Acceptable Use Policy
Last updated: 31 May 2026
1. Purpose
This Acceptable Use Policy ("AUP") sets out the rules and restrictions that govern your use of the Circinova platform and associated services (the "Service") provided by Circinova (sole trader) ("Circinova", "we", "us") at circinova.com. This AUP is incorporated into and forms part of the Terms of Service at circinova.com/legal/terms.
By using the Service, you agree to comply with this AUP. Violations of this AUP may result in suspension or termination of your account, as described in Section 6 below. If you become aware of any violation of this AUP by any person, please report it as described in Section 5.
This AUP applies to all Customers and Users of the Service, regardless of plan.
2. Acceptable Use
The Service is designed and provided for specific, legitimate business purposes. Acceptable uses include:
2.1 SOC2 Compliance Automation
Using the Service to automate the collection, organisation, and management of evidence required for SOC2 Type I or Type II audits, including: connecting your GitHub organisation and AWS environment to enable automated evidence collection; reviewing and exporting evidence packages for submission to qualified auditors; tracking the status of SOC2 controls over time; and managing remediation tasks arising from control gaps identified through the Service.
2.2 Security Posture Management
Using the Service to continuously monitor and assess the security configuration of your connected cloud and development environments, including: identifying misconfigurations in AWS IAM, S3, VPC, and related services; reviewing repository access controls, branch protection rules, and code review requirements in GitHub; and tracking improvements to your security posture over time.
2.3 Compliance Evidence Collection for Other Frameworks
Where the Service supports additional compliance frameworks (such as ISO 27001 or HIPAA), using the Service to collect and manage evidence for those frameworks within the features made available for that purpose on your current plan.
2.4 Internal Audit and Risk Management
Using the Service to support your organisation's internal audit, risk management, and information security governance activities, including producing reports for internal stakeholders, board presentations, and enterprise risk registers.
2.5 Auditor Collaboration
Using the Service's auditor portal features (where available on your plan) to share evidence packages and compliance artefacts with your appointed external auditors and certification bodies, in a controlled and permissioned manner.
3. Prohibited Activities
The following activities are strictly prohibited when using the Service. This list is not exhaustive and Circinova reserves the right to determine whether conduct not expressly listed here is nonetheless a violation of this AUP.
3.1 Illegal Activities
You must not use the Service to engage in, facilitate, or promote any activity that is unlawful under the laws of England and Wales, the laws of your jurisdiction, or applicable international law. This includes but is not limited to: fraud, money laundering, financing of terrorism, violation of export control laws, or transmission of material that infringes third-party rights.
3.2 Abuse of Platform Resources
You must not:
- Make API requests or database queries at rates that exceed the documented rate limits or that are designed to overwhelm or degrade the performance of the Service for other users
- Use automated tools, scripts, or bots to interact with the Service in ways not expressly permitted by the Documentation
- Attempt to circumvent or bypass any rate limiting, throttling, authentication, or access control mechanisms implemented by Circinova
- Mine or extract data from the Service in bulk or in ways not supported by the Service's official export features
3.3 Circumventing Security Controls
You must not:
- Attempt to probe, scan, or test the vulnerability of the Service or any Circinova infrastructure without express written authorisation from Circinova (see our responsible disclosure process at circinova.com/legal/security)
- Attempt to gain unauthorised access to any part of the Service, other customer accounts, or Circinova's infrastructure
- Introduce or attempt to introduce malware, ransomware, viruses, trojan horses, worms, spyware, or any other malicious code into the Service or any system connected to it
- Use the Service in any way that is intended to interfere with or disrupt the Service or its underlying infrastructure
3.4 Unauthorised Data Collection from Third-Party Systems
The Service connects to your third-party integrations (GitHub, AWS, etc.) to collect compliance evidence from your own organisation's systems. You must not:
- Use the Service to collect data from GitHub organisations, AWS accounts, or other systems that you do not own or have explicit authorisation to access on behalf of the system's owner
- Connect integration credentials belonging to another organisation without that organisation's explicit consent and legal authorisation
- Use the Service to harvest personal data about individuals beyond what is reasonably necessary for legitimate compliance evidence collection within your own organisation
3.5 Sharing Auditor Portal Credentials
Auditor portal access tokens and shared evidence links generated by the Service are intended for secure, controlled sharing with your specific appointed auditors. You must not:
- Post auditor portal URLs, tokens, or shared links in public forums, social media, public GitHub repositories, or any other publicly accessible location
- Share auditor portal access with individuals who are not directly involved in your organisation's audit or compliance process
- Allow auditor portal credentials to remain active beyond the scope and duration of the relevant audit engagement
3.6 Impersonation and Misrepresentation
You must not:
- Impersonate any person or entity, including Circinova employees, auditors, or other customers
- Falsely represent your affiliation with any organisation
- Register an account on behalf of an organisation without authorisation to bind that organisation to Circinova's Terms of Service
- Submit false or misleading information to the Service or to Circinova support
3.7 Uploading Malicious Content
You must not upload, submit, or transmit to the Service any file, code, script, or other material that contains malware, malicious code, or any other content designed to damage, intercept, or interfere with computer systems or data.
3.8 Competitive Intelligence and Reverse Engineering
You must not:
- Use the Service to build a competing product or service that replicates the core functionality of the Circinova platform
- Reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, algorithms, or trade secrets underlying the Service, except to the extent expressly permitted by applicable law
- Use the Service to benchmark it against a competing product for the purpose of publishing competitive comparisons without Circinova's prior written consent
- Use information obtained through the Service to unfairly compete with Circinova
3.9 Spam and Unsolicited Communications
You must not use the Service or any data obtained through the Service to send unsolicited commercial communications (spam) to any individual or organisation.
3.10 Misuse of Credentials and Secrets
You must not:
- Submit integration credentials (such as GitHub OAuth tokens or AWS IAM keys) that have broader permissions than are necessary for the Service to function
- Use Circinova's credentials management features to store secrets unrelated to the integrations supported by the Service
- Attempt to retrieve or access integration credentials stored by the Service outside of the documented API and Service interface
4. Intellectual Property
You must not use the Service in any way that infringes the intellectual property rights of Circinova or any third party. This includes:
- Reproducing, distributing, or publicly displaying any part of the Service, the Documentation, or any reports generated by the Service without authorisation
- Using Circinova's trademarks, logos, or branding in any way that implies an endorsement or affiliation not authorised by Circinova
- Removing or altering any proprietary notices, watermarks, or copyright notices contained in the Service or its outputs
5. Reporting Violations
If you become aware of any actual or suspected violation of this AUP by any person, whether or not they are a Circinova customer, please report it as soon as possible to:
Email: legal@circinova.com Subject line: AUP Violation Report
Please include as much detail as possible, including the nature of the violation, the account or URL involved (if known), and any supporting evidence. Circinova will investigate all reports and take appropriate action. Reports will be treated in confidence to the extent possible.
For security vulnerabilities, please follow our Responsible Disclosure process described at circinova.com/legal/security and contact security@circinova.com.
6. Consequences of Violation
Circinova takes violations of this AUP seriously and will respond proportionately based on the nature and severity of the violation. Possible consequences include:
6.1 Warning
For minor or first-time violations, Circinova may issue a written warning to the Customer's account email address, explaining the nature of the violation and the action required to remedy it. The Customer will be given a reasonable opportunity to address the violation before further action is taken.
6.2 Suspension
For repeated violations, serious violations, or where Circinova determines that immediate suspension is necessary to protect the integrity of the Service or the data of other customers, Circinova may suspend the Customer's access to the Service with immediate effect. Notice will be provided as soon as practicable. During suspension, the Customer will not have access to the Service, but Circinova will retain Customer Data in accordance with the Terms of Service.
6.3 Termination
For egregious violations — including but not limited to: uploading malware, attempting to access other customers' accounts, using the Service for unlawful purposes, or repeated violations following prior warnings — Circinova may terminate the Customer's account immediately without further warning. In such cases, the Customer will not be entitled to any refund of pre-paid fees.
6.4 Legal Action
Where violations of this AUP give rise to civil or criminal liability, Circinova reserves the right to pursue all available legal remedies, including injunctive relief, damages, and referral to law enforcement authorities.
6.5 Circinova's Discretion
The above is a non-exhaustive guide to Circinova's response to violations. Circinova reserves the right to take any action it deems appropriate in its sole discretion, acting reasonably, in response to violations of this AUP.
7. Changes to This Policy
Circinova may update this AUP from time to time to reflect changes in the Service, applicable law, or industry standards. Notice of material changes will be provided to the Customer's account email address and/or displayed within the Service. Continued use of the Service following such changes constitutes acceptance of the updated AUP.
8. Contact
For questions about this AUP or to report a violation:
Circinova (sole trader) Email: legal@circinova.com (general enquiries) Email: legal@circinova.com (to report violations) United Kingdom