# Acceptable Use Policy (AUP)

**Effective date:** 2026-07-31  
**Operator:** SQLGuard Inc / DoggyBagg  
**Contact:** hello@sqlguard.io  
**Related:** [Terms](/terms) · [Security](/security) · [Disclaimer](/disclaimer)

This AUP is part of the [Terms of Service](/terms). Violations may result in suspension, credit/Session/Pilot forfeiture, and reports to authorities or facilitators.

## Allowed

- Buying commercial licences and Exact SKUs for your own lawful agents (Gateway invoice, Pilot Challenge unlock, Gateway Pilot, and legacy Session/Workday/Instant/Bind/credits as listed live)
- Submitting SQL/DDL/mandate text you are authorized to process
- Verifying Execution Certificates / calling free `/v1/gate` or `/v1/gateway/decide` before **your own** production writes
- Integrating SQLGuard via documented HTTP/MCP APIs within rate limits
- Operating autonomous agents that use the Service **if** their use is lawful and you accept full responsibility for their spends and writes
- Good-faith security research disclosed per [Security](/security)

## Prohibited

1. **Abuse of infrastructure** — DDoS, credential stuffing, scraping that degrades service, bypassing rate limits.
2. **Payment fraud** — Obtaining credits/certs/Pilot slots without valid settlement; replay of payment proofs; facilitator abuse.
3. **Unauthorized access** — Using others’ agent ids to deplete balances; probing bootstrap or admin interfaces.
4. **Illegal content / activity** — Anything illegal under applicable US law, including CSAM, trafficking, terrorism financing, sanctions evasion, or export violations.
5. **Hostile SQL against third parties** — Using the Service to plan or validate attacks on systems you do not own or lack written authorization to test.
6. **Misrepresentation** — Claiming PASS, BIND, GATE, DENY, Challenge, or Session/Pilot artifacts are insurance, legal approval, KYC, human attestation, SOC 2 evidence, or production guarantees.
7. **Malware / exploits** — Shipping exploit payloads, ransomware kits, or vulnerability weaponization through the Service.
8. **Circumvention** — Reverse engineering payment middleware to steal service without payment (except lawful interoperability research disclosed responsibly).
9. **Mandate fraud** — Submitting Intent Mandates you know are forged, stolen, or exceed the authority you actually have.
10. **Crime facilitation** — Using authorize tooling to assist fraud, ransomware deployment, or other criminal schemes.

## Fair use

Automated agents must honor `429` / rate-limit headers. Sustained abuse may be blocked at IP, agent id, or network level.

## Reporting abuse

Email hello@sqlguard.io with logs, URLs, and timestamps. For security vulnerabilities, follow [Security](/security).
