Cortlet iconCortlet

Cortlet

Acceptable Use Policy

Last updated: September 13, 2026

1. Scope

This Acceptable Use Policy ("AUP") applies to your use of Cortlet websites, software, APIs, developer tools, hosted services, infrastructure, documentation, and other products or services made available by Cortlet.

This AUP forms part of the terms governing your use of Cortlet. If a specific product includes additional acceptable-use rules, those rules also apply.

2. General Requirement

You may use Cortlet only for lawful purposes and in a manner that does not harm Cortlet, other users, third parties, networks, systems, or services.

You are responsible for all activity conducted through your accounts, credentials, API keys, systems, applications, and integrations.

3. Illegal or Harmful Activity

You must not use Cortlet to:

  • violate any applicable law, regulation, court order, or legal obligation;
  • facilitate fraud, theft, deception, impersonation, or other unlawful conduct;
  • knowingly distribute, promote, or facilitate malware, malicious code, ransomware, credential-stealing software, or destructive payloads;
  • engage in conduct intended to cause material harm to another person, organization, service, device, or network.

4. Unauthorized Access and Security Abuse

You must not use Cortlet to gain or attempt to gain unauthorized access to any account, system, device, network, service, data, or infrastructure.

Prohibited activity includes:

  • credential theft, credential stuffing, or password attacks;
  • unauthorized vulnerability exploitation, intrusion, or privilege escalation;
  • bypassing authentication, authorization, rate limits, access controls, or security measures;
  • scanning or probing systems without authorization where such activity is unlawful or harmful;
  • accessing, modifying, intercepting, destroying, or exfiltrating data without authorization.

5. Denial of Service and Resource Abuse

You must not use Cortlet to intentionally disrupt, degrade, overload, disable, or interfere with Cortlet or any third-party service, network, or infrastructure.

This includes:

  • denial-of-service or distributed denial-of-service attacks;
  • intentionally generating abusive traffic or excessive requests;
  • attempts to exhaust compute, bandwidth, connection, database, storage, or other resources;
  • circumventing quotas, technical limits, usage controls, or rate limits.

6. Abuse of APIs and Developer Infrastructure

You must not use Cortlet APIs, gateways, command-line tools, SDKs, endpoints, or developer infrastructure in a manner that materially interferes with normal operation or other users.

You may not use automated systems to bypass documented restrictions, create artificial traffic, evade enforcement, or consume resources substantially beyond the intended use of a product.

7. WebSocket and Network Traffic

Where Cortlet products handle WebSocket, HTTP, webhook, proxy, or other network traffic, you are responsible for ensuring that you are authorized to send, receive, inspect, route, forward, or process that traffic.

You must not use Cortlet to intercept private communications, monitor traffic without authorization, or relay malicious or unlawful traffic.

8. Spam and Unsolicited Communications

You must not use Cortlet to send, facilitate, automate, or relay spam or unlawful unsolicited communications.

You are responsible for complying with applicable messaging, email, anti-spam, marketing, and consent requirements when using Cortlet with communication systems.

9. Fraud, Impersonation, and Misrepresentation

You must not use Cortlet to impersonate another person or organization, misrepresent your identity or affiliation, or deceive others regarding the origin or purpose of communications, software, services, or data.

You may not represent that your product or service is operated, sponsored, certified, or endorsed by Cortlet unless Cortlet has expressly authorized that representation.

10. Intellectual Property

You must not use Cortlet to infringe or misappropriate copyright, trademark, patent, trade-secret, or other intellectual-property rights.

You are responsible for ensuring that you have the rights and permissions necessary for software, code, files, logs, content, data, and other materials you process using Cortlet.

11. Privacy and Personal Data

You must not use Cortlet to collect, access, disclose, process, or distribute personal information in violation of applicable privacy or data-protection law.

You are responsible for obtaining any required notices, consents, permissions, or legal basis for personal data you process using Cortlet.

12. Sensitive Information

You are responsible for determining whether Cortlet is appropriate for the type of information you intend to process.

Unless Cortlet expressly states otherwise for a particular product, you should not assume that a service is designed for regulated, highly sensitive, classified, or safety-critical information.

13. Credentials and Secrets

You are responsible for protecting passwords, API keys, access tokens, private keys, environment variables, certificates, secrets, and other credentials used with Cortlet.

You must not knowingly upload, expose, publish, or distribute credentials belonging to another person or organization without authorization.

14. Malicious Software

You must not use Cortlet to create, host, distribute, deploy, or control malicious software intended to compromise, damage, surveil, extort, disrupt, or gain unauthorized access to systems or data.

Legitimate security testing, research, debugging, malware analysis, or defensive activity is permitted only where lawful and properly authorized.

15. Security Research and Testing

Cortlet developer tools may be used for legitimate security research, testing, debugging, and analysis when you have appropriate authorization.

You are responsible for ensuring that testing is performed against systems you own, control, or have explicit permission to test.

16. Automated Activity

Automated use of Cortlet must comply with documented interfaces, technical limits, rate limits, and product restrictions.

You must not use bots, scripts, crawlers, clients, or automated systems to evade restrictions, create abusive traffic, scrape protected information, or materially interfere with Cortlet.

17. Account and Access Abuse

You must not create, acquire, share, or use accounts for the purpose of bypassing suspensions, bans, usage restrictions, quotas, rate limits, or enforcement actions.

You must not access another user's Cortlet account, organization, project, credentials, or resources without authorization.

18. Resale and Unauthorized Commercial Use

You may use Cortlet in commercial applications where permitted by the applicable product terms.

You may not resell, repackage, sublicense, or provide direct access to a Cortlet service as your own standalone service where the applicable license or product terms prohibit that activity.

19. Circumvention

You must not circumvent or attempt to circumvent technical, security, billing, licensing, usage, authentication, or access restrictions implemented by Cortlet.

This includes attempts to manipulate identifiers, accounts, organizations, API keys, network requests, or other mechanisms to avoid restrictions that would otherwise apply.

20. Interference With Cortlet

You must not interfere with the normal operation, integrity, security, availability, or performance of Cortlet websites, software, services, APIs, infrastructure, or systems.

You must not knowingly exploit a vulnerability in Cortlet to obtain unauthorized access, disrupt service, or access data that does not belong to you.

21. Vulnerability Disclosure

If you discover a suspected security vulnerability affecting Cortlet, you should report it through Cortlet's designated security or contact channel rather than publicly exploiting or disclosing it in a manner that creates unnecessary risk.

Good-faith security research may be subject to additional vulnerability-disclosure or security-testing terms where Cortlet publishes them.

22. Third-Party Services

Cortlet products may integrate with or communicate with third-party platforms, services, APIs, infrastructure, or networks.

You must comply with applicable third-party terms and may not use Cortlet to bypass restrictions or policies imposed by those third parties.

23. High-Risk and Safety-Critical Uses

Unless Cortlet expressly agrees otherwise in writing, Cortlet products are not designed or certified for uses where failure could reasonably be expected to directly result in death, serious personal injury, or severe physical or environmental damage.

You are responsible for evaluating whether Cortlet is suitable for your intended use and for implementing appropriate safeguards, redundancy, testing, monitoring, and human oversight.

24. Compliance With Export and Sanctions Laws

You may not use Cortlet in violation of applicable sanctions, export-control, trade-control, or similar laws.

You are responsible for determining whether restrictions apply to your location, users, organization, software, data, or intended use.

25. Monitoring and Enforcement

Cortlet may use reasonable technical, operational, security, and abuse-prevention measures to protect its services and enforce this AUP.

Where Cortlet reasonably believes that activity violates this AUP, applicable terms, or law, Cortlet may investigate and take proportionate action.

26. Suspension or Restriction

Cortlet may restrict, suspend, or terminate access to a product, service, account, organization, API key, or other resource where reasonably necessary to address abuse, security risks, legal requirements, or material violations of this AUP.

Where appropriate and legally permitted, Cortlet may provide notice or an opportunity to correct the issue before taking permanent action.

27. Emergency Action

Cortlet may take immediate action without prior notice where reasonably necessary to prevent ongoing harm, respond to a security incident, comply with law, protect users, or preserve the integrity and availability of Cortlet systems.

28. Cooperation With Authorities

Cortlet may respond to lawful requests, court orders, subpoenas, warrants, or other valid legal processes as required by applicable law.

Cortlet does not voluntarily provide user information to third parties except as permitted by applicable law and Cortlet's Privacy Policy.

29. Reporting Abuse

Suspected abuse of Cortlet may be reported through the contact, security, or abuse-reporting information provided on the Cortlet website.

Reports should include enough information for Cortlet to identify and evaluate the alleged activity.

30. Changes to This Policy

Cortlet may update this AUP to reflect changes in its products, security practices, legal obligations, abuse patterns, or operational requirements.

The current version will be published with an updated "Last updated" date. Where required by applicable law, additional notice will be provided.

31. Relationship to Other Terms

This AUP should be read together with the Cortlet Terms of Service, Privacy Policy, applicable software licenses, and any product-specific terms.

If this AUP conflicts with product-specific terms concerning acceptable use, the more specific terms apply to that product to the extent of the conflict.

32. Contact

Questions about this Acceptable Use Policy or reports of suspected abuse may be submitted through Cortlet's designated contact or legal channel.

Additional Cortlet legal policies are available at /legal.