Skip to content

Version 1.0.0-draft · not in force · sha256 3a7a863f37d999db…

Acceptable Use Policy

DRAFT — REQUIRES REVIEW BY QUALIFIED COUNSEL IN [JURISDICTION] BEFORE USE. Not legal advice. Not a substitute for a lawyer.

Version: 1.0.0-draft · Status: not in force · Baseline: GDPR-grade


What we will not assess, and will never certify

We refuse assessment, log the refusal, and do not issue a mark for applications that:

  1. Distribute malware, spyware, stalkerware or ransomware;
  2. Conduct phishing or harvest credentials;
  3. Facilitate child sexual abuse material or any sexual content involving minors;
  4. Facilitate the sale or manufacture of weapons or illicit substances;
  5. Offer financial services requiring a licence the operator does not hold, including unlicensed deposit-taking, lending, investment advice or virtual-asset services;
  6. Impersonate a real institution, public authority, payment provider or individual;
  7. Scrape or repackage third-party services in breach of those services' terms;
  8. Exist to deceive users about who is behind them, what data they collect, or what they do with it;
  9. Target or profile a private individual without a lawful basis;
  10. Are designed to evade detection, sanctions, or lawful process.

This list is not exhaustive. We may refuse anything we judge to fall within its spirit.

How it is applied

  • At intake, automatically, from the application's stated purpose, category and observable behaviour.
  • At review, by the human reviewer, who may refuse on the same grounds.
  • After certification, if the application changes into something on this list, the mark is revoked.

What happens when we refuse

We record the refusal and its ground in an append-only log, tell you which ground applied, and refund any fee for the assessment we did not perform. You may appeal under the Appeals & Corrections Policy. We do not publish refusals.

Behaviour on the platform

You must not attempt to obtain a mark for an application you do not control, submit an authorisation warranty you know to be untrue, interfere with the assessment of another customer's application, attempt to influence a score by any means other than fixing the application, or attempt to extract our rubric internals, prompts or reviewer identities.