Legal
Acceptable use policy
Last updated: 2026-09-01. Short version: don't weaponise the sandbox, don't ingest people's data without rights, and don't push anything a judge would frown at.
1. Prohibited uses
You may not use the Service to: store, process or distribute unlawful content; run or distribute malware, cryptominers, DDoS tooling or credential attacks; probe, escape or circumvent tenancy, the sandbox, rate limits or the permission engine; send unsolicited bulk communications; or impersonate persons or organisations.
2. Data & rights
You must have all rights and consents needed to upload and process personal data on the Service. You may not ingest personal data in ways a controller could not lawfully instruct (no scraped databases, no credentialed-exfiltrated data). Indexed or scraped content must respect robots.txt and the source's terms.
3. Compute & the sandbox
Metered compute is for legitimate platform work. You may not run mining workloads, distributed load without our agreement, or attempt to exceed per-execution resource caps. Intentional sandbox escapes are a critical vulnerability report, not a sport.
4. Enforcement
We may suspend or terminate a workspace that breaches this policy, after notice where legally possible. Repeated or severe violations result in termination and, where warranted, referral to authorities. The audit log is our evidence base.
5. Reporting
Suspected breaches affecting another tenant: abuse@cidbee.example. We triage every report within two working days.