Home / Legal
Acceptable Use Policy
This document is a working draft pending attorney review. It is published for transparency; the executed agreement governs any engagement.
Nexus Prism Intelligence Platform Quinn Defense Systems
Version: 1.0-draft (Pending Attorney Review) Effective Date: upon Terms of Service sign-off
This policy supplements and is incorporated into the Terms of Service and the NDA where an NDA is in effect. Capitalised terms have the meanings given there.
1. Purpose
Nexus Prism is an OSINT intelligence platform used by government agencies, managed security providers, fraud and insurance investigators, journalists, and academic researchers. This AUP exists to keep that community safe, to protect third-party data providers whose feeds we license, and to prevent the Platform from being used to harm people.
2. Prohibited Uses
You must not use the Platform -- and must not permit any of your Users to use the Platform -- to:
-
Target protected classes. Conduct surveillance, profiling, or targeting of individuals on the basis of race, national origin, religion, political opinion, sexual orientation, gender identity, disability, or trade-union membership, except to the extent expressly required for a lawful law-enforcement, counter-terrorism, or counter-intelligence investigation conducted under a valid legal predicate and in compliance with the Fourth Amendment, GDPR, UK Data Protection Act 2018, LGPD, or the equivalent local framework.
-
Stalk, harass, or dox. Compile or publish non-consenting individuals' addresses, phones, or family details (doxing); enable stalking, domestic abuse, or intimate-partner surveillance; or facilitate swatting, threat campaigns, or coordinated harassment.
-
Violate sanctions or export controls. Access the Platform from, or deliver Content to, jurisdictions under comprehensive US sanctions (currently Cuba, Iran, North Korea, Syria, and the Crimea/Donetsk/ Luhansk regions of Ukraine); provide Content to parties on the US OFAC Specially Designated Nationals list, the EU Consolidated List, or the UK HM Treasury list; or export Platform capabilities in violation of the US EAR, ITAR, or the Wassenaar Arrangement dual-use regime.
-
Enable critical-infrastructure attacks. Use the Platform to plan, execute, or support attacks against critical infrastructure including energy, water, transport, finance, health-care, and communications systems. Legitimate defensive research against infrastructure you own or are expressly contracted to protect is permitted.
-
Bulk-harvest feed data for resale. Use rate-limit circumvention, multiple accounts, or coordinated Tenants to extract third-party feed data (Shodan, VirusTotal, AbuseIPDB, IntelX, OTX, URLScan, or any successor) in volumes that exceed your Subscription's documented quota, or repackage that data for sale to third parties in a manner inconsistent with the upstream licensor's terms.
-
Compete by cloning. Reverse-engineer, decompile, scrape, or otherwise extract the Platform's dashboards, correlation logic, ML models, or tradecraft for the purpose of building a materially similar product. Normal competitive benchmarking, security research conducted responsibly under Section 9, and academic publication that names the Platform are permitted.
-
Abuse the rate limits. Exceed your Subscription's API rate limits; open excessive concurrent sessions (more than five times the provisioned seat count); use concurrent anonymous / shared-pool accounts to evade metering; or run automated clients that ignore HTTP 429 / Retry-After signalling.
-
Upload prohibited content. Upload classified information above your Tenant's ceiling, child sexual-abuse material, non-consensual intimate imagery, malware intended for in-the-wild deployment, or personal data of third parties for which you lack a lawful basis under the GDPR or equivalent.
-
Misrepresent yourself. Create accounts using materially false identity information, using a stolen identity, or on behalf of another natural person without authority.
-
Interfere with the Platform. Probe for vulnerabilities outside the coordinated-disclosure process in Section 9; attempt to disrupt, degrade, or deny service to other Tenants; tamper with audit logs; or circumvent tenant-isolation boundaries.
3. Investigative Conduct
3.1 The Platform produces decision-support signals -- risk scores, correlations, pivot suggestions, enrichment results -- not determinations of guilt. Investigators, analysts, and operators using Content from the Platform must:
- corroborate material findings with at least one independent source before taking operational action against a natural person;
- preserve the chain of custody (export, hash, timestamp, sign) in a manner appropriate to the forum (criminal prosecution, civil discovery, administrative enforcement, insurance claim);
- honour their own agency's or employer's legal-process requirements (warrants, court orders, FISA predication, EU DPA authorisation) before querying the Platform for a specific individual.
3.2 We do not remove a tenant's access because of the subject of an investigation -- investigators must in good faith believe a legal predicate exists, and we will not interpose ourselves in that judgement.
4. Automated / AI-Assisted Use
4.1 You may use the Platform's API with bots, agents, or LLM orchestration, subject to the rate limits and Section 2.5. You must not:
- chain the Platform's output into fully autonomous adversarial actions (doxxing bots, automated swatting, mass-account-takeover pipelines);
- use third-party LLM providers to post-process Tenant-internal Content in a way that would exfiltrate personal data to an unqualified processor under GDPR or equivalent.
4.2 Bots and agents must identify themselves by a distinct API key
labelled for automation and must include a User-Agent header that
includes your organisation name.
5. Third-Party Feed Compliance
5.1 The Platform integrates Shodan, VirusTotal, AbuseIPDB, IntelX, OTX, URLScan, and (under Gold / Platinum) private feeds. Each provider enforces its own AUP. You agree to follow each provider's published AUP in addition to this one, including any prohibition on bulk export, non-research resale, or regional access.
5.2 If a provider notifies us of a Tenant's suspected breach we will investigate and may restrict that Tenant's access to the affected feed while the investigation is open. Confirmed breaches are grounds for Subscription termination under ToS Section 11.
6. Data Minimisation
6.1 We encourage, and in regulated jurisdictions require, data minimisation:
- Query only what you have lawful basis to query.
- Retain exports only as long as your investigation or case management requires.
- Tag and review Content classified above
UNCLASSIFIED // FOUOin accordance with your agency's record-retention schedule.
6.2 The Platform supports automated purge of case files older than a configurable retention window; contact your tenant admin to enable it.
7. Vulnerability Research and Disclosure
7.1 We welcome responsible security research. You may test the Platform against your own Tenant, provided you:
- Do not attempt to access other Tenants' data.
- Do not degrade service for other customers.
- Do not destroy or exfiltrate data.
- Report findings within seven (7) days via security@quinndefensesystems.com
with PGP encryption preferred (key fingerprint published at
/legal/security.txt).
7.2 We commit to good-faith handling of reports: acknowledgement within 72 hours, reasonable triage timeline (typically 30 days for high severity, 90 for medium), and no legal action against researchers who comply with this section.
8. Law-Enforcement Requests
8.1 We respond to lawful requests for Customer data consistent with the Stored Communications Act, GDPR Art. 48, the UK Investigatory Powers Act 2016, and the Australian Assistance and Access Act, as applicable. Where lawful, we will notify affected Customers so they may seek protective orders.
8.2 Abuse of the Platform that rises to imminent-harm level may be proactively referred to the appropriate law-enforcement agency under the emergency-disclosure provisions of the relevant jurisdiction.
9. Consequences of Violation
9.1 Tier 1 (rate limits, bot labelling). Automatic throttling, warning email to tenant admins.
9.2 Tier 2 (repeated Tier 1, or a single instance of Section 2.7 or 2.8). Temporary suspension of the offending User or API key until acknowledgement received from tenant admin.
9.3 Tier 3 (any of Sections 2.1 -- 2.6, 2.9, 2.10, or confirmed feed-provider complaint). Immediate Tenant suspension pending investigation. Confirmed violations are grounds for Subscription termination under ToS Section 11.
9.4 Appeal. Tenant admins may request review within 30 days by writing appeals@quinndefensesystems.com. A two-person committee (one engineering, one legal) reviews and responds within 14 days.
10. Amendments
We may update this AUP by posting a new version at https://quinndefensesystems.com/legal/aup and giving fourteen (14) days' notice by email or in-portal banner. If the update materially increases restrictions, you may terminate under ToS Section 11.2 without penalty before the effective date.
Quinn Defense Systems -- Nexus Prism Intelligence Platform
Security contact: security@quinndefensesystems.com Legal contact: legal@quinndefensesystems.com