Ours, pending counsel sign-off. Bonterms publishes an example acceptable use policy, not a standard form, so this Acceptable Use Policy ("AUP") is ElasticD3M's own. It is an Attachment to the Terms of Service and is the AUP that Section 7.1 of the Bonterms Standard Online Cloud Terms refers to. It applies to all use of Enclave AI™, and the whole AUP is pending sign-off by counsel.
1. Purpose
This AUP describes the conduct expected from Customer and Customer's Users when using Enclave AI™. It adds to the Usage Rules in Section 7 of the Standard Terms and in Section 2.6 of the Terms of Service.
2. Federal Contracting Eligibility (Required Certification)
By using the Cloud Service, Customer represents and certifies that, as of the date of purchase and throughout the term of the subscription, Customer's organization:
- Is not debarred, suspended, or otherwise excluded from participation in U.S. federal procurement programs (FAR 52.209-5; SAM.gov Exclusions List).
- Does not procure or use covered telecommunications equipment or services from Huawei, ZTE, Hytera, Hikvision, Dahua, or any other entity prohibited under FAR 52.204-25 / NDAA §889 Part A or Part B.
- Is not an entity identified on the NDAA §1260H list of Chinese military-affiliated companies or the U.S. Treasury OFAC SDN list or any other U.S. government denied-party list.
- Complies with applicable U.S. export control laws (Export Administration Regulations / International Traffic in Arms Regulations) in its use of the Cloud Service.
- Is not subject to cybersecurity-related sanctions or restrictions affecting eligibility to procure cloud or compliance services from U.S. providers.
Customer agrees to notify Provider at legal@elasticd3m.com promptly if Customer's eligibility status changes during the term. A change in eligibility status may be grounds for termination for cause under the Terms of Service.
3. Prohibited Uses
Customer agrees not to use the Cloud Service to:
- Violate any applicable law or regulation, including without limitation U.S. export control laws (EAR, ITAR), sanctions regulations (OFAC), or DFARS / NIST cybersecurity requirements.
- Submit Controlled Unclassified Information (CUI) payloads to the Cloud Service. The Cloud Service is designed to read configuration metadata (IAM roles, security-control settings, audit-log metadata), not regulated data contents. Customer is responsible for ensuring the data it submits at intake or otherwise conveys to the Cloud Service does not include CUI payloads or other regulated material.
- Infringe any third party's intellectual property, privacy, publicity, or other rights.
- Interfere with or disrupt the integrity or performance of the Cloud Service or any third-party systems linked to or used by it.
- Attempt to gain unauthorized access to the Cloud Service, other accounts, or ElasticD3M, LLC's computer systems.
- Send through, or facilitate sending through, the Cloud Service any unsolicited bulk email, malware, ransomware, or other malicious code.
- Impersonate any person or misrepresent affiliation with any organization.
Reverse engineering, security testing, resale and building a competing product are governed by Section 7.3 of the Standard Terms, as modified by Section 2.7 of the Terms of Service.
4. Security Research
Good-faith security research is welcome when it follows /.well-known/security.txt: report to hello@ai4cmmc.ai with enough detail to reproduce the issue, give us a reasonable window to remediate before public disclosure, do not run automated scanning that degrades service for customers, do not access or modify data belonging to another party, and do not attempt social engineering against our staff or vendors. Research within those rules is not a breach of Section 7.3(d) of the Standard Terms.
5. System Integrity
Customer will not knowingly take any action that imposes an unreasonable or disproportionately large load on the Cloud Service's infrastructure, or attempt to circumvent any rate limits, access controls, or technical safeguards.
6. Reporting Violations
Suspected AUP violations may be reported to abuse@elasticd3m.com or hello@ai4cmmc.ai. ElasticD3M, LLC will investigate reasonable reports in good faith.
7. Consequences
A breach of this AUP is a breach of Section 7 of the Standard Terms, which is a Suspension Event under Section 11 of the Standard Terms. Provider will give prior notice where practicable, as that Section provides, and restores access promptly once the issue is resolved. Customer remains responsible for fees due for periods prior to suspension or termination.
Effective Date: September 24, 2026 · Version: 2.0