Acceptable Use Policy
Last updated: July 2026
This Acceptable Use Policy ("AUP") governs the use of the Proxara services (the "Service"): Proxara Connect, the hosted connector, and Endpoint Protection, the device agent, each as provided by Proxara, Inc. This AUP is incorporated into and forms part of the Master Subscription Agreement (the "Agreement").
By using the Service, Customer and its Authorized Users agree to comply with this AUP. Capitalized terms not defined herein have the meanings set forth in the Agreement.
1. General Obligations
Customer shall use the Service solely for its internal business purposes in accordance with the Agreement, the Documentation, and applicable law. Customer is responsible for ensuring that all Authorized Users comply with this AUP.
2. Prohibited Uses
Customer and its Authorized Users shall not:
2.1 Unlawful or Harmful Activity
- Use the Service for any purpose that violates applicable federal, state, local, or international law or regulation.
- Use the Service to process data that Customer does not have lawful authority to process.
- Use the Service in a manner that infringes, misappropriates, or violates any third party's intellectual property rights, privacy rights, or other legal rights.
2.2 Circumvention
- Attempt to circumvent, disable, or interfere with the Service's redaction, classification, monitoring, or governance capabilities, including the device-level network proxy, the MCP observability layer, the connector's policy enforcement, and any associated certificates or network controls.
- Instruct or encourage Authorized Users to evade or bypass the Service's controls.
- Remove, distrust, or tamper with the device proxy's root certificate authority when deployed via MDM. The CA is name-constrained to AI service domains; it cannot issue certificates for banking, healthcare, government, or authentication services.
- Alter, tamper with, or falsify audit logs, signed audit events, classification results, or other outputs of the Service. Modification of signed records is detectable through signature verification and breaks the per-tenant hash chain.
- Reconfigure MCP server governance settings (egress mode, block/quarantine status) outside of the compliance console, or otherwise act around the compliance officer's authorization for a downstream MCP server.
- Attempt to extract, reverse, or correlate stand-in mappings: including prompting an AI assistant to reveal the identity behind a stand-in, copying stand-ins between conversations or contexts to probe for resolution, or attempting to access the stand-in vault outside the Service's authorized paths.
- Use, or attempt to use, another employee's Microsoft grant, connection, or session to retrieve or act on data through Proxara Connect.
- Plant instructions in mail, documents, messages, or other content with the intent that an AI assistant retrieving that content through the Service will execute them (prompt injection), or otherwise attempt to make retrieved content act as instructions.
2.3 Unauthorized Access
- Attempt to access any portion of the Service, Customer infrastructure, or third-party systems to which the user is not authorized.
- Share API keys, console credentials, or authentication tokens with unauthorized persons.
- Probe, scan, or test the vulnerability of the Service without Proxara's prior written consent.
2.4 Interference
- Introduce viruses, worms, malicious code, or any other software intended to damage or interfere with the Service.
- Overload, flood, or otherwise impair the availability or performance of the Service through excessive automated requests, denial-of-service attacks, or similar means.
- Reverse engineer, decompile, disassemble, or attempt to derive the source code, algorithms, or data models of the Service, except to the extent expressly permitted by applicable law.
2.5 Misrepresentation
- Impersonate any person or entity, or falsely represent an affiliation with any person or entity, in connection with the Service.
- Submit deliberately misleading test data to manipulate classification outcomes or performance metrics.
2.6 Resale or Redistribution
- Resell, sublicense, redistribute, or otherwise make the Service available to any third party without Proxara's prior written consent.
- Use the Service to provide managed services or bureau services to third parties, except where Customer is an authorized Managed Service Provider under a separate agreement.
3. Customer Responsibilities
3.1 Employee Notification
Before deploying the Service, Customer shall provide adequate notice to all Authorized Users that their interactions with external AI tools may be monitored, reviewed, and subject to automated redaction. Customer shall comply with all applicable employee monitoring laws (see Employee Monitoring Disclosure Template).
3.2 Data Processing Authorization
Customer shall ensure that all data processed through the Service is data that Customer is authorized to process under applicable law and contractual obligations, including any required data protection agreements with its own personnel or third parties.
3.3 Fleet Management and Configuration
Customer is responsible for selecting the appropriate industry profile, configuring retention policies, and maintaining the security of credentials and console accounts. Where Endpoint Protection is deployed to employee devices, Customer shall manage installation, updates, and removal through its MDM platform (Jamf, Intune, Kandji, or compatible). Where Proxara Connect is deployed, Customer is responsible for administering its own AI-assistant workspace and Microsoft tenant, including which employees are enabled, the permissions its employees hold in Microsoft 365 (which bound what the connector can retrieve), and, where Customer requires that all connected source access run through Proxara, disabling overlapping native connectors in the AI host's own settings. For Proxara-Managed deployments, Proxara provisions and manages the dedicated AWS environment; Customer receives read-only access to the compliance console and is not responsible for infrastructure maintenance. For Customer-Managed deployments, Customer is responsible for the infrastructure it controls.
3.4 End User Conduct
Customer shall take reasonable steps to ensure that Authorized Users understand and comply with this AUP. Customer is responsible for the actions of its Authorized Users.
4. Enforcement
4.1 Investigation
Proxara may investigate suspected violations of this AUP. Customer shall cooperate with any reasonable investigation.
4.2 Remedies
If Proxara determines that a violation has occurred, Proxara may, in its reasonable discretion:
- Notify Customer of the violation and request remediation within a specified timeframe.
- Suspend access to the Service (in whole or in part) until the violation is remediated, with reasonable advance notice except where immediate suspension is necessary to prevent harm.
- Terminate the Agreement in accordance with the applicable termination provisions of the Master Subscription Agreement if the violation constitutes a material breach that is not cured within the applicable cure period.
4.3 No Obligation to Monitor
Proxara is not obligated to actively monitor Customer's use of the Service for violations of this AUP but reserves the right to do so.
5. Reporting Violations
If you become aware of a violation of this AUP, or of any security concern related to the Service, please report it to security@proxara.ai.
6. Changes to This Policy
Proxara may update this AUP from time to time. Proxara will notify Customer of material changes at least thirty (30) days in advance. Continued use of the Service after the effective date of any changes constitutes acceptance of the updated AUP.