REVIEW-READY DRAFT — GBOS-specific and factual, but NOT final and NOT legal advice. Must be confirmed by a qualified solicitor before GBOS relies on it (see the [SOLICITOR TO CONFIRM] items).

Acceptable Use Policy

Version 2026-08-r1 · Effective 2026-08-02

What you may not do with the GBOS platform.

1. Prohibited conduct

You must not use the Service to break the law, infringe intellectual-property or privacy rights, transmit malware, send unlawful or unsolicited communications, or store or process data you have no right to.

2. Platform integrity

You must not attempt to breach tenant isolation, bypass authentication/authorisation, defeat approval, segregation-of-duties or audit controls, tamper with the audit trail, or interfere with other tenants or the availability of the Service (e.g. denial-of-service).

You must not exceed the authority limits configured for autonomous agents by manipulating the governance boundary.

3. Security testing

Automated scanning, penetration testing and other security testing are permitted ONLY under a prior written authorisation and rules of engagement agreed with GBOS, against a dedicated test workspace and test accounts. Unauthorised testing is a breach of these terms.

4. Enforcement

We may investigate suspected breaches and may suspend or terminate access for serious or repeated breaches, with notice where practicable. [SOLICITOR TO CONFIRM] the enforcement, notice and appeal mechanics.

Clauses a solicitor must confirm

The following points in this document require qualified legal sign-off before GBOS relies on it.

  • Suspension/termination triggers and notice periods — confirm consistency with the Terms and consumer/business law.
  • Whether the security-testing carve-out should be broadened into a formal vulnerability-disclosure / safe-harbour policy.

This document is a GBOS-specific, review-ready draft. It is not final and does not constitute legal advice; it must be confirmed by a qualified solicitor (see the clauses flagged above) before GBOS relies on it.