This policy is written in plain language for transparency. It does not reduce rights or obligations that applicable law does not permit the parties to change.
1. Use the Services lawfully and safely
You may use the Services only for lawful, authorized business purposes and within your assigned organization, role, subscription, documented API scope, and technical limits.
2. Prohibited activity
- Accessing, testing, enumerating, exporting, modifying, or attempting to discover another organization’s data or identifiers without express written authorization from RestoreCheck IQ and the affected customer.
- Circumventing authentication, two-factor controls, role checks, rate limits, tenant scope, audit logging, retention controls, or other security measures.
- Sharing credentials, API keys, authenticator seeds, activation links, or recovery information; embedding platform-owner credentials in an organization automation; or using credentials after authorization ends.
- Uploading malware, unlawful content, information obtained without authority, or data that creates disproportionate risk without an agreed safeguard plan.
- Using the Services to harass, discriminate, defraud, mislead, surveil unlawfully, infringe rights, interfere with claims, or make unlawful automated decisions.
- Scanning, penetration testing, load testing, reverse engineering, scraping, or vulnerability exploitation without prior written authorization and a defined safe scope.
- Disrupting availability, sending abusive traffic, bypassing usage controls, or using the Services to operate competing hosted functionality.
- Removing proprietary notices, misrepresenting platform outputs as independently certified, or using the marks in a way that suggests endorsement.
- Connecting an AI or automated agent that has broader access than its human sponsor, mixes tenant data, retains data outside approved systems, trains on Customer Data without authority, or executes high-impact actions without human approval.
3. Enforcement and reporting
We may investigate suspected violations, preserve relevant evidence, restrict a token or account, or suspend the minimum necessary access. We will consider severity, intent, recurrence, customer impact, legal duties, and opportunities to cure. Illegal or dangerous activity may be reported where required or appropriate.
Report abuse to security@restorecheckiq.ca. Good-faith security research must be authorized before testing production.