Acceptable Use Policy
What you may not do with QNSI Cloud — and what happens if you do. Applies to every plan, including the free tier.
Last updated: 2026-07-13 · Effective: 2026-07-13
Draft pending review by qualified counsel. It must not be represented as counsel-approved.
Scope
This Acceptable Use Policy (AUP) applies to all use of QNSI Cloud, the APIs, the SDKs, the CLI, the MCP server, and the developer portals, on every plan including the Free tier. It is incorporated into the Terms of Service. Breach of this AUP is a material breach of those Terms.
Prohibited uses
- Unlawful activity, or activity that facilitates unlawful activity, in any jurisdiction that applies to you or to us.
- Attacking, probing, scanning, or attempting to breach QNSI infrastructure, other tenants, or any third party — except in an engagement we have authorised in writing (see the Vulnerability Disclosure Policy for the authorised path).
- Circumventing or attempting to circumvent tenant isolation, crypto-policy enforcement, entitlement checks, quotas, or the audit trail.
- Using the platform to store, process, or transmit malware, ransomware payloads, or command-and-control infrastructure.
- Using QNSI's cryptographic operations to conceal criminal conduct, to operate a service whose purpose is to evade lawful process, or to facilitate sanctions evasion.
- Uploading content you do not have the right to process, or processing personal data without a lawful basis.
- Reselling, sublicensing, or providing the service to a third party as a competing offering, except under a written reseller agreement.
- Automated activity that degrades service for other tenants, including exceeding published rate limits by evasion rather than by entitlement.
- Deliberately misrepresenting QNSI's conformance evidence, certifications, or capabilities to a third party.
Security-research carve-out
We want the platform tested. Good-faith security research conducted within the scope and safe-harbour of our Vulnerability Disclosure Policy is NOT a breach of this AUP. Testing outside that scope — against other tenants, against production data you do not own, or in a way that degrades service — is.
Enforcement
Where we identify a breach we will, proportionate to the risk: contact you, throttle or suspend the offending workload, suspend the account, or terminate it. Where there is an imminent risk to other tenants, to the integrity of the audit chain, or to key material, we may suspend first and notify immediately after.
Report abuse: qnsi-security@heossi.com.