This policy is incorporated into the Legasus Master Subscription Agreement.
This General Acceptable Use Policy (“AUP”) applies to use of the Services provided by AIDAN LLC d/b/a Legasus. Capitalized terms not defined here have the meanings in the Master Subscription Agreement.
Customer is responsible for ensuring that Authorized Users, Administrators, Client Users, and persons using Customer-issued credentials comply with this AUP.
1. Lawful Use
You may use the Services only for lawful business and professional purposes authorized by the Terms.
You will not use the Services to violate or facilitate violation of applicable law, regulation, court order, sanctions, export restrictions, contractual restrictions binding on you, or legally enforceable third-party rights.
2. Security and Access Restrictions
You will not:
- access an account, tenant, matter, file, API, system, or resource without authorization;
- share individual credentials in violation of the Terms;
- circumvent MFA, permissions, rate limits, usage limits, authentication, security controls, or feature restrictions;
- scan, probe, exploit, attack, or test systems except as allowed by the Responsible Disclosure Policy;
- introduce malware, ransomware, worms, destructive code, credential-stealing code, or other malicious payloads;
- interfere with availability, performance, or integrity of the Services;
- conduct denial-of-service activity;
- attempt to access another Customer's data;
- obtain or attempt to obtain secrets, keys, tokens, system credentials, or nonpublic infrastructure information; or
- use compromised credentials or knowingly permit unauthorized access.
3. Abuse and Excessive Use
You will not use the Services in a manner that unreasonably degrades performance for others or imposes excessive load outside authorized usage levels.
Legasus may apply reasonable rate limits, concurrency limits, storage limits, AI usage limits, API quotas, or other technical controls and may restrict usage that materially threatens service stability or security.
4. Spam and Unsolicited Communications
You will not use the Services to send unlawful spam, bulk communications, robocalls, or messages that violate applicable marketing, telemarketing, privacy, or communications laws.
Customer is responsible for obtaining any consent legally required for email, SMS, voice, or automated outreach and for honoring legally required opt-out requests.
5. Fraud, Deception, and Impersonation
You will not use the Services to:
- engage in fraud or theft;
- impersonate another person or organization without lawful authority;
- misrepresent identity for an unlawful or materially deceptive purpose;
- create deceptive documents or communications intended to defraud; or
- misuse e-signature or identity functionality.
6. Harmful or Unlawful Content
You will not knowingly use the Services to host, transmit, create, or distribute content where doing so is unlawful, including material that unlawfully infringes intellectual property, violates privacy rights, constitutes unlawful harassment or threats, or is prohibited by a binding court order.
Legasus does not undertake a general obligation to monitor Customer Data but may act on content or conduct that violates the Terms or creates material legal/security risk.
7. Professional and Regulated Use
Customer is responsible for obtaining licenses, consents, approvals, and professional authorization required for Customer's use.
The Services may not be used to enable unauthorized practice of law, medicine, or another regulated profession.
8. Recording and Communications
You will not record, transcribe, monitor, or analyze a call, meeting, conversation, or communication through the Services unless you have provided any legally required notice and obtained any legally required consent.
9. Client and Third-Party Data
You will not submit information to the Services unless you have authority to do so. This includes client information, medical records, email accounts, cloud-storage data, legal research content, documents under protective order, and third-party confidential information.
10. Protected Health Information
You may submit PHI only through Services/configurations designated by Legasus as HIPAA-eligible and under an executed BAA where required.
11. Intellectual Property and Competitive Misuse
You will not:
- resell or sublicense the Services except where expressly authorized;
- remove proprietary notices;
- reproduce substantial portions of the Services outside authorized functionality;
- reverse engineer or derive source code except where a restriction is prohibited by law;
- scrape or systematically extract the Services for competitive replication;
- use Legasus technology, nonpublic documentation, APIs, or output to create a competing product in violation of the MSA; or
- violate the AI-specific restrictions in the AI AUP.
12. API and MCP
API/MCP use must comply with the API & MCP Developer Terms. You will not:
- exceed applicable limits;
- expose credentials publicly;
- use API/MCP access outside approved scopes;
- create insecure integrations;
- use access to circumvent ordinary permissions; or
- use API/MCP access after authorization is revoked.
13. Client Portal and External Sharing
Customer is responsible for ensuring external recipients and Client Users are authorized to receive information shared through the Services.
You will not knowingly create public or external links to confidential information without appropriate authorization and security settings.
14. Law-Enforcement and Government Misrepresentation
You will not falsely represent that a request or instruction comes from a court, government agency, law-enforcement authority, or regulator.
15. Sanctions and Export Controls
You will not use the Services from, for, or on behalf of a prohibited person or territory in violation of applicable sanctions or export-control laws.
16. Enforcement
Legasus may investigate suspected violations and may throttle, disable features, suspend users, restrict integrations, suspend Customer access, preserve records, or terminate affected Services where reasonably necessary to enforce the Terms, protect security, or comply with law.
Legasus may take immediate action for security emergencies, illegal activity, fraud, material abuse, or threats to another Customer or the platform.
17. Reporting Abuse
Report suspected abuse to legal@legasus.ai.
Report security vulnerabilities or incidents to security@legasus.ai.