Legal

Acceptable Use Policy

The rules for using TrustFix responsibly — what is prohibited, how security testing must be conducted, and how we enforce these terms.

Pending legal counsel review. This document is a working draft provided for transparency. It has not yet been reviewed by qualified legal counsel and is not yet a binding agreement. Do not rely on it as legal advice. The definitive, executed version will be made available before it takes effect.

Last updated: June 25, 2026

1. Purpose

This Acceptable Use Policy ("AUP") governs your use of the TrustFix service operated by Vikavi Security LLC ("TrustFix", "we"). It is incorporated into and supplements the TrustFix Terms of Service. By using the Service, you agree to follow this AUP. Capitalized terms not defined here have the meaning given in the Terms of Service.

TrustFix is a security tool. Because it operates on sensitive identity and infrastructure configuration, misuse can cause real harm. This policy exists to keep the Service safe for everyone who relies on it.

2. Authorization: scan only what you own

You may use the Service only against cloud accounts, repositories, and systems that you own or are explicitly authorized to assess. You are solely responsible for ensuring you have that authorization before connecting any account or initiating any scan.

You must not use the Service to scan, probe, or analyze systems belonging to a third party without that party’s documented permission.

3. Prohibited uses

You must not use the Service to:

  • Access, scan, or attempt to access any account, repository, or system you are not authorized to access.
  • Violate any applicable law or regulation, or infringe the rights of any third party.
  • Probe, scan, or test the vulnerability of the TrustFix platform itself, or breach or circumvent its security or authentication measures, except under an authorized program as described in Section 4.
  • Interfere with or disrupt the integrity or performance of the Service, including by overwhelming it with requests, or attempt to gain unauthorized access to other customers’ data.
  • Reverse engineer, decompile, or attempt to derive the source code or underlying detection algorithms of the Service, except to the extent this restriction is prohibited by law.
  • Resell, sublicense, or provide the Service to third parties except as expressly permitted in writing.
  • Use the Service to develop a competing product, or to misrepresent TrustFix output, attestations, or receipts as covering systems they do not.
  • Upload or transmit malware, or use the Service to facilitate any unlawful, fraudulent, or harmful activity.
  • Use automated means to extract data from the Service except through documented APIs and within the limits set out below.

4. Security research and responsible disclosure

We welcome good-faith security research into the TrustFix platform. If you wish to test the security of TrustFix itself, contact us first at security@trustfix.dev so we can authorize and coordinate the testing. Unauthorized testing against TrustFix infrastructure is prohibited under Section 3.

When conducting authorized testing, you must: act only against your own test tenant or systems we designate; avoid accessing, modifying, or deleting other customers’ data; avoid degrading the Service for others; stop and report immediately if you encounter another party’s data; and give us a reasonable opportunity to remediate before any public disclosure. We will not pursue good-faith researchers who follow these rules.

5. Rate limits and fair use

To keep the Service reliable for everyone, we apply rate limits and fair-use thresholds to the application and its APIs. These limits may vary by plan and may change over time.

You must not attempt to circumvent rate limits — for example, by rotating credentials, distributing requests across accounts, or other evasion. If you have a legitimate need for higher throughput, contact us to discuss an appropriate plan. We may throttle, queue, or temporarily restrict access to protect platform stability.

6. Customer responsibility for fixes

TrustFix generates remediation recommendations, including Terraform changes delivered as pull requests, but never applies changes to your infrastructure automatically. You are responsible for reviewing, testing, and deciding whether to apply any recommended change. Using the Service does not relieve you of responsibility for the security and correct operation of your own systems.

7. Enforcement

We may investigate suspected violations of this AUP. Depending on the severity and circumstances, we may warn you, throttle or restrict your access, remove offending content or configurations, suspend or terminate your account, and, where appropriate, notify law enforcement or affected parties.

Where a violation poses an imminent risk to the Service, to other customers, or to third parties, we may act immediately and without prior notice. We will use reasonable efforts to notify you of significant enforcement actions, except where doing so would compromise security, an investigation, or our legal obligations.

8. Reporting and contact

To report a suspected violation of this AUP or a security issue, contact security@trustfix.dev. For general questions, contact hello@trustfix.dev.

Vikavi Security LLC (operating as TrustFix), a Delaware limited liability company, headquartered in the Greater St. Louis area, United States.

Acceptable Use Policy | TrustFix