Acceptable Use Policy
Purpose
This Acceptable Use Policy (“AUP”) describes how customers, users, partners, and any other persons authorized to access the ORQET email security platform (the “Platform”) may and may not use the Platform. The AUP is incorporated by reference into the Master Services Agreement, Terms of Service, Proof of Concept Agreement, and any other agreement between you and Bayside Solutions, Inc. By accessing or using the Platform, you agree to comply with this AUP.
Capitalized terms not defined here have the meanings set forth in your applicable agreement with Bayside Solutions, Inc.
Who This AUP Applies To
This AUP applies to:
- Customers and their authorized Users.
- Partners, resellers, and managed service providers using the Platform on behalf of end-customers.
- Any other person or entity accessing the Platform, the threat intelligence engine, or any associated APIs, dashboards, or outputs.
General Restrictions
The following restrictions are provided by way of example and are not exhaustive. You shall not, and shall not permit any third party to:
- Use the Platform in violation of applicable law, including data protection, privacy, anti-spam, anti-fraud, and computer misuse laws.
- Use the Platform to infringe, misappropriate, or violate the intellectual property or privacy rights of any third party.
- Interfere with or disrupt the integrity, performance, or availability of the Platform, including by transmitting malware, executing denial-of-service attacks, or attempting to gain unauthorized access.
- Probe, scan, or test the vulnerability of any Bayside Solutions, Inc. system, or breach or circumvent any security or authentication measure, except as part of a coordinated security disclosure with Bayside Solutions, Inc.’s written authorization.
- Resell, sublicense, rent, lease, time-share, or otherwise make the Platform available to any third party except as expressly authorized in writing by Bayside Solutions, Inc.
ORQET-Specific Restrictions
The Platform includes capabilities that, if misused, can cause material harm to mailbox owners, third parties, or downstream systems. The following restrictions are specific to ORQET and apply in addition to the general restrictions above.
Search-and-Purge
You shall not use the Search-and-Purge functionality to access, modify, or delete email items in:
- Mailboxes you do not own or control.
- Mailboxes for which you do not have a valid legal basis and written authority to authorize search or deletion.
- Tenants or domains outside the scope identified in your Invoice or Proof of Concept Agreement.
Managed Service Providers and resellers must maintain documented written authorization from each end-customer before initiating any Search-and-Purge action affecting that end-customer’s mailboxes. You agree to make such documentation available to Bayside Solutions, Inc. upon reasonable request in connection with a compliance investigation.
Threat Intelligence
Threat intelligence outputs (“TI Output”) are licensed for your internal security use only. You shall not:
- Resell, redistribute, sublicense, or publish TI Output as a standalone product or service.
- Use TI Output to train, develop, or improve a competing threat intelligence product, detection model, or security analytics product.
- Use TI Output for any purpose other than the protection of your own (or your end-customer’s) information systems.
You may share specific TI Output indicators with information-sharing partners (such as ISACs or peer organizations) as reasonably necessary for active incident response, provided that you do not characterize such sharing as a commercial product or service.
Inline Detection and Model Outputs
You shall not use the Platform’s inline detection signals, classifications, model outputs, or scoring to train, develop, evaluate, or improve a competing detection model, machine learning system, or security analytics product. You shall not deliberately submit synthetic, adversarial, or poisoning inputs intended to degrade detection performance. You shall not misrepresent any Platform output, classification, score, or determination as having been independently reviewed, approved, or vetted by Bayside Solutions, Inc., or as constituting an original or wholly human-generated work.
Testing and Simulated Attacks
If you submit simulated phishing emails, attack samples, or red-team content to the Platform, you shall ensure that:
- Such submissions cannot cause harm to third parties or violate applicable law.
- Submissions are clearly tagged or scoped where the Platform provides a mechanism to do so.
- You have authority over the destination mailboxes and recipients involved in any simulation.
Reverse Engineering and Model Extraction
You shall not, and shall not permit any third party to:
- Reverse engineer, decompile, or disassemble the Platform, or attempt to derive its source code, model architecture, model parameters, or training data.
- Extract, copy, or systematically harvest the Platform’s detection rules, intelligence feeds, or analytics outputs for purposes outside your internal security use.
- Use the API at a volume, pattern, or in a manner designed to reconstruct or mirror threat intelligence, detection logic, or model behavior.
Content and Use Restrictions
You shall not use the Platform to generate, store, transmit, or process content that:
- Is illegal under applicable law.
- Constitutes child sexual abuse material or other material that exploits minors.
- Constitutes a credible threat of violence, terrorism, or harm to persons or property.
- Constitutes unsolicited bulk commercial email, spam, or fraudulent communications.
- Infringes the intellectual property, privacy, or other rights of third parties.
Account and Credential Security
You are responsible for safeguarding your account credentials, API keys, and any other access mechanisms. You shall:
- Enable multi-factor authentication where the Platform supports it.
- Promptly notify Bayside Solutions, Inc. of any suspected unauthorized access.
- Not share credentials with persons outside your organization, except as expressly permitted in your agreement.
AI and Automated Decision-Making
The Platform uses machine learning and automated decision-making to detect threats and orchestrate response actions. You acknowledge and agree:
You will maintain meaningful human oversight of automated remediation actions.
- You will not rely on Platform outputs as the sole basis for legal, employment, or other consequential decisions about individuals where applicable law requires human review.
- You will provide notice to your users and obtain any required consents under applicable privacy and AI regulation (including the EU AI Act, where applicable).
- You will not use the Platform’s automated decision-making, classifications, or outputs in a manner that is discriminatory, harassing, or otherwise harmful or unlawful toward any individual or group, including any use that results in unlawful disparate treatment of individuals on the basis of a protected characteristic.
Reporting Misuse
If you become aware of any violation of this AUP, or of any misuse of the Platform that may affect Bayside Solutions, Inc., its customers, or third parties, please report it to [email protected]. Bayside Solutions, Inc. investigates reports of abuse and may take action including warning, suspension, or termination.
Enforcement
Bayside Solutions, Inc. may investigate suspected violations of this AUP. Without limiting Bayside Solutions, Inc.’s rights under your agreement, Bayside Solutions, Inc. may, in its reasonable discretion:
- Issue a warning.
- Request that you cure the violation within a stated period.
- Suspend access to all or part of the Platform.
- Remove or quarantine offending content or configurations.
- Terminate the applicable agreement for material breach.
- Cooperate with law enforcement or regulators, including by disclosing information about the violation as legally permitted.
Where practical, Bayside Solutions, Inc. will provide notice and an opportunity to cure before suspension or termination, except where immediate action is necessary to protect the Platform, other customers, or third parties, or where required by law.
Changes to This AUP
Bayside Solutions, Inc. may update this AUP from time to time to reflect new features, threats, legal requirements, or operational practices. Material changes will be communicated through your standard notification channel. Continued use of the Platform after the effective date of an updated AUP constitutes acceptance of the update.
Contact Us
Questions about this AUP may be sent to [email protected]; report suspected misuse to [email protected].