Acceptable Use Policy

Acceptable Use Policy

Last updated: April 6, 2026

This Acceptable Use Policy ("AUP") is incorporated into our Terms of Service and applies to all use of the Veto platform and Services operated by Plaw, Inc. ("Plaw," "we"). Violation of this AUP may result in suspension or termination of your account.

1. Prohibited Uses

You may not use the Services to:

Illegal Activity

  • Violate any applicable law, regulation, or sanctions regime
  • Facilitate money laundering, terrorist financing, or financial fraud
  • Process data in violation of data protection or privacy laws
  • Infringe intellectual property rights of any third party

Security Violations

  • Probe, scan, or test the vulnerability of the Services without authorization
  • Bypass, circumvent, or disable any security or authentication controls
  • Distribute malware, ransomware, viruses, or other malicious code
  • Conduct phishing, social engineering, or credential harvesting
  • Attempt to gain unauthorized access to other customers' accounts, data, or resources
  • Intercept, monitor, or tamper with network traffic not intended for you

Abuse and Interference

  • Overload, disrupt, or degrade the Services or their infrastructure (including DDoS)
  • Interfere with another customer's use of the Services
  • Generate excessive API traffic designed to circumvent rate limits or quotas
  • Use the Services to conduct unauthorized surveillance or data collection
  • Scrape, crawl, or index the Services beyond what is necessary for authorized use

Harmful Content

  • Submit content that exploits or harms children
  • Distribute content that promotes violence, hatred, or discrimination
  • Use the platform for harassment, threats, or intimidation
  • Submit content designed to generate harmful, deceptive, or misleading AI outputs

Competitive Misuse

  • Reverse engineer, decompile, or disassemble the Services (except as permitted by law)
  • Benchmark the Services for competitive analysis without prior written consent
  • Resell, sublicense, or redistribute access without authorization
  • Build a competing product using knowledge gained from the Services

2. API and Integration Requirements

  • Respect API rate limits and implement appropriate retry logic with exponential backoff.
  • Protect API keys and credentials. Do not embed them in client-side code, public repositories, or shared environments.
  • Ensure that outbound integrations (webhooks, MCP upstreams) send data only to endpoints you control or have authorization to use.
  • Identify your integration with a descriptive User-Agent header when making API calls.

3. Responsible AI Use

If you use Veto's AI-assisted features (LLM-based policy evaluation, policy generation):

  • Maintain meaningful human oversight of AI-assisted authorization decisions in production.
  • Do not rely solely on AI-generated outputs for decisions that have legal, financial, or safety consequences without human review.
  • Comply with applicable AI regulations (including the EU AI Act) in your jurisdiction and use case.
  • Do not use AI-assisted features to generate content that is deceptive, discriminatory, or harmful.

4. Reporting Violations

If you become aware of any violation of this AUP, report it to team@plaw.io. We investigate all reports and take appropriate action.

5. Enforcement

We may investigate suspected AUP violations and take action including:

  • Warning the account holder
  • Throttling or suspending API access
  • Suspending or terminating the account
  • Reporting the activity to law enforcement where appropriate

Where practicable, we will provide notice and an opportunity to cure before taking enforcement action, except in cases of imminent harm, security threats, or legal requirements.

6. Changes

We may update this AUP. Material changes are communicated via the Services or the email on your account at least 30 days in advance.