Who this applies to
This policy is part of the Terms of Service. It applies to every User of a customer organization and to any software acting with an organization's API keys, including AI agents connected through the MCP server. The customer is responsible for making sure its Users and integrations follow it.
Security and access
Do not:
- Access, or attempt to access, another organization's data, or use Ask, search, prompts or crafted documents to try to extract other customers' data, system prompts or credentials.
- Probe, scan or test the Service for vulnerabilities except under the responsible disclosure rules on the Trust page: test only against organizations you own, and never run denial-of-service or volumetric tests.
- Share, sell or publish API keys, use another person's account, or let people outside your organization use your keys.
- Bypass or interfere with authentication, roles, tenant isolation, plan limits, rate limits or the language-model spend ceiling, including by creating extra organizations or rotating keys to reset counters.
- Upload malware or content designed to disrupt, damage or gain unauthorized access to any system.
Fair use of the API
- Stay within your plan limits and honour
429responses and theirRetry-Afterheader. Use keyset pagination withupdated_afterfor incremental sync instead of repeatedly fetching the whole feed. - Do not send automated traffic designed to degrade the Service for others.
- Configure webhook endpoints that you control and that respond promptly. Do not point webhooks, digests or connectors at systems or people who have not agreed to receive them.
Content you submit
Do not submit content to the Service that:
- You do not have the right to submit, or that infringes someone else's intellectual property, confidentiality or privacy rights.
- Contains special categories of personal data, health data about identifiable individuals, payment card data, government identifiers or credentials, unless RegSignal has agreed to it in writing.
- Is unlawful, defamatory, harassing or discriminatory, or promotes violence.
- Contains instructions intended to manipulate the Service's language-model processing to the detriment of RegSignal or other customers.
Using outputs responsibly
- Treat classifications, summaries, impact assessments, answers and translations as informational. Verify them against the official source before relying on them, and have qualified people make compliance decisions.
- Do not present Output as legal advice, or as an official publication or statement of a regulator.
- Do not use Output as the sole basis for decisions that have legal or similarly significant effects on individuals.
- Respect the terms of the official publishers whose content appears in the corpus.
- [Business decision to confirm: whether bulk redistribution or resale of the corpus or Output as a standalone dataset, or use of the Service to build a competing product, is prohibited.]
Law and sanctions
Use the Service only in compliance with applicable laws, including export control and sanctions laws. Do not use the Service on behalf of, or for the benefit of, persons subject to sanctions that apply to RegSignal. [Counsel to confirm the applicable sanctions and export regimes.]
Reporting a violation
Report suspected violations to [Legal contact email]. Report security vulnerabilities to the address in /.well-known/security.txt, as described on the Trust page.
Enforcement
If we reasonably believe this policy has been broken, we may warn the organization owner, remove content, revoke an API key, disable a webhook or connector, suspend a User or organization, or terminate under the Terms of Service. We act in proportion to the risk, and we give notice first where that is practical and lawful. Where suspension is needed to protect other customers or the Service, we may act first and explain afterwards.