Acceptable Use Policy
Version 1.0 · Effective August 8, 2026
Operator: Ellis Intelligence LLC, a Colorado limited liability company doing business as SafeguardsMark ("we", "us", "our"). This Acceptable Use Policy ("AUP") governs your access to and use of the SafeguardsMark platform, web application, and related services (collectively, the "Service"). By accessing or using the Service, you ("Customer", "you") agree to this AUP. This AUP is incorporated into and forms part of our Terms of Service, including its governing-law and dispute-resolution provisions.
If you violate this AUP, we may suspend or terminate your access without prior notice or refund and may pursue any other remedy available to us.
1. Permitted use
You may use the Service only: (a) for your own internal business purposes; (b) in compliance with all applicable laws, regulations, and the Terms of Service; (c) within the usage limits of your subscription tier; and (d) subject to the SafeguardsMark addendum below.
2. Account and access
2.1 Account security. You are responsible for maintaining the confidentiality of your account credentials. You must notify us immediately at [email protected] of any unauthorized account access.
2.2 No sharing. Each user account is for a single individual. You may not share login credentials.
2.3 Workspace isolation. Multi-tenant data isolation is a feature of the Service. You will not attempt to access data belonging to any other tenant, account, or workspace.
3. Prohibited content
You will not upload, transmit, store, or generate through the Service any content that: (a) violates any applicable law; (b) infringes any third party's intellectual property, privacy, publicity, or other rights; (c) contains malware, ransomware, exploits, worms, viruses, or any other harmful code; (d) is unlawful, defamatory, harassing, threatening, hateful, obscene, or sexually exploitative; (e) constitutes protected health information ("PHI"), payment-card cardholder data, or classified national-security information unless your subscription and a separate written agreement expressly permit it; or (f) you are not authorized to share, transmit, or process.
4. Prohibited activities
4.1 Service integrity. You will not, and will not permit any third party to: attempt to gain unauthorized access to any portion of the Service, including any other tenant's data; probe, scan, or test the Service's vulnerability except through a program we pre-authorize in writing; interfere with or disrupt the Service; reverse-engineer, decompile, or attempt to extract the source code or underlying architecture of the Service; circumvent rate limits, usage caps, billing controls, or feature gates; use the Service to build or train a competing product; or scrape, harvest, or systematically extract data from the Service.
4.2 Resale. You will not resell, sublicense, lease, or wrap the Service for delivery to third parties as if it were your own.
4.3 AI and output use. You acknowledge SafeguardsMark's WISP narrative drafting uses artificial intelligence whose outputs may be inaccurate, incomplete, or contain errors. The Service assists your work; it does not make decisions for you. You will independently verify every WISP output before relying on it or submitting it to any third party. You will preserve any disclaimers or attribution the Service applies to outputs unless your subscription tier expressly grants removal rights (it does not).
4.4 Data hygiene. You will not upload personally identifiable information of any individual without a lawful basis under applicable privacy law; data you obtained through unauthorized access, theft, or breach of a third party's confidentiality; or children's data without verifiable parental or guardian consent. You will access the Service only through the encrypted (TLS) endpoints we provide. Our own commitments regarding encryption of data at rest and in transit are stated in the Data Processing Addendum.
4.5 Customer responsibility; indemnification. As between you and us, you are responsible for the lawfulness of the data you submit to the Service and of the instructions you give in using it. Violations of this AUP that give rise to a third-party claim against us are covered by the indemnification provisions of the Terms of Service.
5. Reporting and cooperation
Report suspected AUP violations to [email protected]. We will respond to lawful subpoenas, court orders, and government requests in compliance with applicable law, and will notify the affected Customer where lawful to do so. You will cooperate reasonably with any investigation of suspected AUP violations involving your account.
6. Enforcement
6.1 Depending on severity, we may issue a written warning; temporarily restrict features of your account; suspend your account pending investigation; terminate your account for material breach; refer the matter to law enforcement; or pursue civil remedies.
6.2 Material breach — immediate action. The following permit immediate suspension or termination without prior notice or refund: illegal content, malware, or regulated-data violations; unauthorized access or vulnerability probing; use of the Service in violation of export-control, sanctions, or anti-bribery law; or repeated lower-severity violations after written warning.
6.3 No refund of pre-paid fees is owed for the billing period in which a terminating violation occurred; future billing periods follow the Terms of Service's refund provisions.
6.4 Survival. Termination does not relieve you of obligations that by their nature should survive, including confidentiality, data return/destruction obligations, the representations in §4.5, and liability for violations accruing before termination.
7. Modifications
We may update this AUP from time to time. Material changes will be communicated by email to the account's designated contacts (or by in-app banner) and posted at safeguardsmark.com/acceptable-use. Written notice is deemed given when sent; failure to read a properly sent notice does not extend any period. Continued use of the Service after the effective date of a change constitutes acceptance.
8. Contact
Questions about this AUP: [email protected]
Security and abuse reports: [email protected]
SafeguardsMark addendum
In addition to the base AUP above:
SM1. WISP Builder — Not Legal or Compliance Advice. SafeguardsMark helps you build a Written Information Security Program ("WISP") for the Federal Trade Commission ("FTC") Safeguards Rule under the Gramm-Leach-Bliley Act ("GLBA") from your inputs. It is not legal advice and does not guarantee compliance with the Safeguards Rule or any law. The generated WISP carries an issuance mark identifying who issued it and when, bound to a content fingerprint. That mark records authorship and time. It is not a certification, audit result, accreditation, or third-party validation, and it does not indicate that anyone other than you has reviewed or verified the information in the WISP.
SM2. Accuracy; Your Obligation. The WISP reflects the program facts you provide. You remain responsible for implementing, maintaining, and accurately representing your security program, and for your Safeguards Rule compliance.
SM3. No Customer Financial Data. The Service does not require customer financial-account or consumer financial data; do not upload it.
SM4. Outputs Are Drafts. The WISP and supporting documents are drafts you review and adopt.