Acceptable Use Policy
Last updated: 27 April 2026
1. Purpose
This Acceptable Use Policy (AUP) sets out behaviour we expect from all FORTE/CYBERx users. It supplements our Terms of Service. Breach of this AUP is grounds for suspension, termination, or referral to law enforcement.
2. Prohibited uses
You must not use the Service to:
- Conduct illegal activity or facilitate it for others.
- Develop, host, or distribute malicious code, malware, or exploits targeting third parties.
- Scrape, mirror, or systematically extract Service content or AI Outputs across multiple accounts to build a derivative product.
- Reverse-engineer, decompile, or attempt to extract advisor instructions or training data.
- Abuse mission credits via automation, scripted submissions, shared accounts, or secondary accounts created for the purpose of generating referral credits to your primary account (self-referral).
- Attempt to bypass authentication, MFA, rate limits, row-level security, or any other access control.
- Test the Service for vulnerabilities without prior written authorisation (see Security for our responsible-disclosure programme).
- Represent any Output as professional, legal, financial, or regulatory advice to a third party without clearly disclosing it was generated by an AI decision-support tool.
3. AI-specific misuse
Because FORTE/CYBERx is an AI system providing decision support, the following AI-specific behaviours are also prohibited:
- Prompt injection or jailbreak attempts against any advisor, the Architect chat, the Board of Directors panel, or any other AI surface.
- Model exfiltration — repeated probing intended to extract advisor system prompts, board-member personas, orchestration logic, or any other proprietary instruction set.
- Adversarial use against named third parties — you may not submit a mission whose stated objective is to harm, surveil, deceive, defraud, defame, or undermine an identified person, organisation, or government, or to develop offensive cyber capability against any specific target.
- Use in regulated decisions — you may not use Outputs as the sole or determinative basis for clinical, diagnostic, legal-advice-to-clients, financial-product advice, credit, insurance, criminal-justice, immigration, or employment hiring, performance, or termination decisions, in each case without independent sign-off by a person appropriately licensed and accountable under the relevant Australian law (see Terms §4.2).
- Misrepresenting Outputs — you may not present Outputs as the work of a human professional, or remove the AI-origin disclosure from any exported PDF or shared tactical plan.
4. Content rules
- Do not submit personally identifying information of third parties without lawful basis.
- Do not submit live incident-response data containing un-redacted IOCs that could compromise an active investigation.
- Do not submit cardholder data (CHD), full PHI, or government-classified material.
- Do not submit content that is unlawful, harassing, defamatory, hateful, or designed to promote violence or self-harm.
- Do not submit data subject to export-control or sanctions regimes.
5. Enforcement
Breaches are handled via a graduated ladder:
- Warning with explanation and remediation request.
- Suspension of the offending account, with credit forfeiture for any promotional credits implicated in the breach.
- Termination and, where appropriate, referral to law enforcement and relevant regulators.
For severe or repeated breaches we may skip directly to termination.
6. Reporting abuse
Report suspected abuse, account compromise, or AUP violations to info@fortecyberx.au or via /support.