This document is current only for the version and effective date published on this site.
1. Purpose, scope, and legal effect
This Policy protects the integrity, security, availability, lawful operation, and reputation of KAIA websites, software, platforms, APIs, networks, documentation, and related resources (the "Services"). It forms part of the Terms of Use and applies to users, account owners, administrators, integrations, agents, contractors, and anyone acting through their access.
A violation is a material breach. A signed government or enterprise agreement may add stricter, use-case-specific conditions; it does not authorize conduct prohibited by non-waivable law.
2. General duties and responsibility
Use the Services only for lawful, authorized, and legitimate purposes. Protect credentials, configure least privilege, respect third-party rights, maintain required licenses and permissions, and supervise automated or delegated use. Account owners are responsible for activity under their credentials to the extent permitted by law and contract.
Users must assess applicable law, including privacy, intellectual property, employment, financial-crime, trade, sanctions, export-control, anti-corruption, human-rights, and sector-specific rules. KAIA’s technical capability or contractual relationship is not a representation that a proposed use is lawful or appropriate.
- Use accurate identity and authorization information.
- Apply proportional human oversight to consequential decisions.
- Preserve provenance and audit records required by the use context.
- Report suspected compromise promptly without expanding access.
3. Illegal, harmful, deceptive, or abusive conduct
You may not use the Services to commit, promote, plan, facilitate, finance, conceal, or materially support unlawful or harmful activity. Prohibited conduct includes fraud, phishing, impersonation, deceptive marketing, money laundering, terrorist financing, human trafficking, child exploitation, illegal gambling, sale of controlled substances, terrorism, violent extremism, organized crime, threats, harassment, bullying, incitement of violence or self-harm, and unlawful hate-based abuse.
Child sexual abuse material and exploitation are prohibited without exception. KAIA may preserve and report apparent illegal content as required by law, including to NCMEC or another competent authority. Good-faith security, compliance, or law-enforcement activity must remain within documented legal authority and scope.
4. System, network, content, and resource abuse
You may not gain or attempt unauthorized access; scan, probe, or test without written authorization; bypass authentication, rate, use, export, or safety controls; degrade or overload a Service; deploy malware; forge network identity; exfiltrate data; scrape or automate access contrary to published controls; or use Services for unauthorized cryptocurrency mining or disproportionate computation.
You may not infringe intellectual-property rights; disclose another person’s private, confidential, financial, identity, medical, or communication data without lawful authority; dox individuals; distribute malicious disinformation intended to cause harm; send spam; operate deceptive bots; or upload material that exposes KAIA or others to unlawful handling obligations.
- No vulnerability testing without written scope and rules of engagement.
- No reverse engineering except where non-waivable law expressly permits it.
- No bulk extraction for competing products or model training without authorization.
- No classified, controlled, privileged, credential, or active-threat payload through public forms.
5. High-risk and sensitive end uses
Unless expressly authorized by a controlling written agreement and permitted by applicable law, the public Services may not be used to design, develop, produce, test, target, operate, or materially enable conventional weapons; nuclear, chemical, or biological weapons; ballistic missiles; or weaponized unmanned systems. No use may support prohibited proliferation, terrorism, war crimes, unlawful violence, or human-rights abuse.
The Services may not be used to execute offensive cyber operations against critical infrastructure; conduct unlawful interception, mass surveillance, biometric identification, or social scoring; make unlawful discriminatory decisions; evade sanctions or export controls; or remove legally required human decision authority from a consequential intervention. Authorized defense, intelligence, and public-security use remains subject to program-specific law, contract, command authority, rules, review, and technical controls.
- Government status is not a substitute for specific lawful authority.
- A model score is not sufficient authority for coercive action.
- High-consequence use requires documented purpose, evidence, controls, escalation, and accountability.
- KAIA may refuse or restrict a use whose material risk cannot be responsibly bounded.
6. Investigation, enforcement, and reporting
KAIA may investigate credible indications of violation and may preserve relevant evidence, request information, restrict features, rate-limit, block content, suspend or terminate access, require remediation, notify an affected party, or report conduct to a competent authority where lawful and proportionate. Action may be immediate where delay would increase risk.
Enforcement considers severity, intent, scale, vulnerability of affected people, recurrence, cooperation, evidence quality, legal obligations, and the feasibility of mitigation. KAIA may not be able to disclose investigation status or outcome. A user remains responsible for losses and legally available remedies resulting from its violation, subject to applicable law and the controlling agreement.
Report suspected violations through the internal Contact page using Security, Legal, Human Rights, or another appropriate category. Provide only lawfully held, necessary, non-sensitive information; do not send exploit code, classified material, personal dossiers, or secrets through the public channel.
7. Changes, severability, and no waiver
KAIA may update this Policy prospectively to address changes in law, threats, technology, or Services. The effective date and version identify the current public edition. Continued use after an effective update constitutes acceptance to the extent permitted by law and the controlling agreement.
Failure to enforce a provision once is not a waiver. If a provision is invalid or unenforceable, it will be modified or severed to the minimum extent necessary and the remainder remains effective. Questions and authorization requests should be submitted through the internal Contact page.
