This document was approved for publication following qualified Irish/EU and Brazilian legal review. Customer-specific Order Forms and negotiated agreements control where expressly stated.
This Acceptable Use Policy applies to every Customer, administrator, user, integration, and system that accesses kubbeevault. The Customer must ensure that its users and systems comply with it.
1. Lawful and authorised use
- Use the Services only for lawful internal business purposes and within the rights, limits, and documentation provided by kubbeevault.
- Store or process data only when the Customer has a lawful basis and all necessary rights, notices, permissions, and approvals.
- Access only organisations, workspaces, vaults, secrets, systems, integrations, and data that the user is authorised to access.
- Comply with export controls, sanctions, anti-corruption rules, privacy laws, employment rules, and sector requirements that apply to the Customer’s use.
2. Prohibited security activity
- Do not gain or attempt to gain unauthorised access, bypass authentication or access controls, escalate privileges, or obtain another tenant’s data.
- Do not probe, scan, exploit, or test kubbeevault or another customer’s systems except as expressly authorised by the Vulnerability Disclosure Policy or a written testing agreement.
- Do not introduce malware, ransomware, destructive code, credential-stealing software, hidden access, or content designed to disrupt, damage, or monitor without authorisation.
- Do not interfere with availability, overload the Services, evade rate limits, perform denial-of-service activity, or coordinate abusive automation.
- Do not share accounts or authentication factors, publish access tokens, or defeat audit, logging, metering, or security mechanisms.
3. Prohibited content and conduct
- Do not use the Services for fraud, phishing, impersonation, harassment, unlawful surveillance, exploitation, trafficking, or other unlawful conduct.
- Do not store or transmit content that infringes intellectual-property, privacy, confidentiality, publicity, or contractual rights.
- Do not use kubbeevault to operate a credential marketplace, distribute stolen credentials, facilitate unauthorised access, or conceal the origin of malicious activity.
- Do not use the Services in a way that creates a material risk to people, property, critical systems, kubbeevault, its providers, or other customers.
4. Restricted and high-risk data
The Services are designed for business credentials and secrets, which are inherently sensitive. That does not mean every regulated data type or workload is approved. Unless an Order Form expressly authorises it, the Customer must not use the Services as the primary repository for payment-card data, protected health records, biometric templates, criminal-offence records, government-classified information, or data whose storage would require a certification, residency, or control that kubbeevault has not confirmed in writing.
A Customer operating essential, safety-critical, or regulated infrastructure must complete its own risk assessment and obtain written confirmation of required deployment, availability, support, recovery, and compliance terms.
5. Technical and commercial limits
- Do not exceed user, secret, storage, request, integration, or other purchased limits or circumvent enforcement of those limits.
- Do not scrape, mirror, frame, resell, sublicense, or provide the Services as a service bureau unless an Order Form expressly permits it.
- Do not reverse engineer or use non-public interfaces except where applicable law gives a non-waivable right.
- Do not use kubbeevault confidential information or non-public performance data to create a competing product.
6. Investigation and enforcement
kubbeevault may investigate credible suspected violations and may require reasonable cooperation, logs, configuration changes, credential rotation, or removal of prohibited content. kubbeevault may rate-limit, quarantine, or suspend affected access where reasonably necessary to prevent harm, comply with law, protect other customers, or stop an ongoing violation.
Where safe and lawful, kubbeevault will notify the Customer and allow a reasonable cure. Serious, repeated, illegal, or security-critical violations may result in immediate suspension or termination. kubbeevault may preserve and disclose information when required by law or reasonably necessary to protect rights and safety, consistent with the Privacy Notice and Data Processing Agreement.
7. Reporting concerns
Report suspected abuse to the approved support or legal channel in the Order Form. Security vulnerabilities should be reported under the Vulnerability Disclosure Policy to [email protected]. Do not send passwords, private keys, tokens, or unnecessary personal data in an initial report.