Legal

Acceptable use policy

Polestead is a tool for managing risk responsibly. This policy sets out how it may and may not be used, so the platform stays lawful, safe, and trustworthy for everyone on it.

Last updated: 20 July 2026 · Version 1.0

1 · Scope

This Acceptable Use Policy ("AUP") applies to everyone who uses Polestead — the platform, CIIC, and the Trust Center — in any deployment model. It forms part of our Terms of Service. Where a self-hosted or air-gapped deployment places operational control in your hands, you remain responsible for using it in line with this policy.

2 · Permitted use

You may use Polestead to onboard, classify, assess, monitor, and respond to risk from third parties with which your organization has a legitimate business relationship or a lawful basis to evaluate, and to publish your own security posture through the Trust Center.

3 · Prohibited use

You must not, and must not permit anyone to:

  • use the service to profile, rate, or assess parties you have no relationship with or lawful basis to evaluate;
  • upload content you have no right to process, or that infringes the rights of others;
  • misrepresent your identity, your authority, or the accuracy of information you publish in a Trust Center;
  • use the service to harass a vendor, or to coerce disclosure a vendor is not obliged to make;
  • resell, sublicense, or provide the service to third parties except as your agreement permits;
  • use the service in violation of export controls, sanctions, or applicable law.

4 · Lawful basis & data protection

You are the controller of the personal data you bring into Polestead about your vendors and their staff. You must have a lawful basis for processing it, provide any notices your jurisdiction requires, and honour data-subject rights. Do not upload special-category data unless you have a specific lawful basis and it is necessary for the assessment.

5 · External scanning

Polestead does not scan third parties by default. External-scan signals are available only through the External Signals add-on, using an external attack-surface-management license that you bring and are authorized to use, and scoped to the vendors your classification warrants. You are responsible for holding the necessary authorization for any scanning; unauthorized scanning of systems you do not own or have permission to test is prohibited.

6 · Platform integrity

Do not attempt to probe, penetrate, or disrupt the hosted service, circumvent access controls or entitlements, or interfere with other tenants. Legitimate security testing of managed deployments requires prior written authorization — see our responsible-disclosure programme. For self-hosted deployments, you are responsible for securing your own environment.

7 · Trust Center content

Content you publish in a Trust Center must be accurate and not misleading. Do not misrepresent certifications you do not hold, or publish documents you are not permitted to share. Access controls and NDAs you configure must reflect genuine restrictions.

8 · AI use

Where you enable AI features, inference runs on your own provider keys. You are responsible for complying with your AI provider's terms and for the lawful, appropriate use of AI-assisted output within your organization. AI-assisted classifications and drafts are decision support, not a substitute for human review.

9 · Enforcement

Depending on the severity of a violation, we may require remediation, throttle or suspend the affected capability or account, or terminate the agreement under the Terms of Service. Where a violation affects safety or breaks the law, we may report it to the relevant authorities.

10 · Reporting abuse

If you believe someone is misusing Polestead, or you have found a security issue, contact abuse@polestead.com or security@polestead.com. We investigate every report.

FAQ

Using it responsibly.

Can I assess any vendor I want?+

You may assess third parties you have a legitimate relationship with or a lawful basis to evaluate — not parties you have no relationship with or right to profile.

Does Polestead scan my vendors?+

Only via the External Signals add-on, with a scanning license you bring and are authorized to use, scoped to vendors your classification warrants. Unauthorized scanning is prohibited.

What happens if the policy is violated?+

We may require remediation, suspend the capability or account, or terminate the agreement. Serious violations affecting safety or law may be reported to authorities.

Who's responsible for AI use under BYOK?+

You are. Inference runs on your keys, so you're responsible for your provider's terms and the lawful use of AI-assisted output — which is decision support, not a substitute for review.