Kanvify

Acceptable Use Policy

Last updated: July 20, 2026

1. Scope and Responsibility

This Acceptable Use Policy (“AUP”) applies to Kanvify (the “Service”), operated by Plus Ultra Industries, LLC, and is incorporated into the Terms of Service. It applies to every account, workspace, sandbox, API client, integration, inside-sandbox process, automated agent, and person acting under your credentials or authority.

You are responsible for activity initiated by your users, agents, scripts, integrations, and credentials. You must use the Service only for lawful purposes and must ensure your authorized users comply with this AUP.

2. Prohibited Uses

You must not use the Service to:

  • Violate law, facilitate fraud, or infringe another person’s rights
  • Mine cryptocurrency or run proof-of-work, proof-of-space, token farming, airdrop farming, or similar compute-farming workloads
  • Launch denial-of-service attacks, unauthorized port or vulnerability scans, brute-force activity, credential stuffing, or penetration testing of a system you are not expressly authorized to test
  • Send spam or unsolicited bulk messages, phish, distribute malware, operate command-and-control infrastructure or botnets, or provide an open proxy or relay
  • Escape or attempt to escape sandbox isolation; access a host, another tenant, or another person’s data; or evade tenant boundaries
  • Circumvent or tamper with metering, quotas, spend caps, rate limits, authentication, network policy, or security controls
  • Obtain, test, collect, sell, expose, or use passwords, API keys, session tokens, private keys, personal data, or other secrets without the owner’s explicit authorization
  • Interfere with or create an unreasonable burden on the Service, providers, networks, or other customers
  • Use a customer-provided LLM route in violation of the selected provider’s terms or policies, or to create illegal content or materially facilitate serious harm
  • Host, transmit, or distribute unlawful, defamatory, deceptive, infringing, or exploitative material
  • Operate anonymization, residential-proxy, traffic-forwarding, relay, or similar infrastructure to facilitate abuse, conceal prohibited activity, evade provider controls, or obstruct an investigation
  • Resell or sublicense raw Service access or compute capacity without our prior written permission
  • Reverse engineer or attempt to derive non-public source code except to the extent applicable law expressly permits it

High-risk security research, malware analysis, credential testing, regulated-data processing, mass scraping, high-volume messaging, and proxy services require our prior written approval even when the underlying activity may be lawful.

3. Third-Party Providers

If you enable a third-party integration or a customer-provided Anthropic or OpenAI route, you must comply with the provider terms and usage policies applicable to your account. You supply and control the LLM provider credential and pay the provider directly. Workspace aliases or fallbacks may select a different model or provider only as configured by the workspace.

4. Security Testing

Permission to use Kanvify is not permission to test Plus Ultra, another customer, a provider, or any third-party asset. This AUP does not authorize vulnerability scanning, penetration testing, sandbox-escape testing, load testing, or other security research against Plus Ultra systems.

Before testing Kanvify itself, request written authorization from security@plusultra.industries and wait for an approved scope. A report of an accidentally discovered vulnerability is welcome, but you must stop when you encounter another person’s data, gain unintended access, or affect availability. Do not exfiltrate data, establish persistence, conduct social engineering, or send malware or live credentials by email.

5. Abuse Reports

Report suspected abuse to abuse@plusultra.industries. Include, where available:

  • The account, workspace, sandbox, request, IP address, or other resource identifier
  • A concise description of the activity and why it may violate this AUP
  • Relevant timestamps and time zone
  • Redacted headers, logs, screenshots, or other evidence
  • Contact information for follow-up

Do not send malware, illegal content, live credentials, or unnecessary personal information. We may ask for a safer transfer method if additional evidence is needed.

6. Monitoring and Investigation

We monitor for and may investigate and act on suspected abuse. Monitoring can include rate-limit events, account and usage records, network-policy data, operational logs, and reports. We do not claim automated cryptomining or attack detection, and we do not guarantee that we will identify every violation.

You must reasonably cooperate with an investigation involving your account, including identifying authorized activity, containing harmful workloads, and preserving relevant evidence after a lawful preservation request. We will seek to minimize access and disclosure consistent with security, legal, and enforcement needs.

7. Enforcement

When we reasonably believe activity violates this AUP or creates a security, legal, or operational risk, we may throttle traffic, revoke credentials, isolate or suspend a sandbox, block supported actions, disable an integration, restrict a workspace, preserve relevant evidence, or suspend or terminate an account.

We may act without prior notice where reasonably necessary to stop ongoing harm, protect the Service or others, preserve an investigation, respond to a provider, or comply with law. Where appropriate, we may ask for remediation before restoring access and may refer activity to a provider or competent authority.

Repeated violations, a pattern of abusive resources, failure to remediate, failure to cooperate, or evasion of a restriction may lead to broader or permanent suspension or termination.

8. Review of an Enforcement Action

You may request review by emailing abuse@plusultra.industries with the affected resource and why the action was mistaken or how the issue was remediated. A request does not automatically pause an action. Review may be limited where law prohibits disclosure, an investigation must be protected, or continuing risk requires the restriction to remain. Statutory rights that cannot be waived remain available.

9. Changes and Contact

We may update this AUP. We post changes with an updated effective date and make reasonable efforts to notify affected users. Emergency changes addressing security, abuse, provider, or legal requirements may take effect when posted.

Abuse reports and enforcement reviews: abuse@plusultra.industries

Security vulnerabilities and authorization requests: security@plusultra.industries

Policy and legal questions: legal@plusultra.industries