Skip to content
CipherCruCipherCru

Menu

Acceptable Use Policy

This policy sets the standards of conduct that apply to anyone using CipherCru's systems, APIs and deliverables, and explains what happens when they are broken.

Last updated 1 September 2026

This Acceptable Use Policy is Version 1.0 and applies to all use of the systems, services and deliverables of CipherCru Innovations Private Limited.

Part I: Introduction

1. Purpose and scope

1.1 Purpose. This Acceptable Use Policy (this “AUP” or “Policy”) establishes the standards of conduct and use that apply when any individual or entity (“User”) accesses or uses:

  1. software applications, platforms, systems, modules, and APIs developed, delivered, hosted, or operated by CipherCru Innovations Private Limited (“CipherCru”);
  2. CipherCru's websites, client portals, and online tools;
  3. any services provided by CipherCru under a Master Services Agreement (“MSA”), Statement of Work (“SOW”), or other engagement agreement.

1.2 Who Is Bound. This AUP applies to all clients of CipherCru who access or use CipherCru's services, platforms, or deliverables; end-users who access client-operated systems built or managed by CipherCru, where the applicable SOW incorporates this AUP; employees, contractors, and agents of clients who use CipherCru-developed systems in the course of their duties; and any third party who accesses CipherCru's systems with or without authorisation.

1.3 Incorporation. This AUP is incorporated by reference into CipherCru's MSA and applicable SOWs. Use of CipherCru's services constitutes acceptance of this AUP. Where there is a conflict between this AUP and the MSA or an applicable SOW, the SOW prevails, followed by the MSA, followed by this AUP.

1.4 Review and Updates. CipherCru reserves the right to update this AUP at any time with appropriate notice to Users as set out in Section 18.

2. Core principles

2.1 CipherCru's services are provided to enable legitimate business activities. Users are expected to use CipherCru's services lawfully and in compliance with all applicable laws and regulations; in a manner that respects the rights, privacy, and safety of other individuals; in accordance with the documented specifications and intended use cases of the applicable system; and in a manner that does not harm CipherCru, its infrastructure, its other clients, or third parties.

2.2 The prohibitions in this AUP are not exhaustive. CipherCru reserves the right to determine, at its reasonable discretion, whether any use violates the spirit of this AUP even if not expressly prohibited.

Part II: Permitted uses

3. Permitted uses

3.1 Users may use CipherCru's services and deliverables for:

  1. Authorised business operations: activities within the scope of the client's authorised business operations as described in the applicable MSA and SOW;
  2. Permitted internal use: use by the client's employees, contractors, and agents for business purposes within the client's organisation;
  3. Authorised end-user access: providing authorised end-users (customers, partners, suppliers) with access to client-operated systems built by CipherCru, subject to appropriate end-user terms of service and privacy notices;
  4. Integration and API use: accessing CipherCru-developed APIs and integrations for the purposes and within the rate limits specified in the applicable SOW and API documentation;
  5. Testing and development: testing, debugging, and development activities on non-production environments designated for such purposes by CipherCru, provided that such testing complies with this AUP and uses only synthetic or appropriately anonymised data.

3.2 Permitted use is subject to the rate limits, data usage limits, and geographic restrictions specified in the applicable SOW or API documentation. CipherCru may impose technical throttling measures to enforce such limits.

Part III: Prohibited uses

4. Illegal and harmful activities

4.1 Users must not use CipherCru's services to:

  1. engage in any activity that is unlawful under the laws of India, the User's own jurisdiction, or any applicable international law, including the Indian Penal Code, the Information Technology Act 2000, the Information Technology (Amendment) Act 2008, the Prevention of Money Laundering Act 2002, the Foreign Exchange Management Act 1999, and the Digital Personal Data Protection Act 2023;
  2. engage in, facilitate, promote, or finance any form of terrorism, violent extremism, human trafficking, child exploitation, drug trafficking, arms dealing, or any other activity that is harmful to individuals or society;
  3. transmit, store, display, publish, or distribute any content that is obscene, pornographic, or sexually explicit, and particularly any content that sexually exploits or depicts minors (which is absolutely prohibited and will be reported to law enforcement); that constitutes hate speech, incites discrimination, or promotes violence against individuals or groups based on race, ethnicity, religion, gender, sexual orientation, disability, or other protected characteristics; that defames any individual or organisation; or that is false, misleading, or deliberately deceptive in a manner likely to cause harm;
  4. engage in any form of fraud, deception, impersonation, identity theft, or misrepresentation, including creating fake accounts, false identities, or fictitious entities;
  5. engage in gambling, betting, or games of chance in jurisdictions where such activities are unlawful;
  6. engage in any activity prohibited under the Foreign Contribution (Regulation) Act, SEBI regulations, RBI guidelines, or other sector-specific Indian regulations applicable to the Client's business.

5. Intellectual property violations

5.1 Users must not use CipherCru's services to:

  1. reproduce, distribute, publish, broadcast, or make available any content in which a third party holds Intellectual Property Rights, without the authorisation of the rights-holder or a valid licence or legal exception;
  2. remove, alter, obscure, or falsify any copyright notices, trade mark symbols, or other proprietary notices on content or materials;
  3. use CipherCru's deliverables, source code, frameworks, libraries, or tools in a manner that exceeds the scope of the licence granted under the applicable MSA or SOW, including attempting to use Internal Frameworks (as defined in the MSA) outside of the deliverable in which they are embedded; to reverse-engineer, decompile, or disassemble any software component; or to resell, sublicense, or otherwise commercialise CipherCru's proprietary tools and frameworks beyond the client's own business use;
  4. use CipherCru's AI Tools, models, prompts, or AI agent outputs to develop, train, or fine-tune competing AI systems or to extract the underlying logic of CipherCru's proprietary AI implementations;
  5. infringe any patent, design right, database right, trade secret, or other Intellectual Property Right of any third party.

6. Privacy and data violations

6.1 Users must not use CipherCru's services to:

  1. collect, process, store, or transmit Personal Data in violation of the Digital Personal Data Protection Act 2023, the IT (Amendment) Act 2008, the SPDI Rules 2011, the GDPR, the CCPA/CPRA, or any other applicable data protection legislation;
  2. collect Personal Data of individuals without providing appropriate notice and, where required, obtaining valid consent under applicable law;
  3. transfer Personal Data to countries or recipients not permitted under applicable data protection law without implementing appropriate transfer safeguards;
  4. collect, use, or disclose Sensitive Personal Data (including health data, financial data, biometric data, data about minors) in violation of applicable law or without the explicit consent of the data subject;
  5. build, maintain, or use databases of Personal Data for purposes not disclosed to data subjects in an applicable privacy notice;
  6. use CipherCru's systems to conduct surveillance, tracking, or monitoring of individuals without lawful authority or the individual's informed consent;
  7. scrape, harvest, or extract Personal Data from CipherCru's systems or any third-party systems in an unauthorised manner.

7. Security attacks and technical abuse

7.1 Users must not:

  1. Unauthorised access: access, or attempt to access, any system, account, network, or database without authorisation, or exceed authorised access permissions, whether belonging to CipherCru, other clients, or any third party;
  2. Malicious code: upload, transmit, install, or distribute malware, ransomware, spyware, adware, viruses, Trojan horses, worms, keyloggers, rootkits, or any other malicious or destructive code or software;
  3. Denial of service: conduct, facilitate, or participate in any Denial of Service (DoS), Distributed Denial of Service (DDoS), volumetric attack, or any other attack intended to disrupt, degrade, or overwhelm CipherCru's systems or any third-party systems;
  4. Vulnerability exploitation: exploit any security vulnerability, software bug, or system misconfiguration in CipherCru's systems or any third-party system accessed through CipherCru's services, except through CipherCru's responsible disclosure programme with prior written authorisation;
  5. Penetration testing: conduct security testing, penetration testing, vulnerability scanning, fuzzing, or similar testing on CipherCru's infrastructure or client systems managed by CipherCru without prior written authorisation from CipherCru;
  6. Credential abuse: share, transfer, or use login credentials, API keys, tokens, or authentication mechanisms in an unauthorised manner, including sharing production credentials with unauthorised individuals;
  7. Network interference: attempt to intercept, interfere with, or tamper with network communications, including packet sniffing, man-in-the-middle attacks, ARP poisoning, or DNS hijacking;
  8. Bypass of controls: attempt to circumvent, disable, or otherwise undermine any security feature, access control, authentication mechanism, monitoring system, or rate limiter implemented by CipherCru;
  9. Automated abuse: use bots, scrapers, crawlers, automated scripts, or other automated tools to access CipherCru's services in a manner that exceeds normal human interaction patterns, unless explicitly authorised in the applicable SOW as a legitimate use case, such as an API integration.

8. Spam, unsolicited communications, and platform abuse

8.1 Users must not use CipherCru's services or deliverables to:

  1. send spam, unsolicited bulk email, SMS, push notifications, or any other form of unsolicited commercial communication in violation of the Telecom Regulatory Authority of India (TRAI) regulations (including DND and TCCCPR 2018), the CAN-SPAM Act, the GDPR ePrivacy requirements, or any other applicable anti-spam law;
  2. operate, facilitate, or host an email or messaging relay for the purpose of sending unsolicited bulk communications;
  3. engage in email, SMS, phone, or online fraud, including phishing, vishing, smishing, spoofing, or pretexting, intended to deceive recipients into providing credentials, financial information, or Personal Data;
  4. artificially inflate usage metrics, app store ratings, website traffic, social media engagement, or advertising impressions through automated means such as click fraud, bot traffic, or rating manipulation;
  5. use CipherCru's systems to operate a proxy, VPN service, or anonymisation service that masks the origin of prohibited activities;
  6. engage in any activity that places an unreasonable or disproportionate load on CipherCru's infrastructure, including conducting load tests, stress tests, or simulated traffic surges without prior written authorisation.

9. AI and automated decision-making misuse

9.1 Where CipherCru's services incorporate AI-powered features, automated workflows, or machine learning components, Users must not:

  1. use AI features to generate, disseminate, or amplify misinformation, disinformation, or deepfakes, including fabricated news, synthetic media depicting real individuals without consent, or manipulated content designed to deceive;
  2. use AI features to harass, intimidate, stalk, or threaten any individual, including generating targeted abusive content;
  3. use AI-generated content in a manner that implies human authorship where AI generation must be disclosed under applicable law or professional rules; that violates the Intellectual Property Rights of third parties, for example by reproducing copyrighted text, images, or code without authorisation; or that violates data protection laws by generating content that reveals Personal Data of real individuals;
  4. attempt to manipulate, jailbreak, prompt-inject, or otherwise subvert the intended behaviour or safety guardrails of AI components embedded in CipherCru's systems;
  5. input into AI components any Personal Data, trade secrets, or confidential information of third parties beyond what is authorised and disclosed in the applicable privacy notice;
  6. use AI-assisted features for high-risk automated decision-making, including decisions that have legal effect or significantly affect individuals such as credit scoring, insurance underwriting, medical diagnosis, hiring decisions or law enforcement, without implementing appropriate human oversight, legal basis, and safeguards as required by applicable law;
  7. use AI-generated outputs as the sole basis for professional advice, whether legal, medical, financial or psychological, without appropriate human professional review and without disclosing to the recipient that AI was used in generating the advice.

10. Export control and sanctions violations

10.1 Users must not use CipherCru's services to:

  1. violate any applicable export control laws, trade embargo, or economic sanctions, including restrictions administered by the Government of India, the United States Bureau of Industry and Security (BIS), the Office of Foreign Assets Control (OFAC), the European Union, or the United Nations;
  2. provide, transfer, or make available any goods, services, technology, software, or data to any person, entity, or country subject to applicable sanctions or export restrictions without first obtaining all required governmental licences or authorisations;
  3. use CipherCru's systems to conduct business with entities on the SDN List (OFAC), the EU Consolidated Sanctions List, or equivalent restricted party lists.

11. Misuse of CipherCru's brand and identity

11.1 Users must not:

  1. represent, imply, or suggest that CipherCru endorses, approves, sponsors, or has any affiliation with any third-party product, service, organisation, or individual without CipherCru's prior written consent;
  2. use CipherCru's trade marks, trade names, logos, or branding in a manner not expressly permitted under the applicable MSA or SOW;
  3. use content generated by CipherCru's systems in marketing materials, publications, or public communications that attribute authorship to CipherCru without CipherCru's written consent;
  4. make false or misleading statements about CipherCru's services, capabilities, pricing, or performance.

Part IV: Specific platform obligations

12. API usage

12.1 Where Users access CipherCru-developed APIs, they must:

  1. use the API solely for the purposes and within the rate limits, data limits, and geographic restrictions specified in the applicable SOW or API documentation;
  2. keep API keys, tokens, and credentials confidential and not share them with unauthorised parties;
  3. immediately notify CipherCru of any suspected or actual compromise of API credentials;
  4. not attempt to reverse-engineer the API beyond what is documented or permitted;
  5. implement appropriate error handling and not rely on undocumented API behaviour;
  6. comply with all versioning requirements. CipherCru will provide appropriate deprecation notice before retiring API versions, and continued use of deprecated versions is at the User's own risk.

13. Data uploads and content

13.1 Where Users upload data, content, or files to CipherCru's systems, they must ensure they have all necessary rights, licences, and authorisations to upload and process the data within CipherCru's systems; not upload malicious files, executable payloads, or content that would violate this AUP; ensure that any Personal Data uploaded is processed in accordance with Applicable Data Protection Laws and the applicable DPA; and comply with any file size, format, or content restrictions specified by CipherCru.

13.2 CipherCru may implement automated scanning of uploaded content for malware, prohibited content, or file-type violations. CipherCru reserves the right to quarantine, delete, or reject content that violates this AUP.

14. Third-party integrations

14.1 Where CipherCru's systems integrate with third-party services, Users must comply with the terms of service of the applicable third-party providers; not use CipherCru's integrations as a means to circumvent the terms of a third-party provider; and ensure that any data shared with third-party services through CipherCru's integrations is done with appropriate legal basis and in compliance with applicable data protection laws.

Part V: Enforcement

15. Monitoring and investigation

15.1 Right to Monitor. CipherCru may monitor usage of its systems for the purpose of ensuring compliance with this AUP; detecting security incidents, unusual traffic patterns, and potential abuse; maintaining system performance and reliability; and complying with applicable law and responding to valid legal process.

15.2 Limitation. Monitoring is conducted in accordance with CipherCru's Privacy Policy and applicable data protection laws. CipherCru does not monitor the substantive content of private communications unless required by law, a valid court order, or to investigate a specific reported violation.

15.3 Investigation. Upon becoming aware of a potential AUP violation, CipherCru may investigate the matter, which may include reviewing system logs, access records, and usage data. CipherCru shall carry out investigations proportionately and in a manner that minimises disruption.

16. Enforcement actions

16.1 Where CipherCru reasonably determines that a User has violated this AUP, CipherCru may, depending on the severity and nature of the violation, take one or more of the following actions:

  1. Warning: issue a written warning to the Client requiring remediation within a specified timeframe;
  2. Content removal: remove, disable, or quarantine content or data that violates this AUP;
  3. Feature restriction: restrict access to specific features or capabilities pending investigation or remediation;
  4. Account suspension: temporarily suspend access to CipherCru's systems while an investigation is ongoing or pending remediation;
  5. Termination for cause: terminate the applicable MSA and/or SOW for material breach in accordance with the termination provisions of the MSA;
  6. Legal action: pursue civil or criminal legal remedies where appropriate, including seeking injunctive relief, damages, or referral to law enforcement.

16.2 Severity-Based Response. CipherCru will calibrate its enforcement response to the severity of the violation.

How CipherCru calibrates its enforcement response to the severity of a violation
SeverityExamplesLikely response
CriticalChild sexual abuse material; active security attack; terrorism-related use; large-scale fraudImmediate suspension; law enforcement referral; termination
HighData breach caused by AUP violation; large-scale spam; deliberate IP theftSuspension pending investigation; formal notice; potential termination
MediumRepeated rate limit abuse; unauthorised scraping; minor IP violationsWarning; feature restriction; remediation required
LowFirst-time minor violations; inadvertent technical policy breachWritten notice; education; opportunity to cure

16.3 Emergency Suspension. CipherCru may suspend access immediately without prior notice where necessary to prevent or contain an active security threat; to comply with a legal obligation or valid court order; or to protect CipherCru's infrastructure or other clients from imminent harm. CipherCru shall provide notice to the Client as soon as reasonably practicable after an emergency suspension.

16.4 Client Responsibility for End-Users. Clients are responsible for ensuring that their end-users comply with this AUP. A violation by an end-user of a client-operated system is treated as a violation by the Client for the purposes of this AUP.

17. Reporting violations

17.1 CipherCru encourages Users and third parties to report suspected AUP violations by contacting:

Where to report each kind of suspected violation
ChannelContact
General AUP violationsabuse@ciphercru.com
Security incidentssecurity@ciphercru.com
Privacy violations and data breachesprivacy@ciphercru.com
Child sexual abuse material and child safetysafety@ciphercru.com (reports also forwarded to NCMEC and applicable law enforcement)
Legal and court orderslegal@ciphercru.com

17.2 CipherCru aims to acknowledge reports within forty-eight (48) hours and to complete an initial assessment within five (5) Business Days.

17.3 Responsible Disclosure. Security researchers who discover vulnerabilities in CipherCru's systems should submit reports via security@ciphercru.com, following CipherCru's responsible disclosure guidelines. CipherCru does not take enforcement action against good-faith security researchers who comply with the responsible disclosure process.

18. Changes to this AUP

18.1 CipherCru may update this AUP from time to time to reflect changes in applicable law, technology, or business practice.

18.2 Notice. For material changes, CipherCru shall provide at least thirty (30) days' written notice to existing clients before the change takes effect; CipherCru shall post the updated AUP on its website and update the effective date at the top of this document; and continued use of CipherCru's services after the effective date of a change constitutes acceptance of the revised AUP.

18.3 For changes required by law or to address an imminent security threat, CipherCru may implement changes with less than thirty (30) days' notice, provided that CipherCru notifies clients as soon as practicable.

19. Relationship to other agreements

19.1 This AUP is supplementary to and does not replace or limit the terms of the MSA or any applicable SOW; the Privacy Policy and Cookie Policy of CipherCru; the DPA executed between the Parties; or any applicable laws and regulations.

19.2 In cases where this AUP imposes more stringent standards than the MSA in respect of a particular use, the more stringent standard applies.

20. No waiver

20.1 CipherCru's failure to enforce any provision of this AUP on any occasion does not constitute a waiver of its right to enforce that provision on any subsequent occasion or to enforce any other provision.

20.2 Tolerance of a violation does not constitute acceptance or approval of the violating conduct.

21. Indemnification

21.1 The Client shall indemnify, defend, and hold harmless CipherCru and its directors, officers, employees, contractors, and agents from and against all claims, liabilities, losses, damages, costs, and expenses (including reasonable legal fees) arising out of or in connection with the Client's or its end-users' violation of this AUP; any claim by a third party arising from the Client's or its end-users' use of CipherCru's services in breach of this AUP; and any regulatory fine, penalty, or enforcement action arising from the Client's or its end-users' misuse of CipherCru's services.

22. Governing law

22.1 This AUP is governed by and shall be construed in accordance with the laws of the Republic of India, including the Information Technology Act 2000 and the Digital Personal Data Protection Act 2023.

22.2 Any disputes arising under or in connection with this AUP shall be subject to the dispute resolution provisions of the applicable MSA. The courts at Jaipur, Rajasthan, India shall have exclusive jurisdiction over matters not resolved through the dispute resolution process.

23. Contact details

For queries about this Acceptable Use Policy, contact:

Entity
CipherCru Innovations Private Limited
Registered office
602, The Elysian, A-31, Swej Farm Circle, Swej Farm, New Sanganer Road, Sodala, Jaipur, Rajasthan 302019, India
Email
legal@ciphercru.com
Website
https://www.ciphercru.com

Schedule A: Summary of prohibited uses

The prohibitions of Part III in summary. The full text of each section governs.
CategoryProhibited activities
Illegal activitiesCrime facilitation, terrorism, human trafficking, child sexual abuse material, drug trafficking, fraud
IP violationsUnauthorised reproduction, reverse engineering, unlicensed use of frameworks
Privacy violationsUnauthorised data collection, illegal transfers, surveillance without consent
Security attacksHacking, malware, DoS and DDoS, credential abuse, bypassing security controls
Spam and abuseBulk unsolicited communications, phishing, click fraud, platform manipulation
AI misuseDeepfakes, misinformation, jailbreaking, prohibited automated decisions
Export violationsTransactions with sanctioned parties, export without authorisation
Brand misuseFalse CipherCru endorsement, unauthorised trade mark use

Schedule B: Applicable laws reference

Indicative reference of the principal laws bearing on this policy, by jurisdiction
JurisdictionKey applicable laws
IndiaInformation Technology Act 2000 and Amendment 2008; DPDP Act 2023; SPDI Rules 2011; Indian Penal Code; PMLA 2002; TRAI TCCCPR 2018; FEMA 1999
European Union and United KingdomGDPR (EU) 2016/679; UK GDPR; ePrivacy Directive 2002/58/EC; NIS2 Directive
United StatesCCPA/CPRA; CAN-SPAM Act; CFAA; COPPA (for child-directed services); OFAC sanctions
InternationalUN Security Council Sanctions; Wassenaar Arrangement (export controls)

This table is indicative only. Users must ensure compliance with all laws applicable in their own jurisdiction.

Strictly necessaryEssential for the site to function: page navigation, security, session management, and remembering the cookie choices you make here.
Always on
FunctionalRemembers choices you make, such as language, region or display preferences, so the site opens the way you left it.
Performance and analyticsPerformance and analytics cookies show us how the Website is used: which pages are visited, how long is spent on them, where visitors came from, and what errors occur. They are set by Google Analytics and by HubSpot, whose cookies also link the pages you viewed to any enquiry you later send us.
Marketing and targetingTracks browsing activity to measure advertising and show relevant ads. We set none of these today, and will not without your opt-in.