Draft for legal review. This document is a starting point written for Responder's counsel to review and complete. It is not in effect and must not be published as-is. Bracketed items need decisions.
Acceptable Use Policy
Last updated [date]
What Responder may and may not be used for.
1. Classified information
Never upload or enter classified national security information of any level. Responder is not authorized for it. If it happens, tell us immediately at [security@…] so we can contain it.
2. Procurement integrity
Don't record, upload or share another offeror's bid or proposal information, or source selection information, obtained in violation of the Procurement Integrity Act (41 U.S.C. 2101–2107; FAR 3.104). Responder asks you to confirm the lawful origin of competitive information that looks like it.
3. Export-controlled data
Don't upload ITAR- or EAR-controlled technical data, or CUI, while Responder runs in commercial AWS. Once it runs in AWS GovCloud (US), upload export-controlled data only if everyone with access to it, including partner guests you invite, is authorized to receive it.
4. Security
- Don't share accounts or bypass multi-factor authentication.
- Don't probe, scan or test the service's security without our written permission ([security@…] for coordinated disclosure).
- Don't upload malware or attempt to access other customers' data.
5. Fair use
Don't use automated means to extract data at volume, resell the service, or use it to build a competing product.
6. Enforcement
We may suspend access that violates this policy, and will tell the organization's admins why and how to resolve it.