RedactAgent Acceptable Use Policy
This policy protects RedactAgent, customers, data subjects, and subprocessors. It forms part of the RedactAgent Terms and Conditions unless a signed client agreement states otherwise.
1. Authorised professional use
RedactAgent is intended for authorised document review, redaction, DSAR, legal, compliance, investigation, privacy, and regulated-data workflows. Customers must ensure that their users have authority to process the relevant documents and personal data.
2. Prohibited use
- Do not upload or process data without lawful authority or required client approval.
- Do not use the service to harass, discriminate, defraud, surveil, dox, or harm individuals.
- Do not upload malware, exploit payloads, secrets for unauthorised systems, or content intended to compromise the service.
- Do not attempt to bypass authentication, tenant isolation, billing limits, rate limits, plan limits, or export controls.
- Do not scrape, benchmark, reverse engineer, overload, resell, or provide bureau-style access unless expressly permitted in writing.
- Do not use AI or OCR outputs as final legal determinations without appropriate human review.
3. Fair use and bulk processing
Plans include stated allowances and fair-use limits. Customers must not use multiple trial accounts, shared logins, scripted queueing, excessive retries, abnormal reruns, or automated bulk uploads to avoid the intended commercial limits. Large matters, unusually high-volume processing, API-like usage, or dedicated deployment needs should use an appropriate paid or enterprise plan.
4. Security responsibilities
- Use strong account security and protect access links, passwords, SSO sessions, and API keys.
- Promptly remove users who no longer need access.
- Configure tenant, matter, export, AI, OCR, integration, and retention settings appropriately.
- Report suspected unauthorised access, exposed credentials, or cross-tenant data issues promptly.
5. AI and redaction review obligations
AI suggestions, OCR, ML detections, DSAR classifications, privilege risk indications, and extraction output must be reviewed by qualified users before disclosure, reliance, or production. Customers remain responsible for final legal, privacy, disclosure, withholding, and redaction decisions.
6. Enforcement
RedactAgent may throttle, suspend, block, or terminate access where use creates security risk, legal risk, service instability, non-payment, excessive load, policy breach, or risk to other customers. RedactAgent may preserve relevant logs and evidence to investigate abuse or security incidents.
7. Contact
Report misuse or security concerns to team@redactagent.io.