# Acceptable Use Policy (AUP)

**Effective date:** 2026-07-27  
**Contact:** hello@doggybagg.cc

This AUP is part of the [Terms of Service](/terms). Violations may result in suspension, credit forfeiture, and reports to authorities or facilitators.

## Allowed

- Buying prepaid credits via x402 for your own agents
- Submitting SQL/DDL you are authorized to test
- Verifying Execution Certificates before your own production writes
- Integrating SQLGuard via documented HTTP/MCP APIs within rate limits

## Prohibited

1. **Abuse of infrastructure** — DDoS, credential stuffing, scraping that degrades service, bypassing rate limits.
2. **Payment fraud** — Attempting to obtain credits without valid settlement; replay of payment proofs; facilitator abuse.
3. **Unauthorized access** — Using others’ agent ids to deplete balances; probing bootstrap or admin interfaces.
4. **Illegal content / activity** — Anything illegal under applicable US law, including CSAM, trafficking, terrorism financing, or sanctions violations.
5. **Hostile SQL against third parties** — Using the Service to plan or validate attacks on systems you do not own or lack written authorization to test.
6. **Misrepresentation** — Claiming PASS certificates are insurance, legal approval, or production guarantees.
7. **Malware / exploits** — Shipping exploit payloads, ransomware kits, or vulnerability weaponization through the Service.
8. **Circumvention** — Reverse engineering payment middleware to steal service without payment (except lawful interoperability research disclosed responsibly).

## Fair use

Automated agents must honor `429` / rate-limit headers. Sustained abuse may be blocked at IP, agent id, or network level.

## Reporting abuse

Email hello@doggybagg.cc with logs, URLs, and timestamps. For security vulnerabilities, follow [SECURITY.md](/security).
