Skip to content

AcceptableUse Policy

Last updated: September 15, 2026

1. Who This Applies To

This policy applies to anyone using this website, and to any client, employee or contractor operating a system XOVO Technologies has built, deployed or hosts. Where you hold a signed contract, this policy sits inside it and your contract governs anywhere the two differ.

Most of what follows is ordinary and would go without saying. The parts that matter are in section 3, because an autonomous system fails differently from ordinary software. A misused web application leaks data. A misused agent takes actions, in a real system, with your authority behind it.

2. General Conduct

Do not use our services or this site to:

  • Break the law, or help anyone else do so, in any jurisdiction that applies to the engagement.
  • Access a system, account or dataset you have not been granted access to.
  • Probe, scan or load-test infrastructure that is not yours, without written permission first.
  • Interfere with another client, another tenant, or the availability of a shared service.
  • Misrepresent who you are, or who an automated message is from.

In the United Kingdom, unauthorised access to a computer system is an offence under the Computer Misuse Act 1990, whoever owns the system and whatever tool was used to reach it.

3. Autonomous Agent Rules

These are the rules specific to agentic systems, and the ones most often broken by accident rather than intent.

Stay inside the authority you actually hold

An agent acts with the permissions of the credentials it is given. Pointing one at a system you are not authorised to change does not make the action authorised, and the audit trail will show your name on it.

Do not route around a guardrail

Prompt injection, jailbreak prompts, and instructions embedded in documents the agent will read are all attempts to make a system act outside its specification. Testing your own deployment for these is expected and welcome. Doing it to bypass a control is not.

Keep the human step where the design has one

Where a workflow routes an action through a person before it commits, that step is a control, not a bottleneck. Removing it after handover changes the risk profile of the system and voids the assumptions the architecture was signed off against.

Do not use an agent for high-stakes decisions it was not scoped for

A system built to draft and rank should not be repurposed to decide alone on employment, credit, housing, insurance or clinical care. Those uses carry legal obligations that attach to the deployment, and a change of purpose needs a change of design.

Volume discipline on outbound

Where a system sends email or messages on your behalf, sending limits, list hygiene and unsubscribe handling exist to keep your sending reputation and ours intact. Overriding them damages deliverability for everyone on the shared infrastructure.

4. Data You Supply

What goes into a system is your responsibility, and it is the single most common source of a compliance problem that surfaces months later:

  • Do not put personal data into a system unless you have a lawful basis to process it for that purpose.
  • Do not supply special category data, health records or data about children unless the engagement was scoped for it, with the safeguards that requires.
  • Do not upload content you do not hold the rights to, including datasets licensed for another use.
  • Do not paste credentials, keys or secrets into a prompt. Use the secret store the engagement provides.

Our side of this is set out in the Privacy Policy and the GDPR page: where we act as your processor, we act on your documented instructions and nothing else.

5. Model Outputs

Output belongs to you, subject to the intellectual property terms in the Terms of Service and to the underlying model provider’s own terms. Within that, there are limits:

  • Do not use outputs to train a model that competes with the system built for you, or with the provider whose model produced them.
  • Do not present machine-generated output as human-written where the context makes that misleading, including reviews, testimonials and correspondence.
  • Do not resell or sublicense access to a system built for your organisation without agreement.
  • Check outputs before acting on them. A model can be fluent and wrong in the same sentence.

6. This Site and Its Content

Ordinary search engine crawling is welcome, and so is quoting our published guides with attribution and a link. Bulk automated scraping beyond that is not, and neither is republishing an article wholesale.

Images and video on this site are licensed, not public domain. The Terms of Service covers how to request permission to use one, and the answer is often yes when you ask.

7. Reporting Misuse

If you believe a system of ours is being misused, or you have found a way to make one act outside its specification, tell us. Reports made in good faith are treated as help rather than as a problem, and we would much rather hear it from you than read about it later.

Security vulnerabilities go to the same address, and the Security page sets out what happens next:

contactus@xovotechnologies.com

8. Enforcement

Most breaches are mistakes, and most are resolved with a conversation. Where one is not, we may restrict a feature, suspend access, or end the engagement under the terms of your contract.

Where data or a production system is at immediate risk we may suspend first and explain afterwards. That is deliberate: the alternative is leaving an active problem running while an email thread catches up with it. We will tell you what happened and why as soon as the risk is contained.

Chat with us on WhatsApp