01AI agent tooling
The AI agents run against an explicit, audited allowlist of tools. Do not attempt to bypass that allowlist, smuggle additional capabilities into an agent, or coax an agent into actions it is not authorized to take.
Do not use URL-fetching or other network tools to reach internal services, private network ranges, or cloud metadata endpoints, or to make the platform send requests on your behalf to systems you should not reach.
Do not use agents to exfiltrate data, to cross from your tenant into another, or to extract system prompts, credentials, or configuration that is not yours.
02Tenant boundaries
Operate only within your own tenant workspace. Do not try to access, list, or detect the existence of another tenant's data, accounts, or content.
Do not probe other tenants or the platform itself for vulnerabilities without prior written authorization. Authorized security testing is welcome. Coordinate it with us first via security@spaltx.com.
03Content you upload
Do not upload content you lack the legal rights to process, including third-party data you are not authorized to share with us.
Do not upload malware, exploit payloads, or material designed to compromise the platform, other users, or downstream systems.
Do not use the platform to store or transmit unlawful content, or content that infringes the rights of others.
04Abuse & rate limits
Do not attempt to overwhelm the platform, evade rate limits, or automate abusive volumes of requests against the API, the agents, or the extraction pipeline.
Do not interfere with the integrity or performance of the service, including by scraping at scale or running denial-of-service patterns.
05Consequences
Violations may result in throttling, suspension, or revocation of access, with or without notice depending on the severity and the risk to other tenants.
Where activity appears unlawful, we may preserve relevant records and cooperate with appropriate authorities.
06Reporting abuse
If you discover abuse, a vulnerability, or behavior that violates this policy, report it to security@spaltx.com. We treat good-faith security reports seriously and will work with you in good faith.
