1. Apply the strictest relevant rule
Customer must use AI Gateway HQ in accordance with law, the Terms of Service, this policy, and the applicable model provider's use policy. If rules differ, follow the strictest rule that applies to the request. Customer is responsible for configuring policies, roles, provider eligibility, and human review suitable for its users and use cases.
2. Do not attack systems or identities
- Do not gain or attempt to gain unauthorized access to another account, tenant, provider credential, model, system, network, or data source.
- Do not discover, harvest, purchase, sell, expose, or misuse passwords, API keys, tokens, session cookies, personal authentication factors, or payment credentials.
- Do not upload malware, create a botnet, operate phishing or credential-theft infrastructure, or use model output to automate compromise or persistence without explicit defensive authorization.
- Do not probe production tenant boundaries, evade authorization, disable logging, bypass a budget or policy, or conceal the origin of prohibited traffic.
- Security research must be scoped, authorized, rate-limited, non-destructive, and reported through the Contact and Security Disclosure page. Never access another customer's data.
3. Do not harm shared availability
- Do not intentionally overload the gateway, control plane, support channel, provider connection, or another customer's resources.
- Do not evade quotas, request limits, concurrency limits, billing controls, geographic restrictions, or abuse-prevention measures by rotating identities, workspaces, keys, or payment methods.
- Do not benchmark, scan, scrape, or generate load against production without written authorization and an agreed test window.
- Do not resell, sublicense, or pool service access outside the licensed organization unless an Order expressly permits it.
4. Do not facilitate illegal or abusive conduct
- Do not use the Services to violate law, sanctions, export restrictions, intellectual-property rights, privacy rights, or contractual confidentiality.
- Do not generate or distribute child sexual abuse material, non-consensual intimate imagery, credible threats, targeted harassment, or material intended to facilitate human trafficking or exploitation.
- Do not impersonate a person or organization deceptively, commit fraud, manipulate a financial market, distribute spam, or misrepresent automated content as an official human decision where disclosure is required.
- Do not use model traffic to develop, acquire, or deploy biological, chemical, nuclear, or radiological weapons or to cause unlawful physical harm.
5. Protect data and high-impact decisions
Only submit data Customer has the right and lawful basis to process. Minimize personal and confidential data and configure the selected provider and region appropriately. Do not submit specially regulated data unless an executed Order and the active technical controls expressly permit it.
Do not use the Services as the sole basis for decisions that determine a person's access to employment, housing, credit, insurance, education, healthcare, legal services, or essential government benefits without qualified human oversight, validation, notice, and appeal safeguards required by law. Model output is not a substitute for professional judgment.
6. Keep humans and applications accountable
- Test model behavior and failure modes before production rollout and monitor material changes in models, prompts, tools, and routes.
- Use least privilege for users, service accounts, tools, data connectors, and virtual keys.
- Make automated actions reversible when practical and require approval for high-impact, destructive, financial, or externally published actions.
- Do not remove provenance, safety notices, or required disclosures from model-generated content.
- Prompt-injection and jailbreak defenses reduce risk but do not guarantee safe output; applications must enforce their own authorization and output-handling boundaries.
7. Enforcement
AI Gateway HQ may block a request, revoke a key, rate-limit traffic, preserve relevant evidence, or suspend the affected account when reasonably necessary to investigate or stop a violation. We consider severity, intent, repetition, harm, legal obligations, and the customer's response. When safe and practical, we provide a reason and a remediation path.
A Customer that believes traffic was blocked in error should contact support with the request identifier and decision reason, not the secret key or sensitive prompt body. Imminent threats or unlawful content may be reported to appropriate authorities when required or permitted by law.
Questions, requests, or notices
Use the encrypted contact workflow for account, billing, privacy, cancellation, or legal requests. Do not submit passwords, card data, provider credentials, gateway keys, or sensitive prompt content.