Acceptable Use Policy
Effective 2026-08-13. Last updated 2026-08-13.
These are the rules for using Vendeflect. The most important one for this product: do not use it to fabricate compliance claims or certifications you do not hold. You also must not upload content you have no right to, attack the service, resell it without agreement, or evade your plan limits.
1.Scope
This Acceptable Use Policy applies to everyone who uses Vendeflect. It is part of our Terms of Service, and breaking it is a breach of those terms.
2.No fabricated compliance claims
Vendeflect helps you answer security questionnaires and publish a Trust Center. You must not use it, or the AI drafting in it, to state a certification, audit, standard or control that you do not actually hold or operate. Examples of what is prohibited:
- Claiming a SOC 2, ISO 27001, HIPAA, PCI DSS or similar status you have not achieved.
- Publishing a Trust Center answer that asserts a control you do not have in place.
- Using the AI to generate a compliance claim and sending it without verifying it is true.
Every answer is approved by a person on your side precisely so that a human confirms it is accurate. Fabricating compliance claims misleads your buyers and is not a use of this product we permit.
3.Content and conduct that is prohibited
- Uploading or publishing material you do not have the right to use or share, including someone else's confidential or copyrighted documents.
- Unlawful, deceptive, infringing, defamatory or harassing content.
- Malware, or content designed to harm, deceive or defraud others.
- Personal data you have no lawful basis to process, or special category data you are not permitted to handle.
4.No attacks on the service
- Attempting to access another workspace, account or data that is not yours.
- Probing, scanning or testing the security of the service without our written permission, or circumventing access controls, rate limits or plan gates.
- Interfering with or disrupting the service, its infrastructure, or other customers, including denial of service attempts.
- Scraping or bulk extracting data other than through your own workspace and your own API keys.
5.No reselling without agreement
You may use the service for your own organisation. You must not resell, sublicense, or provide the service to third parties as a service of your own without a separate written agreement with us.
6.Fair use and plan limits
Each plan has explicit limits, including a questionnaire cap and an AI answer cap, set out on our pricing page and enforced in the product with a warning at 80 percent and a block at 100 percent. Where a plan is described as offering an unlimited resource, that is subject to fair use: it means normal use for a single organisation, not automated, bulk or abusive volumes that degrade the service for others.
You must not attempt to evade a plan limit, for example by scripting around the caps or splitting one organisation's use across many free accounts.
7.Enforcement
If we believe you are breaking this policy, we may, depending on severity, contact you, remove or disable the content or activity in question, throttle or suspend access, or terminate your account under the Terms of Service. Where practical and lawful, we will give notice and a chance to fix the problem first, but we may act immediately where there is a risk to security, to others, or of legal harm.
To report a suspected violation or a security issue, email security@vendeflect.com.
Contact
- Support
- support@vendeflect.com
- Privacy requests
- privacy@vendeflect.com
- Entity
- Vendeflect