Draft for attorney review — not yet in force.
AssemblyWright AI — Acceptable Use Policy
Effective date: [DATE]
This Acceptable Use Policy ("AUP") is part of the AssemblyWright AI Terms of Service. It applies to you, to every user in your Workspace, and to anyone acting through your credentials. If you let someone use the Service through you, their conduct is your responsibility.
The short version: AssemblyWright reads and writes real business systems on your instruction. Do not point it at a system you are not authorized to change, and do not use it to produce or deploy anything illegal, harmful, or deceptive.
1. Authorization to touch a system — the rule that matters most
You may connect a CRM instance to the Service only if:
- you own it, or you are engaged by its owner and authorized in writing to make changes to it;
- connecting it does not breach your agreement with your CRM vendor or with the org's owner;
- the credentials you supply were issued to you for this purpose and grant the narrowest permissions the work needs.
You may not:
- connect an org belonging to a client, employer, or third party without that party's authorization;
- use credentials belonging to someone else, or a shared credential whose owner has not agreed to this use;
- use the Service to bypass a control, approval process, or change-management requirement your organization or your client has in place;
- deploy to a production org anything you have not reviewed, or anything you have been told not to deploy.
We cannot verify your authorization, and we do not try to. The Service acts on the credentials you give it. That is why this section is first.
2. Do not break the law or harm people
You may not use the Service, or content produced by it, to:
- violate any applicable law or regulation, or facilitate doing so;
- infringe a patent, copyright, trademark, trade secret, or other right;
- exfiltrate, sell, or misappropriate data from a system you do not have the right to take it from;
- build, document, or deploy a system whose purpose is fraud, unlawful discrimination, illegal surveillance, or harassment;
- generate content that sexually exploits a minor, is non-consensual intimate imagery, threatens or incites violence, or promotes terrorism — the first of these we report to the appropriate authorities and terminate immediately, without notice or cure;
- violate export control or sanctions law, or use the Service from an embargoed jurisdiction or as a restricted party.
3. Do not put regulated or hazardous data in the Service
The Service is not designed, certified, or sold for:
- protected health information subject to HIPAA — we will not sign a Business Associate Agreement;
- payment card data subject to PCI DSS;
- government-classified or export-controlled technical data;
- children's personal information subject to COPPA;
- biometric identifiers, financial account credentials, or full government identity numbers;
- data whose handling requires a certification we do not hold. We hold none.
Keep this in mind when importing org context and seeding test data, which are the two operations most likely to pull production records into the Service. Where your org holds regulated data, scope the import and use masked or synthetic data.
You may not use the Service where its failure could cause death, personal injury, or severe environmental damage — including aircraft or vehicle control, life support, nuclear facilities, or emergency dispatch.
4. Use the review gates — do not defeat them
The Service is a governed pipeline. You may not:
- present an unreviewed Deliverable to a client or a regulator as reviewed;
- configure the product to remove human checkpoints on work that materially affects a production system, and then rely on us for the outcome;
- deploy to production a change whose pre-flight warnings you did not read;
- use the Service to mass-generate documentation you have no intention of reviewing, in order to satisfy an audit or a contract requirement by volume.
AI output can be wrong. The gates exist so that a person decides. Turning them down is your choice and your risk.
5. Do not attack the Service
You may not:
- attempt to access another Workspace's data, another customer's Connected Org, or any system or credential you were not given;
- probe, scan, or test the vulnerability of the Service except by reporting to security@assemblywright.ai — good-faith research reported responsibly is welcome and we will not pursue you for it;
- circumvent or interfere with authentication, roles, rate limits, spend ceilings, entitlements, metering, or the audit trail;
- introduce malware or destructive code, including inside a Knowledge Base entry, a prompt, or a skill definition;
- attempt prompt injection against the pipeline, including by planting instructions in org data or Knowledge Base content intended to make a Wright take an action a person did not authorize;
- overload the Service with automated traffic beyond documented limits, or use it to generate abusive load against your CRM vendor's API;
- reverse engineer, decompile, or derive source code, except where law expressly permits and only to that extent;
- resell, sublicense, or provide the Service to a third party as a bureau service without a written agreement from us, or share one Workspace across organizations to avoid entitlements.
6. Do not misuse the AI features
You may not use the Service's AI to:
- generate content prohibited elsewhere in this AUP;
- attempt to extract model weights, system prompts, or another customer's content;
- circumvent a model provider's safety systems;
- generate deceptive material presented as human-authored where that presentation would be unlawful or materially misleading;
- produce legal, medical, financial, or safety-critical advice that you then pass on as reviewed when it was not.
7. Spend and metering
You may not manipulate metering, budget brakes, or entitlement checks, or run automated Builds whose purpose is to exhaust an allowance, degrade service for others, or resell model access. Spend controls protect both of us; defeating them is a breach.
8. Enforcement
What we may do. Where we believe this AUP has been violated, we may disable a specific connection, feature, or user, suspend a Workspace, or terminate the Agreement.
Notice and cure. Where the violation does not present an ongoing risk of harm, we will give notice and a reasonable opportunity to cure first. Where it does — an active attack, a legal order, an unauthorized org connection causing damage, prohibited content — we act first and tell you as soon as we can.
Proportionality. We prefer the narrowest action that stops the harm: disabling one connection before suspending a Workspace.
No monitoring obligation. We do not review Customer Data as a matter of course, and nothing here creates an obligation to monitor. Acting on one report does not oblige us to act on any other.
Refunds. Fees are not refunded for a suspension or termination caused by your violation.
Your data on termination for cause. You keep the 30-day export window in the Terms, unless retaining or returning the data would itself be unlawful.
9. Reporting
- Abuse or a violation of this policy: legal@evadaroo.com
- Security vulnerabilities: security@assemblywright.ai
- Copyright (DMCA): legal@evadaroo.com, addressed to the Copyright Agent, Evadaroo & Company, LLC, [REGISTERED OFFICE ADDRESS], with the elements required by 17 U.S.C. § 512(c)(3). We honor counter-notices under § 512(g) and terminate repeat infringers.
10. Changes
We may update this AUP. Material changes get 30 days' notice to Workspace owners, except where a change is required immediately by law or to stop an active harm.
Evadaroo & Company, LLC · [REGISTERED OFFICE ADDRESS] · Pennsylvania, USA · legal@evadaroo.com