Acceptable Use Policy
1. Prohibited content
You may not use Findrix to audit, deploy to, or track:
- Child sexual abuse material (CSAM) — we report it to NCMEC and equivalent authorities;
- Content that incites violence, terrorism, or genocide;
- Fraudulent commerce (counterfeit goods, fake services, phishing-as-a-service);
- Stolen credentials, malware, or exploit kits; or
- Doxxing or harassment targeting individuals or protected groups.
2. Prohibited data
Findrix is not designed to receive sensitive or highly regulated personal data. You must not submit through the Service, or direct it to collect:
- Health or medical information (including PHI);
- Payment-card data within PCI scope;
- Personal data of children below the applicable age (16 in the EEA/UK, 13 in the US);
- Financial data protected by GLBA;
- Government identifiers such as national-ID, passport, or social-security numbers; or
- Special-category data (for example, on health, ethnicity, or beliefs) or suspicious-activity reports.
We have no obligation to handle prohibited data and disclaim liability for it. If you need to process regulated data, contact us first at legal@findrix.ai.
3. Prohibited technical activity
You may not:
- Direct the Service to scan, probe, or audit sites you do not own or have written authorization to audit;
- Use the Service to attack third parties — denial of service, credential stuffing, or unauthorized vulnerability scanning;
- Scrape the Service or bypass its rate limits, quotas, or access controls, including through multiple accounts or IP rotation;
- Reverse-engineer, or otherwise reconstruct or derive, our source code, scoring, algorithms, or methodology — which are our trade secrets — beyond lawful observation of public-facing behavior; or
- Submit known-malicious URLs to consume our outbound IP reputation.
4. Competitive and commercial restrictions
You may not:
- Access or use the Service as, or on behalf of, a competitor of Findrix, except with our prior written consent;
- Use the Service, or its outputs, scores, reports, or methodology, to build, train, benchmark, or improve a competing product or service; or
- Publish or disclose benchmarks, comparisons, or performance evaluations of the Service without our prior written consent.
These mirror Section 8 and Section 2 of the Terms of Service; breach may be enforced by injunctive relief as described there.
5. Prohibited AI-citation tactics
Findrix exists to make legitimate brands findable. We will not deploy, and you may not use the Service to attempt:
- Prompt injection — hidden instructions, Unicode or escape-code tricks, or jailbreak payloads embedded in content;
- Cloaking — serving different content to AI crawlers than to humans;
- Mass-generated low-quality content produced solely to seed citations;
- Link farms — coordinated cross-site link injection aimed at AI crawlers; or
- Deceptive attribution — claiming credentials, certifications, or endorsements you do not hold.
6. Rate limits and fair use
We enforce per-account and per-IP rate limits to protect our infrastructure and the third-party systems we depend on. Limits are indicative, may vary by plan, and are subject to change; the current values apply and are shown in-product and in the API documentation.
| Action | Free plan | Paid plans |
|---|---|---|
| Audit submissions | A few per hour | Higher hourly allowance |
| API calls | Not available | Per-key rate limits (see API docs) |
| Deploy operations | Not available | Per-connection daily caps |
7. Activities we expressly permit
For clarity, the following are allowed and are not violations of this policy or the Terms:
- Good-faith security testing of your own account, in line with our coordinated vulnerability-disclosure process: report findings to security@findrix.ai and see our security.txt. Do not test other customers' data or our production infrastructure without prior written coordination; and
- Taking screenshots or recordings of your own use of the Service for your internal purposes.
Publishing benchmarks or comparisons of the Service, and using the Service to build a competing product, are not permitted — see Section 4.
8. Enforcement
We aim to enforce proportionally and with notice where practicable. If we believe you have violated this policy, we may:
- Warn you and pause the specific action, with a chance to cure a first, non-severe issue;
- Suspend or terminate the account for repeat or severe violations;
- Refuse refunds for the period in question; and
- Cooperate with law enforcement where legally required.
For genuine accidents — for example, an unintended scan of a domain you do not own — email abuse@findrix.ai and we will work it out.
9. Reporting abuse
If you believe Findrix is being used to abuse a site you operate, or you wish to report other misuse, email abuse@findrix.ai with the affected domain and any logs you have. We respond within 24 business hours and will block the offending account if the report is substantiated.
10. Changes
We may update this policy as new abuse patterns emerge. Material changes are posted here with at least 14 days' notice.
11. See also
- Terms of Service — your overall contract with Findrix;
- Privacy Policy — how we handle data; and
- security.txt — our security contact.
