Acceptable Use Policy
Last changed 20 August 2026
In brief
Use Telos Brain for your own business, on information you are entitled to use, without harming anyone and without trying to break, copy or extract the service. Use your own AI model accounts properly and within their providers' rules. If you breach this policy we can suspend or terminate your access — including entitlement for a self-hosted deployment, which will stop it running. If you see something wrong, tell us.
1. Application
1.1 This Policy applies to you and to every Permitted User, in both a Cloud Deployment and a Self-Hosted Deployment. You are responsible for their compliance under clause 5.4 of the Terms of Use.
1.2 Capitalised terms have the meaning given in the Terms of Use. This Policy is published by Telos Limited for the Telos Group and is incorporated into your Terms of Use with Telos NZ Limited. References to "we", "us" and "our" mean Telos NZ Limited as your contracting party.
1.3 This Policy is not exhaustive. Conduct that is not listed may still breach the Terms of Use.
1.4 Running a Brain in your own environment does not narrow this Policy. It applies to what you do with the Software wherever it runs.
2. Prohibited content
2.1 You must not upload to, input into, generate with, or store in the Service any material that:
- is unlawful, or that you do not have the right to hold, use or disclose to us;
- sexually exploits or abuses a child, or sexualises a minor in any way;
- facilitates or promotes terrorism, violent extremism, or violence against any person or group;
- infringes any person's Intellectual Property Rights, or breaches an obligation of confidence you owe to another person;
- contains malicious code, or is designed to interfere with any system;
- is defamatory, harassing, or intended to intimidate or threaten a person; or
- you are prohibited by law, by court order, or by a regulator from disclosing to us.
2.2 Some categories of information carry heightened legal obligations. You must not input into the Service health information, biometric information, information about criminal convictions, government identity document numbers, or information about children, unless you have confirmed that you have a lawful basis to do so and that your obligations for that category can be met given how the Service operates, including the processing described in the AI Terms and the fact that content is transmitted to a Model Provider you select.
2.3 Payment card data and protected health information. The Service is not certified to the Payment Card Industry Data Security Standard, and we do not act as a HIPAA business associate or enter into business associate agreements. You must not input payment card data or protected health information into a Cloud Deployment. If you process such data in a Self-Hosted Deployment, you do so entirely on your own responsibility and compliance is yours alone.
3. Prohibited conduct
3.1 You must not use the Service to:
- send unsolicited commercial electronic messages, or otherwise breach the Unsolicited Electronic Messages Act 2007 or equivalent law in any jurisdiction;
- impersonate any person, or misrepresent your affiliation with any person;
- surveil, track or profile any individual without a lawful basis;
- generate or distribute material intended to mislead about an election, a public health matter, or the identity or statements of a real person;
- make or automate a decision of a kind restricted by clause 4.2 of the AI Terms;
- facilitate gambling, weapons dealing, or trade in illegal goods or services; or
- breach any sanctions or export control law, or provide access to the Service to a person subject to sanctions.
3.2 Prohibited AI practices. You must not use the Service to:
- deploy subliminal, manipulative or deceptive techniques that materially distort a person's behaviour in a way likely to cause significant harm;
- exploit a vulnerability of a person or group arising from age, disability, or a specific social or economic situation, in a way likely to cause significant harm;
- evaluate or classify people over time based on their social behaviour or personal characteristics, in a way that leads to detrimental or disproportionate treatment (social scoring);
- assess or predict the risk that a person will commit a criminal offence based solely on profiling or on personality traits;
- create or expand facial recognition databases through the untargeted scraping of facial images;
- infer the emotions of a person in the workplace or in an educational setting, except for medical or safety reasons; or
- categorise people on the basis of biometric data to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.
Clause 3.2 reflects the practices prohibited by Article 5 of the EU Artificial Intelligence Act. It applies to all customers, whether or not that Act applies to you.
4. Platform integrity and security
4.1 You must not:
- reverse engineer, decompile, or attempt to derive the source code, architecture, system prompts or configuration of the Platform, except as permitted by clause 6.2(b) of the Terms of Use, by clause 11.6 of the Terms of Use in relation to Starter Templates, or by an open source licence;
- scrape, crawl, harvest or systematically extract the Platform or any part of the Service other than Your Content, including for the purpose of training, fine-tuning or evaluating any model;
- attempt to access another customer's account, Brain or content, or any part of our systems you are not authorised to access;
- probe, scan or test the security of the Cloud Service or the Control Plane, or attempt to defeat any authentication, authorisation, rate limiting or safety measure, except with our prior written consent under clause 14.4 of the Terms of Use;
- tamper with, disable, falsify, obstruct or circumvent any licensing, entitlement, telemetry or metering function of the Software or the Control Plane, or misreport usage;
- introduce any virus, worm, ransomware or other malicious code into the Service;
- use the Service to attack, overload or interfere with any third-party system; or
- remove, obscure or alter any proprietary notice.
4.2 Vulnerability reporting. If you discover a security vulnerability in the Service, report it to security@telosbrain.com. Do not exploit it, do not access data you are not authorised to access, and do not disclose it publicly until we have had a reasonable opportunity to remedy it. You may test a Self-Hosted Deployment running within your own environment, provided you do not test the Control Plane or any system we operate, and you report anything you find under this clause.
5. Fair use, limits and automation
5.1 We may apply rate limits, concurrency limits, storage limits, instance limits and usage limits to the Service, and may publish them in the Documentation. You must not circumvent them.
5.2 You must not use the Service in a way that places an unreasonable load on it, degrades it for other customers, or is designed to generate Usage Fees without a genuine business purpose. You must not create multiple accounts to obtain more than one Welcome Credit.
5.3 Automated and programmatic use of the Service through the Management API, the command line interface or a Model Context Protocol endpoint is permitted, subject to this Policy and to any limits we publish. You are responsible for the behaviour of any agent, script or workflow you configure, including the Usage Fees and the Model Provider Charges it generates. You should set spend limits with your Model Providers.
5.4 You must not resell, sublicense, distribute or provide the Service or the Software to a third party, operate it as a service bureau, or use it to provide a service to a third party that substantially replicates the Service, except as permitted by clause 4.1 and Schedule B of the Terms of Use.
5.5 You must not use the Service to develop or train a competing product, or publish a benchmark or comparative evaluation of the Service, without our prior written consent.
6. Model providers and credentials
6.1 You must only configure into a Brain Model Credentials for an account you are authorised to use. You must not use another person's or organisation's Model Provider account, or credentials obtained without authority.
6.2 You must comply with the terms of service and usage policies of each Model Provider you use. Those policies may prohibit things this Policy does not, and it is your responsibility to know them.
6.3 You must not use the Service to circumvent a restriction, rate limit, safety measure or content policy imposed by a Model Provider, or to obscure from a Model Provider the nature of the use being made of its models.
6.4 You must not configure a Brain in a way that is designed to generate Model Provider Charges for a person who has not authorised them.
7. Connected services
7.1 Where you connect the Service to a Third-Party Service, you must have the right and any necessary consents to do so, and must configure the connection so the Brain can access only what it needs.
7.2 You are responsible for content that enters the Service through a connected Third-Party Service as if you had uploaded it yourself, including for the prompt injection risk described in clause 7.3 of the AI Terms.
8. Enforcement
8.1 If we reasonably believe you have breached this Policy, we may take any of the following steps, proportionate to the breach:
- require you to remedy the breach within a stated period;
- restrict or remove access to particular features, or to particular content;
- suspend your access under clause 18 of the Terms of Use, including by suspending entitlement in the Control Plane;
- terminate the Terms of Use under clause 19.2; or
- report the matter to a regulator or law enforcement agency where we are required to, or where we reasonably believe there is a risk of serious harm.
8.2 Self-Hosted Deployments. Because a Self-Hosted Deployment depends on the Control Plane for entitlement, suspension or termination will stop it operating, even though the Software and Your Content remain in your environment. We cannot access, alter or delete Your Content in a Self-Hosted Deployment and will not attempt to.
8.3 Where practicable and lawful, we will notify you before acting and give you an opportunity to respond. We may act without prior notice where the breach is serious, where notice would prejudice an investigation, or where immediate action is needed to protect any person, the Service or another customer.
8.4 Suspension or termination under this Policy does not waive your liability for Usage Fees already incurred, and does not entitle you to any credit or refund.
8.5 To report a suspected breach of this Policy by any person, contact abuse@telosbrain.com.
9. Changes to this Policy
9.1 We may change this Policy in accordance with clause 2 of the Terms of Use. Superseded versions are archived at https://trust.telosready.com.