Acceptable Use Policy
What this policy is
1.1 This Acceptable Use Policy forms part of the Obstruo Terms of Service and expands Section 4 of those Terms. Breaching it is a material breach of the Terms.
1.2 It applies to the Customer, to its Users, and to any application, agent or end user acting through the Customer's credentials. The Customer is responsible for the conduct of all of them.
1.3 Two sets of rules apply to you, not one. Obstruo does not operate models. Requests are routed to Upstream Providers using credentials the Customer supplies, under the Customer's own agreement with each provider. That provider's usage policy governs what may be asked of its model; this policy governs use of the Obstruo control plane. Where they differ, the stricter applies. A provider suspending your account is a matter between you and that provider.
1.4 What Obstruo can and cannot see. By design, unredacted request content is not retained: redaction is applied in memory and only post-redaction content reaches the audit log. Obstruo therefore does not routinely inspect the content of Customer traffic and does not police it in the way a model provider does. Enforcement relies on guardrail and classifier signals, operational and billing patterns, reports from customers and third parties, and legal process. The Customer's own governance is the primary control, which is the point of the product.
Universal rules
You must not use the Service, and must not permit anyone using your credentials to use it:
Against children. To generate, request, transmit, store or distribute child sexual abuse material, including material that is wholly or partly synthetic; to sexualise a minor; or to facilitate grooming, sextortion or trafficking. There is no research, testing or red-team exception. Suspected material of this kind is reported to the competent authorities.
To build weapons. To design, develop, acquire or deploy chemical, biological, radiological or nuclear weapons, high-yield explosives, or their precursors or delivery systems, or to circumvent export controls or sanctions relating to them.
To attack systems. To develop or operate malware, ransomware or exploit code; to conduct unauthorised access, denial-of-service or credential-stuffing activity; or to support any of these, whether against Obstruo, an Upstream Provider, another customer, or any third party.
To harm people. To incite or plan violence, terrorism or self-harm; to run harassment, stalking or doxxing campaigns; or to produce non-consensual intimate imagery.
To deceive. To impersonate a person or organisation without authorisation; to run fraud, phishing or social-engineering operations; to present content as human where a person would reasonably need to know it is not; or to manipulate an election, referendum or democratic process, including through coordinated inauthentic behaviour.
Against EU law. To carry out a practice prohibited by Article 5 of the AI Act, including subliminal or manipulative techniques causing significant harm, exploitation of vulnerabilities of age, disability or social or economic situation, social scoring, untargeted scraping of facial images to build recognition databases, emotion inference in the workplace or in education outside safety or medical grounds, biometric categorisation to infer protected characteristics, and real-time remote biometric identification in public spaces for law enforcement outside the narrow permitted cases.
Unlawfully generally. To infringe intellectual property or trade secrets, to breach confidentiality obligations you owe, or to process personal data without a lawful basis.
Integrity of the control plane
3.1 You must not deliberately defeat or circumvent the redaction, guardrail, tool-permission or audit functions, including by encoding, chunking or splitting content across requests or projects to evade detection.
3.2 You must not use raw-audit mode, or any other configuration, to evade a control your own organisation has imposed on itself, or to defeat an obligation you owe to a third party.
3.3 You must not attempt to extract model weights, another customer's provider credentials, or Obstruo's own detection logic, rules or models.
3.4 You must not probe, scan, stress-test or attempt to disrupt the Service outside the rules in Section 8, circumvent rate limits or quotas, or share credentials across legal entities not covered by your Order.
3.5 You must not resell, white-label or provide the Service to third parties without a separate written agreement.
3.6 You must not use the routing features to circumvent territorial, entity-based or sanctions-related restrictions imposed by an Upstream Provider or by law.
High-risk applications
4.1 The Service must not be the sole basis of a decision producing legal effects concerning a person or similarly significantly affecting them. A competent human must be able to review the decision, to disagree with it and to change it, and your audit log must record that this took place.
4.2 This applies in particular to credit and lending, insurance underwriting and claims, employment, promotion and dismissal, education admission and grading, housing, healthcare, benefits and other public services, migration, and law enforcement or criminal justice.
4.3 Where you operate a high-risk AI system within the meaning of the AI Act, you remain responsible for your own obligations under it, including risk management, data governance, technical documentation, record-keeping, human oversight, accuracy and cybersecurity. Obstruo provides tooling that assists with some of these obligations. It does not discharge them and does not make you compliant.
4.4 In medicine, the Service must not be used for diagnosis or treatment decisions without qualified human oversight, and must not be used in life-support or other systems where failure risks death or serious injury. It must not be used to control critical infrastructure, autonomous vehicles or weapons systems.
Disclosure
5.1 Where an end user interacts with an AI system through your deployment, tell them. The disclosure must be clear and made before or at the start of the interaction.
5.2 Do not present AI-generated output as coming from a named human, and do not use the synthetic voice or likeness of a real person without their consent.
5.3 Where the law requires machine-readable marking of synthetic content, meeting that obligation is your responsibility.
Agents, tools and MCP servers
6.1 You are responsible for every tool you allow an agent to call and for everything the agent does with it. Destructive operations, meaning anything that writes, deletes, transfers value or contacts a third party, should require human approval unless you have assessed the risk and accepted it.
6.2 You must not register an MCP server you are not authorised to expose, or use the MCP gateway to reach systems you do not own or have permission to access.
6.3 You must not use agents to conduct automated activity against third parties that would breach Section 2, including scraping in breach of a site's terms, mass account creation, or automated pressure on individuals.
6.4 Agent traffic consumes plan limits like any other traffic. Runaway agent loops are your responsibility, and Section 6.5 of the Terms applies to the resulting charges.
Minors
7.1 The Service is offered only to businesses and is not directed at individuals under 18.
7.2 If your deployment is directed at or likely to be used by children, you are responsible for the additional protections the law requires, including age assurance where applicable, and for a documented assessment of the risks before launch. Tell us at office@obstruo.ai before you go live so we can agree any additional measures.
Security research
8.1 Testing of the redaction, guardrail, MCP gateway or routing functions requires our prior written approval. Write to office@obstruo.ai with the scope, timing and the identity of the testers. We will not unreasonably refuse approval for testing under a documented security assessment.
8.2 Approved testing must stay within your own projects and credentials, must not target other customers' data or Upstream Provider accounts, and must not degrade the Service for others.
8.3 Report any vulnerability you find to office@obstruo.ai and give us a reasonable opportunity to fix it before publishing details or proof-of-concept code. We will not pursue good-faith research conducted within these rules.
Data you route through the Service
9.1 You must have a lawful basis for the personal data you submit, and your instructions to us must comply with data protection law.
9.2 You must not submit special categories of personal data under Article 9 GDPR, or data on criminal convictions and offences under Article 10, without our prior written agreement and the additional measures recorded in it.
9.3 You must not submit datasets you have no right to use, including data obtained by scraping in breach of terms, by unauthorised access, or from a breach.
Enforcement
10.1 Where we believe this policy has been breached, we may warn you, require you to change a configuration, throttle or suspend an affected project, key or endpoint, suspend or terminate the account, or refer the matter to the authorities. Section 3.4 of the Terms governs suspension and Section 12 governs termination.
10.2 We act proportionately. A misconfigured recogniser or a developer tripping a filter is not the same as deliberate, repeated evasion, and we treat them differently. Deliberate circumvention of safety controls, and anything in the children's-safety or weapons categories in Section 2, are grounds for immediate termination without a cure period.
10.3 Where we can, we tell you what happened and what we need from you before acting, unless doing so would risk ongoing harm, prejudice an investigation, or breach a legal obligation.
10.4 You may appeal by replying to the enforcement notice within 14 days. The appeal is considered by someone other than the person who made the original decision.
10.5 We may preserve evidence where the law requires it, and will disclose it only where legally obliged or where necessary to protect a person from serious harm.
Reporting
Report a suspected breach of this policy, whether by you or by anyone else, to office@obstruo.ai. Reports made in good faith will not be held against the reporter. If you believe someone is in immediate danger, contact the emergency services first.
Changes
We may update this policy on at least 30 days' notice, or immediately where a change is needed for legal or safety reasons. Section 13 of the Terms governs changes and your right to terminate where a change materially reduces your rights.