Acceptable Use

Use Qytherion AI responsibly and lawfully.

This Acceptable Use Policy defines what is and is not allowed when using Qytherion AI services, including GPT Workspace, Qytherion AI orchestration, call center features, AI workflows, and integrated providers such as Twilio.

Quick rules

  • One seat, one person. Named users and MFA are mandatory.
  • Consent first. Calls and texts require legally valid consent where required.
  • No abuse. Spam, fraud, impersonation, and illegal surveillance are prohibited.
  • Report fast. Security incidents must be reported immediately and no later than 24 hours after discovery.
  • Strict enforcement. We monitor for abuse and may block traffic or report malicious activity to network operators.

1. Identity & Access

Seat ownership, authentication, and permissions

Every action in the workspace must map to an accountable operator.

Named users only. Shared credentials, alias accounts, and generic inbox logins are prohibited.

MFA required. Multi-factor authentication must remain enabled for all users with platform access.

Least privilege. Grant only the minimum permissions required for each role and remove access promptly when no longer needed.

Credential protection. API keys, tokens, and secrets must be stored securely and never embedded in public repositories, screenshots, or support forums.

Provisioning records. Access grants, role changes, and removals should be traceable by timestamp and approver.

2. Communications Compliance

Rules for calls, SMS, voice agents, and campaigns

If you use call center or messaging features, compliance obligations apply at all times.

Consent and permissions. You must obtain, retain, and be able to prove legally sufficient consent before contacting recipients where consent is required.

Do-not-call and suppression. You must maintain and honor internal suppression lists, national/state DNC requirements, and recipient opt-outs without delay.

Opt-out processing. STOP/UNSUBSCRIBE and equivalent commands must be honored promptly across all relevant channels.

Caller identity integrity. Spoofing, deceptive caller ID, or masking origin to mislead recipients is prohibited.

Recording disclosure. If calls are recorded or monitored, required notices and consent must be provided per jurisdiction.

Calling windows. You must operate within legally allowed local contact windows and holiday/time restrictions.

Provider policy flow-down. Use of Twilio or any messaging/voice provider must comply with that provider's terms, campaign registration requirements, and anti-abuse policies.

High-risk outreach. Political persuasion, sensitive health outreach, debt collection workflows, and regulated vertical campaigns require legal review before activation.

3. Content & Workflow Safety

What automations may not do

Workflows must not harm people, systems, or platform integrity.

Fraud and deception prohibited. No impersonation, phishing, scam scripting, identity theft, or deceptive offer framing.

No harassment or abuse. Do not generate threatening, discriminatory, exploitative, or harassing content or outreach flows.

No malware or intrusion. You may not use the platform to deliver malware, exploit vulnerabilities, evade controls, or interfere with systems.

No illegal surveillance. Stalking, covert tracking, unauthorized interception, or non-consensual monitoring is prohibited.

No model abuse. Attempts to jailbreak, bypass platform safeguards, or create disallowed outputs at scale are prohibited.

Human review for sensitive use. AI outputs used for legal, medical, financial, or rights-impacting decisions must undergo qualified human review before action.

4. Data Protection

Privacy, data minimization, and records

Collect and process only what is needed, and protect it appropriately.

Minimum necessary data. Only collect and upload fields required for campaign execution and compliance.

Sensitive data controls. Do not process sensitive categories unless explicitly authorized by your agreement and secured with required safeguards.

Retention discipline. Keep campaign and contact data only as long as needed for operations and legal obligations, then delete or anonymize it.

Consent evidence. Preserve consent source records and compliance metadata for audit, dispute, and provider review.

Cross-border caution. You are responsible for complying with jurisdictional transfer and privacy obligations applicable to your recipients and operations.

5. Platform Integrity

Load limits, integrations, and environment security

Keep operations stable and avoid behavior that degrades shared infrastructure.

Within-plan usage. Respect plan limits, fair-use controls, and configured throughput safeguards.

No abusive scaling. Do not run unbounded loops, uncontrolled retries, or traffic floods that can degrade service for others.

Approved integrations. Connect only APIs and tools you are authorized to use. Unauthorized connectors or unvetted extensions may be disabled.

Device hygiene. Use encrypted endpoints with current OS patches, endpoint protection, and secure local storage.

Network trust. Avoid public or anonymous networks for privileged operations unless additional controls are in place.

Security monitoring. We operate continuous automated and manual monitoring for unauthorized access attempts, vulnerability scanning, credential theft, spam, and other platform abuse. Monitoring may include network identifiers, request metadata, authentication signals, and security event logs.

Sentinel. We operate an automated security layer named Sentinel that analyzes traffic and may block, rate-limit, or report abusive behavior without prior notice. Sentinel is designed to defend production systems; its rules, signals, and response playbooks are not published.

Additional in-house models. We use other proprietary models for workspace routing, quality, and operations. We do not publish their names, weights, or internal specifications.

Prohibited security research. Unless we give you written permission, you may not run automated scanners against our production surfaces, attempt to access sensitive or non-public paths, harvest credentials or configuration, or use browser developer tools to inspect production systems for unauthorized security research.

Protective controls. We may apply rate limits, blocks, quarantines, account restrictions, and permanent denial of access when we reasonably believe traffic is malicious, deceptive, or harmful. Controls may be applied at the edge, application layer, or through upstream providers and may occur automatically.

No circumvention. You may not probe, bypass, disable, or interfere with our security controls, monitoring systems, or enforcement mechanisms.

6. Incident Response

Reporting, containment, and cooperation

Fast reporting and transparent remediation are required.

Immediate containment. Disable affected workflows and rotate exposed credentials as soon as suspicious behavior is detected.

Report within 24 hours. Notify us at [email protected] with incident time range, impacted systems, agent names, and mitigation actions.

Evidence preservation. Preserve relevant logs, campaign payloads, and event traces needed for forensic review.

Cooperation duty. You must cooperate with reasonable remediation requirements, including temporary pauses, key rotation, and runbook updates.

7. Enforcement

What happens when this policy is violated

Enforcement is risk-based and may be immediate for severe violations.

Graduated controls. Depending on severity, we may issue warnings, reduce limits, disable integrations, pause campaigns, or suspend accounts.

Immediate suspension cases. Fraud, abuse, legal exposure, recipient harm, or provider enforcement risk may result in immediate suspension without prior notice.

Termination. Repeated or severe violations can result in permanent termination and denial of future access.

Provider and regulator cooperation. We may share required records with infrastructure providers, telecom carriers, network operators, and regulators where law, contract, or reasonable abuse-handling practice requires.

Network abuse reports. Where we have reasonable evidence of scanning, credential theft, malware distribution, or similar misuse originating from a network address, we may submit abuse complaints to the responsible hosting provider, ISP, or upstream operator. Reports are based on our security logs and are intended to stop ongoing harm—not to disclose internal security methods.

No duty to warn attackers. We are not obligated to notify unknown third parties before applying blocks or filing abuse reports when delay could increase risk to our systems or users.

8. Exceptions & Appeals

Requesting exceptions or review

Some use cases may be approved with additional controls.

Exception requests. Submit exception requests in writing before launching non-standard workflows or high-risk campaigns.

Required detail. Include campaign purpose, target audience, jurisdictions, consent model, scripts, and safety controls.

Appeals. If you believe enforcement was applied in error, you may request review with supporting evidence and remediation history.

Reference documents. See the Terms of Service, Privacy Policy, Data Retention, and Proof of Consent pages for related obligations.

Policy updates. This policy may be revised as legal, provider, and platform requirements evolve. Continued use indicates acceptance of the current version.

Last updated: May 21, 2026.