifiers, payment card data, or other sensitive data without an appropriate lawful basis and the redaction or pseudonymisation steps required by law
- Generate artificial or synthetic event volume to manipulate usage metrics or billing
- Use the Service to monitor individuals without a legitimate audit, governance, or workplace-policy purpose
- Resell, sublicense, or provide access to the Service to third parties without our written consent
- Scrape, mirror, or extract content from the Service or our marketing site for the purpose of training a competing product or model
- Submit content that depicts the sexual exploitation or abuse of minors, that promotes or facilitates terrorism, or that incites violence or unlawful discrimination
4. API and SDK Usage
- Respect published rate limits. Automated retries should use exponential backoff and respect
Retry-Afterheaders - Do not share API keys across organisations or expose them in client-side code or public repositories
- Rotate signing keys promptly if a private key is compromised; revoke API keys promptly when no longer needed
- Use the latest supported SDK version to ensure compatibility, security, and access to PII protection features
- Verify webhook signatures before acting on webhook payloads
5. Data Responsibilities
You are responsible for the content of the audit events you submit. Ensure that your use of the Service complies with all applicable data protection laws, including but not limited to the GDPR, UK GDPR, Swiss FADP, CCPA/CPRA, LGPD, PIPEDA, and any sector-specific regulations that apply to your industry. Use the SDK's built-in PII redaction before submitting events that may contain personal data, and use the Business plan with customer-hosted storage where data residency or sovereignty requirements demand it.
6. Resource Limits
Each plan includes defined limits for agents, events, and data retention. Usage beyond your plan's included allocation is subject to overage charges as described in your subscription terms. We reserve the right to throttle or suspend accounts that consistently exceed reasonable usage patterns or that create disproportionate load on the Service.
7. Enforcement
Violations of this AUP may result in warnings, temporary suspension, or permanent termination of your account, and where appropriate, referral to law enforcement. We will make reasonable efforts to notify you before taking action, except where immediate action is necessary to protect the Service, other users, or the public. Decisions regarding enforcement are at our sole discretion.
8. Reporting Violations
If you become aware of any violation of this policy, or content on the Service that you believe is illegal, please report it to support@wytness.ai.
9. Changes
We may update this AUP from time to time. Material changes will be communicated via email or through the dashboard. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.