Acceptable Use Policy
Last updated August 15, 2026
1. Scope
This policy applies to everyone who uses the CompanyFabric API, SDKs, dashboard, or documentation (“the Service”). It forms part of our Terms of Service. Violating it is grounds for immediate suspension or termination of API keys and accounts.
2. What CompanyFabric is
CompanyFabric is developer infrastructure: a routing and metering layer that forwards authenticated API requests to third-party model providers under a single key and one balance. It is sold to software developers and businesses who integrate it into their own products.
- We do not train, host, or operate the underlying models. Every request is routed to a third-party provider under that provider’s own usage policies, which apply in addition to this one.
- The API serves text and code completions only. We do not offer image, video, audio or voice generation, and there is no consumer-facing product — no end-user app, gallery, feed, marketplace, or published output. Outputs return to the calling application over the API and are not hosted, displayed or distributed by us.
- Our customer is the developer who holds the API key. That developer is responsible for their own end users, and for the terms and moderation that govern them.
3. Prohibited uses
You may not use the Service — directly, or by permitting your end users to — for any of the following. This list is not exhaustive, and each provider’s own usage policies apply in addition.
- Deception and impersonation. Fraud, phishing, scams, fake reviews or engagement, impersonating a real person, business or public body, or generating text presented as authentic human authorship where that breaks applicable rules.
- Security and unauthorised access. Malware, ransomware, credential theft, or exploit development against systems you do not own or have written permission to test.
- Harm and harassment. Content that harasses, threatens, defames, or incites violence or self-harm, or that promotes hatred against a protected group.
- Dangerous capability. Instructions enabling weapons, explosives, or chemical, biological, radiological or nuclear harm.
- Sexual content involving minors. Zero tolerance, including text. We report this to the relevant authorities and terminate the account immediately, without notice or refund.
- Intellectual property. Infringing copyright, trademark, trade secret or other rights, including deliberate reproduction of protected works for passing off.
- Unlicensed regulated activity. Gambling, pharmaceuticals, controlled substances, weapons sales, and unlicensed financial, legal or medical advice presented as professional advice.
- Manipulation at scale. Coordinated political manipulation, election disinformation, or large-scale synthetic astroturfing.
- Personal data misuse. Profiling or surveillance of individuals without a lawful basis, or sending us personal data you have no right to process.
- Anything otherwise unlawful where you or your end users operate.
4. Your obligations as an integrator
Because your end users reach the models through your product and not through ours, moderation at the point of use is yours to run. If your application allows end users to submit prompts or receive generated output, you must:
- publish end-user terms and an acceptable-use policy at least as restrictive as this one;
- operate moderation appropriate to your use case, and be able to act on reports of abuse;
- disclose to your end users that outputs are AI-generated, where they could otherwise be mistaken for human-authored or authentic material;
- keep the ability to identify and suspend an abusive end user, and act on our notice when we forward a complaint;
- hold any consents and lawful bases you need for the personal data you send us.
5. How we enforce this
- Provider safety systems. Every request is executed by a third-party provider whose own safety filters and usage policies apply. A request refused upstream is refused here.
- Authenticated access only. There is no anonymous use. Every request carries an API key bound to an account, so any usage can be traced to an accountable customer and stopped.
- Suspension and revocation. We may suspend or revoke keys, freeze balances against investigation, or terminate accounts for violations of this policy — immediately, and without notice where there is risk of serious harm.
- Reports and cooperation. We act on abuse reports and cooperate with lawful requests from providers, payment partners, and law enforcement.
- Metering records. We retain request metadata (timestamp, model, token counts, cost) for billing and abuse investigation. See the Privacy Policy for what we do and do not retain.
6. Reporting abuse
Report suspected misuse to [email protected]. Include the affected URL or account where you can. We review every report and respond to credible ones within five business days — sooner where there is risk of serious harm.
7. Changes
We may update this policy as the Service, the law, or our providers’ policies change. Material changes are announced by email to account holders and take effect 30 days after posting, except where an earlier change is required for legal or safety reasons. Continued use after that date constitutes acceptance.