1. PURPOSE AND SCOPE#
1.1 Why this policy exists. The Groundwork platform assembles working software from descriptions of intent, and renders governed figures on surfaces that people rely on to make operational decisions. Two things follow. First, the Platform can be misused in the ordinary ways any hosted service can be misused. Second, and less obviously, it can be misused by being configured to say something untrue — to present a figure as current when it is not, or to record a decision against a person who did not make it. This policy addresses both.#
1.2 Application. This policy is incorporated into the Groundwork Software License and Subscription Terms (the “Terms”) by the Order Form and forms part of the Agreement. It applies to Customer and to every Authorized User. Capitalized terms not defined here have the meanings given in the Terms and in the Support and Service Level Schedule.#
1.3 Relationship to the Terms. This policy adds to, and does not replace, the restrictions in Section 4.1 of the Terms. Where conduct is addressed by both, both apply.#
1.4 Plain reading. This policy is written to be read by the people who use the Platform, not only by their lawyers. Where a provision is unclear in a particular situation, ask Groundwork before proceeding rather than after.#
2. LAWFUL AND PROPER USE#
2.1 You must not use the Platform to:#
(a) violate any applicable law or regulation, or infringe or misappropriate any third party’s rights;
(b) store, process or transmit material that is unlawful, defamatory, harassing, or that you have no right to submit;
(c) submit special categories of personal data, government identifiers, payment card data, health records, or any data whose handling requires controls beyond those described in the Data Processing Addendum;
(d) conduct any activity in violation of applicable export control or sanctions laws; or
(e) misrepresent your identity, your authority, or your affiliation with any organization.
3. SECURITY AND INTEGRITY OF THE PLATFORM#
3.1 You must not:#
(a) probe, scan or test the vulnerability of the Platform, or breach or circumvent any security, authentication, access control or usage limit, except under a written testing authorization from Groundwork;
(b) introduce malicious code, or any code intended to disrupt, disable, overburden or impair the Platform;
(c) access the Platform other than through the interfaces Groundwork provides and documents;
(d) attempt to access another customer’s data, configuration or environment; or
(e) impose an unreasonable or disproportionate load on the Platform, including through automated, scripted or bulk requests beyond the rates stated in the Documentation.
3.2 Coordinated disclosure. If you discover a security vulnerability, report it to Groundwork promptly and do not disclose it publicly or exploit it. Groundwork will not pursue a claim under this policy against a person who reports a vulnerability in good faith, without exfiltrating data, and without degrading the Platform.#
4. CREDENTIALS AND ATTRIBUTION#
4.1 You must not:#
(a) share credentials, or permit another person to use your account;
(b) use a shared, generic or role-based account to take a governance action, where the Platform offers an individual account;
(c) take a governance action in another person’s name, or hold out an action as having been taken or approved by a person who did not take or approve it; or
(d) configure, modify or operate the Platform so that a governance action is recorded against anyone other than the person who took it, or is not recorded at all.
4.2 Service identities. Where a Surface operates without an interactive session, Customer may use a service identity for that purpose. A service identity must not be used to take or approve a governance action that the Platform attributes to a person.#
5. INTEGRITY OF GOVERNED FIGURES#
5.1 Impairment must not be suppressed. You must not configure, modify or operate the Platform so as to suppress, delay, disguise, override or falsify an Impairment State, or to present a figure or element as current and conforming when it is not.#
5.2 Definitions must be genuine. A definition, formula, threshold, band or cause line configured in the Platform must reflect a genuine operational meaning approved by a person with authority to approve it. You must not set or adjust a threshold for the purpose of preventing a condition from being signaled, rather than for the purpose of describing when that condition obtains.#
5.3 No fabricated authority. You must not present a figure, surface or element as approved, owned or signed off where no such approval, owner or sign-off exists. Where a figure has no owner, the Platform is designed to show that rather than to invent one, and you must not configure it otherwise.#
5.4 No fabricated action path. You must not present an action, instruction or remedy on an operational surface unless a person or team is genuinely accountable for it. An instruction displayed in an operational setting reads as policy to the person reading it.#
5.5 Source integrity. You must not register a Customer Source, or describe a field or mapping, in a way you know or reasonably ought to know to be inaccurate, or in a way that attributes data to a system or owner it did not come from.#
6. OPERATIONAL AND SAFETY LIMITS#
6.1 Not a control system. As stated in Section 5.6 of the Terms, the Platform observes and does not control. You must not use it, or configure it, to control, actuate, command or write back to any operational, safety or industrial control system.#
6.2 Not a regulated control function. You must not use the Platform as a component of a safety instrumented system, an alarm management system, a protective function, or any function subject to a regulatory control regime, including pipeline control functions regulated by the Pipeline and Hazardous Materials Safety Administration.#
6.3 Not a sole indication. You must not configure or rely on the Platform as the sole indication of a safety-critical or regulatory condition, or as the sole system of record where law or regulation requires one.#
6.4 Publication authority. Customer is responsible for determining who may publish to an operational surface, and for ensuring that each such person is competent and authorized to do so. Groundwork records who published; it does not decide who should be permitted to.#
6.5 Notice of changed reliance. Notify Groundwork before placing the Platform into a materially more critical role than that described in the Order Form, so that the deployment posture, availability commitments and support arrangements can be reviewed.#
7. AUTHORING AND INTAKE#
7.1 Describe intent accurately. When describing what you want built, describe it accurately. You must not misdescribe your intent, your role, or the use to which a Solution will be put in order to obtain an assembly you would not otherwise be authorized to obtain.#
7.2 Do not circumvent validation. You must not attempt to bypass, disable or defeat the Platform’s validation of a specification, or to introduce a component, block or rule that has not been vetted through the Platform’s own process.#
7.3 Do not extract the Platform. You must not use an authoring or intake surface to attempt to extract the Platform’s internals, including its prompts, rule libraries, component definitions, manifests or assembly logic. This is a restriction on the manner of use and is separate from, and additional to, Section 4.1(b) of the Terms.#
7.4 Do not automate abusively. You must not submit intake or authoring requests through automated or scripted means beyond the rates stated in the Documentation, or in a manner designed to enumerate the Platform’s capabilities or catalog.#
7.5 Outputs remain your responsibility. A Solution assembled through the Platform is used at Customer’s discretion and on Customer’s responsibility. The Platform validates a specification against its rules; it does not certify that a Solution is fit for a particular operational purpose.#
8. RESPONSIBILITY FOR AUTHORIZED USERS#
8.1 Customer is responsible for compliance with this policy by every Authorized User, including personnel of Customer’s contractors and delivery partners. An act or omission by an Authorized User that would breach this policy if done by Customer is a breach by Customer, as provided in Section 3.3 of the Terms.#
8.2 Make it known. Customer shall make this policy available to each Authorized User before granting access, and shall promptly withdraw access from any person who breaches it.#
9. REPORTING AND ENFORCEMENT#
9.1 Reporting. Report security vulnerabilities to security@groundwork4ai.com and suspected violations or abuse to abuse-reports@groundwork4ai.com. Report suspected inaccuracy in a governed figure through the ordinary support channel, which is the faster route to correction.#
9.2 Enforcement. Groundwork may act under Section 7.3 of the Terms where use violates this policy. Groundwork will use the least disruptive measure reasonably available, will limit any suspension in scope and duration to what is reasonably necessary, and will give notice before suspension where practicable.#
9.3 Operational surfaces. Groundwork recognizes that suspending an Operational Surface may affect a working environment. Except where an immediate and material security risk requires otherwise, Groundwork will notify Customer’s named contacts and allow a reasonable opportunity to remedy before suspending an Operational Surface.#
9.4 Immediate action. Groundwork may act without prior notice where use presents an immediate and material risk to the security or integrity of the Platform, to another customer, or to any person.#
9.5 Cooperation. Customer shall reasonably cooperate in investigating a suspected violation, and shall take prompt steps to stop and remedy any violation it becomes aware of.#
10. CHANGES TO THIS POLICY#
10.1 Updates. Groundwork may update this policy in accordance with Section 1.3 of the Terms. Each version is published at a permanent address with its effective dates.#
10.2 Re-acceptance by users. Where a change to this policy alters what an Authorized User must or must not do, what is recorded about them, how an action is attributed to them, or the route for reporting a problem, Authorized Users will be required to read and accept the updated policy before continuing to use a Governance Surface or an Authoring Surface. Smaller corrections are published without further acceptance.#
10.3 Record of determination. Groundwork records, for each version of this policy, whether the change required re-acceptance under Section 10.2, who made that determination and when. Where a change does not clearly fall outside Section 10.2, it falls within it.#
