Polestead is a tool for managing risk responsibly. This policy sets out how it may and may not be used, so the platform stays lawful, safe, and trustworthy for everyone on it.
This Acceptable Use Policy ("AUP") applies to everyone who uses Polestead — the platform, CIIC, and the Trust Center — in any deployment model. It forms part of our Terms of Service. Where a self-hosted or air-gapped deployment places operational control in your hands, you remain responsible for using it in line with this policy.
You may use Polestead to onboard, classify, assess, monitor, and respond to risk from third parties with which your organization has a legitimate business relationship or a lawful basis to evaluate, and to publish your own security posture through the Trust Center.
You must not, and must not permit anyone to:
You are the controller of the personal data you bring into Polestead about your vendors and their staff. You must have a lawful basis for processing it, provide any notices your jurisdiction requires, and honour data-subject rights. Do not upload special-category data unless you have a specific lawful basis and it is necessary for the assessment.
Polestead does not scan third parties by default. External-scan signals are available only through the External Signals add-on, using an external attack-surface-management license that you bring and are authorized to use, and scoped to the vendors your classification warrants. You are responsible for holding the necessary authorization for any scanning; unauthorized scanning of systems you do not own or have permission to test is prohibited.
Do not attempt to probe, penetrate, or disrupt the hosted service, circumvent access controls or entitlements, or interfere with other tenants. Legitimate security testing of managed deployments requires prior written authorization — see our responsible-disclosure programme. For self-hosted deployments, you are responsible for securing your own environment.
Content you publish in a Trust Center must be accurate and not misleading. Do not misrepresent certifications you do not hold, or publish documents you are not permitted to share. Access controls and NDAs you configure must reflect genuine restrictions.
Where you enable AI features, inference runs on your own provider keys. You are responsible for complying with your AI provider's terms and for the lawful, appropriate use of AI-assisted output within your organization. AI-assisted classifications and drafts are decision support, not a substitute for human review.
Depending on the severity of a violation, we may require remediation, throttle or suspend the affected capability or account, or terminate the agreement under the Terms of Service. Where a violation affects safety or breaks the law, we may report it to the relevant authorities.
If you believe someone is misusing Polestead, or you have found a security issue, contact abuse@polestead.com or security@polestead.com. We investigate every report.
You may assess third parties you have a legitimate relationship with or a lawful basis to evaluate — not parties you have no relationship with or right to profile.
Only via the External Signals add-on, with a scanning license you bring and are authorized to use, scoped to vendors your classification warrants. Unauthorized scanning is prohibited.
We may require remediation, suspend the capability or account, or terminate the agreement. Serious violations affecting safety or law may be reported to authorities.
You are. Inference runs on your keys, so you're responsible for your provider's terms and the lawful use of AI-assisted output — which is decision support, not a substitute for review.