Acceptable Use Policy

Last updated: September 23, 2026

This Acceptable Use Policy governs how TokenUity may be used and is incorporated into the Terms of Service. It reflects the tiered, pay gated, enterprise only design of the Platform.

1. Acceptance & Relationship to the Terms

This Acceptable Use Policy (this “AUP”) is incorporated into and forms part of the Terms of Service. Capitalized terms used but not defined here have the meaning given in the Terms. By accessing or using TokenUity (the “Platform”), you agree to comply with this AUP. TokenUity LLC (“TokenUity”, “we”, “us”) may update this AUP from time to time; material changes are reflected by the “Last updated” date.

2. Permitted Use

You may access and use the Platform solely for your internal business purposes of ESG, FinOps, and attribution analysis, within the scope of the package and seat entitlements you have purchased, and only through the access credentials issued to you or your organization members. Use of the Platform is limited to members who have been provisioned through the pay then register or invitation flow and who maintain an active, paid subscription (or, for evaluators, a valid procurement docs access link).

3. Prohibited Uses

  • Reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, models, weighting logic, detector rulesets, or internal structure of the Platform or its client side calculation engines.
  • Reidentify, deanonymize, or attempt to decode any opaque Member ID, one way hash, salt, or other pseudonymized metadata produced or stored by the Platform.
  • Attempt to decrypt, access, or recover any vault entry, encrypted report snapshot, or passphrase derived key that does not belong to you or your organization.
  • Access, probe, or attempt to access another member's, another organization's, or TokenUity's data, accounts, or infrastructure without explicit authorization.
  • Circumvent, disable, or evade any access control, entitlement limit, seat cap, rate limit, anti abuse control, or Turnstile verification mechanism; provided, however, that an authorized headless agent session (under an Agentic plan or an enterprise organization's Bring Your Own Agent entitlement) minted through the Platform's designated headless session endpoint is an operator sanctioned exception that substitutes server side signed token verification for the human Turnstile widget, and the standing down of client side deterrents for that session is not a circumvention under this Section, while all server side controls (authentication, row level security, rate limits, and seat entitlements) remain fully enforced.
  • Overload, disrupt, or impair the Platform or its underlying infrastructure, including by way of automated scraping, volumetric requests, denial of service, or stress testing; automated access via a sanctioned headless session (under an Agentic plan or an enterprise organization's Bring Your Own Agent entitlement) is permitted within your purchased seat entitlements to drive the Platform's calculators, reviewers, and reporting, but systematic or volumetric extraction of Platform data or content by any means remains prohibited.
  • Introduce or transmit malware, ransomware, backdoors, logic bombs, or any malicious code through any input, upload, or integration path.
  • Use the Platform to process, store, or transmit content that is unlawful, infringing, defamatory, or abusive, or that violates any applicable law or third party right.
  • Use the outputs, reports, or modeling results of the Platform as the sole basis for securities trading, investment advice, or regulatory disclosures without independent verification and, where required, appropriate professional qualification; the Platform provides internal analytical estimates, not audited financial or legal advice.
  • Use the Platform, its outputs, or its documentation to train, fine tune, evaluate, or benchmark any competing machine learning model, AI product, or intelligence service.
  • Redistribute, resell, sublicense, lease, or otherwise transfer access to the Platform or any report snapshot to a third party outside your purchased seat entitlements.
  • Share your authentication credentials, vault passphrase, or procurement docs access link with any person other than the authorized member, or permit concurrent use of a single seat by more than one individual.
  • Use the Platform in violation of applicable export control, sanctions, or anti bribery laws, or in connection with any activity prohibited under U.S. or Maryland law.
  • Input, upload, or process on the Platform any regulated personal data (including PHI regulated by HIPAA, nonpublic personal information regulated by the Gramm Leach Bliley Act, or student education records regulated by FERPA), as prohibited by Section 7 of the Terms of Service. No PHI, HIPAA, GLBA, or FERPA regulated data is processed; any such data that reaches the Platform is hashed and purged and never persisted.
  • Initiate a friendly fraud chargeback as defined in Section 11 of the Terms of Service; a first occurrence is recorded as a warning strike with access retained, and a second occurrence results in permanent termination and blacklisting under that Section.

4. Security & Credentials

You are responsible for safeguarding all credentials and vault passphrases associated with your organization's use of the Platform. Your Sync Vault is end to end encrypted under a passphrase that never leaves your device, so TokenUity cannot recover a lost passphrase or decrypt vault contents on your behalf; other data you save (calculation records, compensation profiles, and aggregate metrics) is stored on Platform servers under row level access control and is not passphrase gated. You must promptly notify TokenUity through the in app Report an Issue channel of any suspected or actual unauthorized access, credential compromise, or misuse of which you become aware.

5. Enforcement

Violation of this AUP may result in immediate suspension or termination of your access, your organization's access, and any associated subscriptions, at TokenUity's sole discretion, without prior notice or warning. Where TokenUity elects to suspend rather than terminate, reinstatement is not guaranteed. Nothing in this AUP limits TokenUity's other rights or remedies under the Terms or applicable law. Your Sync Vault is end to end encrypted, so termination does not give TokenUity access to your vault contents; your server side data (calculation records, compensation profiles, and aggregate metrics) is subject to the automated data erasure process described in Section 13 of the Terms of Service. You remain responsible for exporting or deleting any vault contents you wish to retain before or after termination.

6. Reporting Violations

To report a suspected violation of this AUP, or to report suspected misuse by any member, use the in app Report an Issue feature with the category set to Security or Access. TokenUity will review good faith reports and, where appropriate, take action under Section 5.

7. No License to Violations

TokenUity's failure to enforce any provision of this AUP, or its decision to allow a limited exception in a particular case, does not constitute a waiver of TokenUity's right to enforce this AUP or the Terms in that or any other instance.

8. Changes to This AUP

We may update this AUP from time to time to reflect changes in the Platform, applicable law, or acceptable use norms. Material changes will be reflected by the “Last updated” date and, where required, communicated to registered users. Continued use of the Platform after a change constitutes acceptance of the revised AUP.

© 2026 TokenUity™ · Zero trust · End to end encrypted