Acceptable Use Policy
Last updated: June 9, 2026
Table of Contents
1. Purpose and Scope
This Acceptable Use Policy (“AUP”) governs the use of all products and services provided by LiteSecurity (“LiteSecurity”), including LiteGRC and LiteAI. This policy supplements the Terms of Service and the EULA, and applies to all users and organizations.
2. Prohibited Uses
You may not use LiteSecurity products for any of the following purposes:
General Prohibitions
- Any activity that violates applicable local, state, national, or international laws or regulations
- Sharing, publishing, or distributing your license key to unauthorized parties
- Circumventing license verification mechanisms, usage limits, device counts, or organization counts
- Using the Products to develop, market, or sell a product or service that competes with LiteSecurity's offerings
- Violating export control laws or sanctions regulations
LiteGRC-Specific Prohibitions
- Generating fraudulent, fabricated, or misleading compliance evidence or audit documentation
- Misrepresenting compliance status or audit results to auditors, regulators, or third parties using data produced by the platform
LiteAI-Specific Prohibitions
- Intercepting network traffic from users or systems without proper authorization or consent
- Scanning, probing, or testing systems, networks, or AI services that you do not own or have explicit authorization to test
- Using vulnerability scanning features against third-party systems without written permission from the system owner
3. LiteAI-Specific Rules
LiteAI is a security tool that intercepts and analyzes AI traffic. Given its capabilities, the following rules apply:
Gateway Traffic Interception
The LiteAI gateway must only intercept traffic from users and systems that have been properly consented or authorized within your organization. You are responsible for ensuring that all employees, contractors, or users whose traffic passes through the gateway have been notified and have provided any required consent under applicable law.
DLP Scanning
DLP scanning of prompts and AI traffic must comply with all applicable privacy laws in your jurisdiction, including but not limited to GDPR, CCPA, and applicable employment privacy laws. You are responsible for implementing appropriate notice and consent mechanisms.
LLM Vulnerability Scanning
Vulnerability scanning and security testing features must only be used against AI models and systems that you own or have explicit written authorization to test. Unauthorized scanning of third-party AI services constitutes a violation of this policy and may violate applicable laws.
4. MSP Responsibilities
If you are an MSP licensee managing the Products on behalf of multiple client organizations, the following additional responsibilities apply:
- You are responsible for ensuring that all client organizations using the Products through your MSP license comply with this AUP and the Terms of Service.
- You must communicate this AUP to each client organization and ensure they acknowledge its terms before granting them access.
- LiteSecurity reserves the right to suspend access for individual client organizations or the entire MSP license depending on the nature and severity of a violation.
- If a client organization violates this AUP, you must promptly notify LiteSecurity and take reasonable steps to remedy the violation.
5. Responsible Disclosure
If you discover a security vulnerability in any LiteSecurity product, we encourage responsible disclosure:
- Report the vulnerability to security@litesecurity.net
- Include a detailed description of the vulnerability and steps to reproduce it
- Allow reasonable time for LiteSecurity to investigate and address the issue before public disclosure
- Do not exploit the vulnerability beyond what is necessary to demonstrate it
Safe Harbor
LiteSecurity will not pursue legal action against individuals who discover and report security vulnerabilities in good faith, in compliance with this responsible disclosure policy. Good-faith security research conducted under this policy is considered authorized activity and will not be treated as a violation of this AUP, the EULA's restrictions on reverse engineering, or any applicable anti-hacking laws. This safe harbor does not extend to vulnerabilities in third-party systems or services.
6. Compliance Monitoring
LiteSecurity's ability to monitor compliance with this AUP is limited to license verification data (heartbeat pings containing license ID, product version, and timestamp). We do not monitor your product usage, data, network traffic, or the content processed by the Products. Violations of this AUP are typically identified through reports, audit rights (see EULA Section 9), or license verification anomalies.
7. Enforcement
Curable Violations
For violations that can be remedied (e.g., exceeding licensed device counts, missing user consent notifications), LiteSecurity will provide written notice specifying the violation and a cure period of at least 15 days. If the violation is not remedied within the cure period, LiteSecurity may proceed with suspension or revocation.
Material Violations
For material violations that pose immediate risk (e.g., circumventing license verification, unauthorized redistribution, illegal activity), LiteSecurity may suspend or revoke your license immediately without a cure period. Material violations include:
- Circumventing license verification or usage limits
- Sharing or redistributing license keys
- Using the Products for illegal activity or to generate fraudulent compliance evidence
- Intercepting traffic or scanning systems without authorization
Enforcement Actions
Depending on the nature and severity of the violation, enforcement actions may include:
- Warning notification with a deadline to remedy the violation
- Suspension of your license key and access to Products
- Permanent revocation of your license without refund
- Reporting to appropriate law enforcement authorities where violations involve illegal activity
LiteSecurity reserves the right to determine, in its sole discretion, whether a violation has occurred and what enforcement action is appropriate.
Appeals
If you believe an enforcement action was taken in error, you may appeal by contacting legal@litesecurity.net within 30 days of the action. Include a detailed explanation of why you believe the action was incorrect. LiteSecurity will review the appeal and respond within 15 business days. During the appeal period, enforcement actions remain in effect unless LiteSecurity determines otherwise.
8. Changes to This Policy
We may update this Acceptable Use Policy from time to time. We will provide at least 30 days' notice of material changes via email to the address associated with your account. Your continued use of the Products after the effective date of the updated AUP constitutes acceptance.
9. Contact
To report a violation of this policy or for questions, contact us at abuse@litesecurity.net.