Skip to main content
ColleagueOne
Product
OverviewColleagues & teamsWorkspaceAutomationsConnectionsGovernance & security
Use casesSecurityDocsCompany
Sign inRequest access
ProductUse casesSecurityDocsCompanyRequest accessSign in
Draft — pending legal review

Legal · Responsible use

Acceptable Use Policy

ColleagueOne can browse, create files, use connections, and run scheduled work. These rules keep that power directed toward lawful and authorised business use.

Effective date: [DATE]

On this page

  1. Scope
  2. Illegal or harmful use
  3. Security abuse
  4. Data and identity
  5. High-impact decisions
  6. Automated actions
  7. Enforcement

1. Scope

This Acceptable Use Policy applies to all use of ColleagueOne, its public API, AI colleagues, teams, automations, skills, plugins, files, connections, and outputs. It forms part of theTerms of Service. Customers are responsible for ensuring that their Users and anyone acting through their accounts complies with it.

Use must be lawful, authorised by the relevant organisation, consistent with third-party terms, and subject to meaningful human review appropriate to the risk.

2. Do not use ColleagueOne for illegal or harmful activity

You must not use the Service to:

  • violate a law, court order, regulation, sanctions restriction, or another person’s legal rights;
  • promote, facilitate, or instruct violence, abuse, exploitation, trafficking, or self-harm;
  • create, obtain, or distribute child sexual abuse material or sexual content involving minors;
  • harass, threaten, stalk, defame, or unlawfully discriminate against a person or group;
  • create or distribute malware, ransomware, destructive code, phishing, scams, or fraudulent content;
  • sell, purchase, or facilitate illegal goods, services, weapons, or controlled substances; or
  • infringe intellectual property, privacy, publicity, confidentiality, or contractual rights.

3. Do not attack systems or evade controls

You must not:

  • gain or attempt to gain unauthorised access to an account, system, network, data source, or device;
  • scan, probe, scrape, test, or exploit a third-party system without documented authorisation;
  • bypass approvals, roles, data-classification, DLP, rate, usage, budget, or safety controls;
  • conceal the origin of activity, impersonate another person, or use deceptive authentication details;
  • interfere with the Service, overload infrastructure, or disrupt another customer’s use; or
  • extract non-public service code, prompts, models, or security mechanisms except as law permits.

Good-faith security research must follow ourResponsible Disclosure process. Do not test production systems without prior written authorisation.

4. Protect data, credentials, and identity

You must not:

  • submit data you lack authority or a lawful basis to process;
  • collect, infer, expose, or trade sensitive personal data unlawfully;
  • request or store passwords, secret keys, or authentication tokens in prompts or workspace files when a secure connection should be used;
  • use another person’s identity, likeness, voice, or account to deceive or cause harm;
  • generate deceptive synthetic media without legally required disclosure or consent; or
  • circumvent connected-service permissions or use a connection beyond its authorised purpose.

Customers should apply least-privilege access, choose appropriate model providers, use classifications and DLP policies, and review memory before approving it.

5. High-impact and professional decisions

You must not use ColleagueOne to make a solely automated decision that determines a person’s legal rights or access to employment, housing, education, healthcare, insurance, credit, public benefits, immigration, or another comparably significant service unless the use is lawful, explicitly authorised, appropriately tested, transparent, and subject to qualified human review and an effective appeal process.

Output is not a substitute for legal, medical, financial, accounting, compliance, or other licensed professional judgment. A qualified person must verify Output before it is relied on in those contexts.

6. Automated and external actions

Users must review colleague configurations and use approvals for sensitive actions. You must not configure unattended automations that can create material legal, financial, safety, privacy, or reputational harm without proportionate limits, monitoring, testing, rollback procedures, and human escalation.

Do not send spam, unsolicited bulk communications, deceptive messages, or communications that violate consent, marketing, or platform rules. Respect rate limits and robots directives when browsing or collecting public information.

7. Reporting and enforcement

Report suspected misuse to hello@avapti.com. Security vulnerabilities should be reported to security@avapti.com (placeholder).

We may investigate suspected violations and preserve relevant records. Depending on severity and urgency, we may limit functionality, suspend activity, remove content, or terminate access. Where appropriate, we will notify the Customer and allow a reasonable opportunity to correct the issue. We may report conduct to authorities where legally required or necessary to address imminent harm.

8. Changes and contact

We may update this policy to address new service capabilities, risks, or laws. Material changes will be communicated as required by the applicable agreement or law.

Questions can be sent to hello@avapti.com.

ColleagueOne

AI colleagues that do real work,
under your governance.

Invite-only beta

Product

Colleagues & teamsWorkspaceAutomationsConnectionsGovernance & securityRequest access

Resources

DocumentationAPI referenceChangelogStatus

Company

AboutContactSecurityResponsible disclosure

Legal

PrivacyTermsCookie noticeAcceptable useDPA summarySubprocessors

© 2026 Avapti. All rights reserved.

Built for accountable work.