# Acceptable Use Policy

> What customers and users must not do with the Ward service, including monitoring beyond legitimate security purposes and attacking the service.

Effective date: 10 October 2026.

## Purpose

Ward is built to protect company data in the browser while collecting as little about people as possible. This policy applies to every customer, administrator and user of the Ward service and forms part of our [Terms of Service](https://valvayn.com/legal/terms/).

## You must not

- Deploy Ward on browsers or devices you are not entitled to manage, or without the notices and consultations the law requires.
- Use Ward to monitor individuals for purposes other than protecting your organisation’s data and systems, or in breach of employment, privacy or data protection law.
- Configure Ward — for example custom detectors, justification prompts or webhooks — to capture content, credentials or personal data beyond what the Service is designed to collect.
- Attempt to access another organisation’s data, bypass tenant isolation, or probe, scan or test the Service except under our [responsible disclosure policy](https://valvayn.com/security/disclosure/).
- Interfere with or overload the Service, or circumvent its rate limits or security controls.
- Reverse engineer the Service except as the law allows, or resell or share access without our agreement.
- Use the Service to break the law, including export control and sanctions laws.

## Enforcement

We may suspend access that breaches this policy, as described in the [Terms of Service](https://valvayn.com/legal/terms/). Report suspected misuse to legal@valvayn.com.

---

Canonical: https://valvayn.com/legal/acceptable-use/ · Markdown: https://valvayn.com/legal/acceptable-use.md · Built: 2026-10-10
