Platform Governance

Acceptable Use Policy (AUP)

Effective Date: August 2026 • Version 2.0

Standard of Conduct

This Acceptable Use Policy outlines the rules and standards required of all users of SiteMind. By creating a workspace, generating embeddings, or embedding our widgets, you agree to adhere strictly to these guidelines.

1. Prohibited Content

  • Illegal Content: Any content that violates applicable local, national, or international laws, including child sexual abuse material (CSAM), human trafficking, or terrorism recruitment.
  • Malicious Software: Distributing viruses, trojans, worms, ransomware, keyloggers, or other harmful computer code.
  • Infringing Material: Indexing, uploading, or distributing text, documents, or media that infringe copyright, trademark, patent, trade secret, or other intellectual property rights of third parties.
  • Harassment & Defamation: Using the assistant or widget to generate defamatory, threatening, abusive, racially offensive, or hateful communications.
  • Phishing & Deceptive Impersonation: Forging identities, deploying deceitful lead-capture forms, or pretending to be an unaffiliated financial, governmental, or law enforcement institution.

2. Regulated Data Prohibitions (HIPAA, PCI & Financial Data)

  • Protected Health Information (PHI): SiteMind is designed for public website assistance and general logistical support. SiteMind is NOT a HIPAA-compliant repository and does not execute Business Associate Agreements (BAAs). You MUST NOT upload, crawl, or solicit Protected Health Information (PHI), medical records, or diagnostic data through the Service.
  • Payment Card Data (PCI-DSS): You MUST NOT use SiteMind chat forms or document uploads to collect or store primary account numbers (PANs), card security codes (CVV/CVC), or bank account PINs.
  • Classified & National Security Data: Ingesting government-classified information, defense articles, or export-controlled technological data is strictly forbidden.

3. Prohibited Technical Activities & Abuse

  • Adversarial Prompt Injection & Jailbreaks: Attempting to bypass system safety guardrails, force model instruction leakage, or manipulate the assistant to execute unauthorized system commands.
  • Unauthorized Crawling & Web Scraping: Initiating crawl jobs against domains you do not own or for which you lack explicit written authorization to scrape.
  • Denial of Service & Rate-Limit Bypasses: Flooding API endpoints, deploying automated bot attacks, rotating forged headers to evade rate limiters, or interfering with system availability for other customers.
  • Reverse Engineering: Decompiling, reverse-engineering, or extracting proprietary source code, vector ranking heuristics, or prompt templates from the SiteMind platform.
  • Security Probing: Performing uncoordinated vulnerability scans, penetration testing, or stress tests against SiteMind production infrastructure without prior written authorization from [email protected].

4. Crawler Etiquette & Fair Use

  • Authorized Scope: Crawlers must only be targeted at public website URLs and approved subdirectories.
  • Traffic Limits: SiteMind enforces concurrency controls and domain-level crawl ceilings to ensure destination web servers are not overwhelmed.
  • Resource Respect: If a target website owner requests the cessation of crawling, Customer must immediately disconnect the domain.

5. Enforcement, Investigation & Reporting

  • Monitoring & Investigation: SiteMind reserves the right to investigate any suspected violation of this Policy, inspect anomalous traffic patterns, and cooperate with law enforcement authorities.
  • Remediation Actions: In the event of a violation, SiteMind may issue warnings, remove offending content, disable crawler jobs, or immediately suspend or terminate workspace access without liability or refund.
  • Abuse Reporting: To report suspected abuse, spam, phishing, or safety violations involving a SiteMind widget, contact us immediately at [email protected] or [email protected].