01Scope and incorporation
This Acceptable Use Policy (“AUP”) forms part of the Terms of Service between you and Nead, LLC (d/b/a DEV.co). Capitalised terms not defined here have the meaning given in the Terms.
It applies to you, to your Users, and to anyone accessing the Services through your account, including API credentials, automated Agents, and portal users. You are responsible for their compliance.
02Prohibited activity
2.1 Legal compliance
You must not use the Services:
- in violation of applicable law, including securities, financial reporting, tax, sanctions, export control, anti-money-laundering, or consumer protection law;
- to record transactions you know to be fictitious, or to conceal, misstate, or falsify financial records;
- to facilitate money laundering, terrorist financing, sanctions evasion, or tax evasion;
- to process data you have no lawful basis or right to process; or
- to infringe the intellectual property, privacy, or other rights of any person.
On the second point. This is accounting software with an append-only ledger and a full audit trail. The system is built so that falsification is difficult and detectable, and we will not modify that behaviour on request. If a prospective customer asks whether entries can be edited without trace, the answer is no and the question is noted.
2.2 Security
You must not:
- attempt to gain unauthorised access to the Services, other customers’ environments, or our infrastructure;
- circumvent or attempt to circumvent authentication, authorisation, rate limiting, tenant isolation, or the policy engine;
- probe, scan, or test the vulnerability of the Services except under Section 5;
- introduce malicious code, or upload content containing it;
- use credentials you are not authorised to use, or share credentials between individuals; or
- operate an API credential or Agent under an individual’s identity, which defeats the audit trail.
2.3 Integrity of the Services
You must not:
- impose an unreasonable or disproportionate load, or interfere with Service integrity or performance;
- use automated means to access the Services other than through the documented API, MCP server, or webhooks;
- exceed documented rate limits, or engineer around them by distributing requests across credentials;
- reverse engineer, decompile, or disassemble the Services, except to the extent that restriction is unenforceable under applicable law; or
- remove, obscure, or alter proprietary notices.
2.4 Commercial restrictions
You must not:
- resell, sublicense, timeshare, or provide the Services on a service-bureau basis without our written consent;
- use the Services to develop a competing product or service;
- publish benchmark or performance results without our prior written consent, which we will not unreasonably withhold provided the methodology is disclosed; or
- access the Services for the purpose of competitive analysis while representing yourself as a prospective customer.
2.5 Content and data restrictions
Unless expressly agreed in writing, you must not submit to the Services protected health information subject to HIPAA, cardholder data subject to PCI-DSS, biometric identifiers, government identification numbers other than tax identifiers required for statutory reporting, classified information, or data subject to ITAR or EAR controlled-technology restrictions.
The Services are not designed for those categories. This restriction protects you as much as us: submitting regulated data to a system not built for it creates a compliance exposure that is difficult to unwind.
03Automated Agent use
Specific to the automation capabilities of the Services, you must not:
- attempt to configure an Agent to release payment, create a vendor or change vendor banking details, grant or modify permissions, close or reopen an accounting period, or make a statutory filing;
- attempt to circumvent the authority model, confidence thresholds, or escalation routing;
- use the Services to make automated decisions producing legal or similarly significant effects concerning individuals, including credit, employment, housing, insurance, or benefits decisions;
- deliberately submit content designed to manipulate an Agent into acting outside its granted authority, including prompt injection against your own tenant; or
- represent Agent Output as reviewed by a qualified professional where it has not been.
The prohibited capabilities in the first item are not configurable by us either. An instruction asking us to enable them is void under the Terms, and we will decline it at any price.
3.1 Your review obligation
You must review and accept Output before relying on it for financial reporting, filing, or any decision with external consequence. Granting an Agent authority does not transfer to us responsibility for the accuracy of your financial records.
04How we enforce this policy
Our response is proportionate to the risk. We do not treat every breach as grounds for termination, and we do not use this policy as a pretext.
| Situation | Our response |
|---|---|
| Inadvertent breach with no ongoing risk — for example exceeding a rate limit | We contact you and work out a fix. No suspension, no penalty. |
| Breach creating risk to your own data | We notify you, explain the exposure, and give you a reasonable period to remediate. |
| Breach creating risk to other customers or to the Services | We may suspend the specific capability at issue, narrowly, with prompt notice. |
| Imminent and serious risk | We may suspend access without prior notice, limited to what is necessary, with notice as soon as practicable. |
| Unlawful activity or a breach not capable of cure | We may terminate immediately under the Terms. |
4.1 Commitments when we act
- We will tell you what we did, why, and what would resolve it.
- Suspension will be as narrow as the risk permits — a capability rather than an account where that is sufficient.
- We will not suspend your ability to export your data under this policy, except where the export itself is the vector of harm.
- We will restore access as soon as the risk is resolved.
- You may escalate any enforcement decision to [email protected] and a different person will review it.
4.2 Reporting a breach
To report suspected misuse by another party, write to [email protected]with “AUP” in the subject line.
05Security research
Section 2.2 prohibits probing and scanning. This section is the exception, and it is deliberately broad because a vendor that threatens researchers gets told about vulnerabilities last.
5.1 What we permit
Good-faith security research conducted in accordance with responsible disclosure, provided you:
- test only against your own tenant or an environment we designate;
- do not access, modify, or exfiltrate data belonging to any other customer;
- do not degrade the Services for others — no denial of service, no volumetric testing, no automated scanning that generates disproportionate load;
- do not use social engineering against our personnel or customers, or attempt physical access;
- stop as soon as you have confirmed a vulnerability, and do not pivot further into systems; and
- report to [email protected] with “Security” in the subject line and give us a reasonable period to remediate before public disclosure.
5.2 Our commitment to researchers
- We will not pursue legal action, or support action by others, against research conducted within these bounds. This includes claims under the Computer Fraud and Abuse Act and anti-circumvention claims under the DMCA.
- We will acknowledge your report within one business day.
- We will keep you informed of remediation progress and tell you when it is fixed.
- We will credit you publicly if you want that, and respect a request for anonymity if you do not.
- We will not require you to sign an NDA as a condition of reporting.
We do not currently operate a paid bug bounty. We will say so plainly rather than implying a reward that does not exist.
06Changes to this policy
We may update this AUP. For changes that materially restrict permitted use, we will give at least 30 days’ notice before they take effect. Clarifications and changes that broaden permitted use take effect on posting.
Where a restriction is materially adverse to your existing use and we cannot agree an accommodation, you may terminate the affected Services before it takes effect and receive a pro-rata refund of prepaid unused fees.
Changes are logged in the changelog. Prior versions on request.
Questions, reports, and appeals
General questions and AUP reports: [email protected]. Security reports: same address with “Security” in the subject line — acknowledged within one business day, and we will not pursue good-faith research.
To appeal an enforcement decision, write with “AUP appeal” in the subject line and a different person will review it.
Related: Terms of Service · Privacy Policy · Security · Service Level Agreement