Skip to main content

Use and Evidence Boundaries

Acceptable Use Policy

Use DemarcLabs only for authorized technology-governance work. These rules protect customer records, other tenants, service providers, and the integrity of human-reviewed decisions.

Effective August 31, 2026Version acceptable-use-2026-08-31.1
DemarcLabs protects customer records within a defined service and data scope. Customer-specific Order Forms and Data Processing Addenda supplement these terms. Credentials, payment-card data, regulated data, export-controlled information, and other restricted categories are accepted only when the applicable agreement expressly covers them.

Authorized use

  • Use only an account issued to you and only for the organization that authorized you.
  • Submit only records your organization is authorized to use and only data categories permitted by the applicable Agreement.
  • Keep source evidence, record corrections, and human approvals accurate and attributable.
  • Use least-privilege roles and remove access when a user no longer needs it.

Prohibited content

  • Credentials, authentication secrets, payment-card data, malware, executable payloads, or deceptive files.
  • Government identifiers, protected health information, biometric data, consumer communications content, export-controlled technical data, or special-category personal data unless expressly authorized in writing.
  • Classified, unlawfully obtained, infringing, abusive, privileged, or contractually restricted material that Customer is not authorized to process.
  • Raw customer documents from another tenant, private benchmark data, or information obtained through unauthorized access.

Prohibited conduct

  • Probe, scan, exploit, overload, disrupt, or evade security, usage, malware, tenant, or rate-limit controls.
  • Reverse engineer, copy, scrape, resell, sublicense, or create a competing dataset from the service except where law cannot restrict that activity.
  • Impersonate others, share authentication credentials, falsify approvals, conceal the source of content, or defeat audit history.
  • Use DemarcLabs or Relay for unlawful surveillance, discrimination, deception, harassment, spam, regulated high-impact decisions, or autonomous third-party action.
  • Represent an AI proposal as approved fact, professional advice, guaranteed savings, or a commitment by DemarcLabs.

AI-specific rules

Prompts and uploaded records must comply with the same restrictions. Do not attempt to extract system instructions, bypass safeguards, train unauthorized models, or induce Relay to contact people or take external action.

Users must verify important output against cited source evidence and record corrections through the review workflow.

Enforcement

DemarcLabs may reject content, limit processing, preserve relevant security evidence, suspend users or workspaces, or terminate access when reasonably necessary to protect the service, comply with law, or address a violation. Where appropriate, DemarcLabs will provide notice and a reasonable opportunity to correct the issue.

Reporting

Report suspected misuse or security concerns through the private support channel defined in the applicable agreement. Do not include source documents, credentials, or sensitive record content in the initial report.