1. Introduction and Incorporation

This Acceptable Use Policy ("AUP") governs Customer's and its authorized users' use of TFALKE's zero-polling, real-time endpoint management platform, including the single-device natural language AI agent (the "AI Agent") and all associated software, dashboards, APIs, and infrastructure (collectively, the "Service"). This AUP is incorporated by reference into, and forms part of, the Master Services Agreement and Terms of Service (the "Agreement") between TFALKE PRIVATE LIMITED ("TFALKE," "we," "us") and the customer ("Customer," "you"). Capitalized terms not defined here have the meaning given in the Agreement.

This AUP applies to Customer and to every individual, contractor, or system Customer permits to access the Service under Customer's account (collectively, "Authorized Users"). Customer is responsible for ensuring that all Authorized Users comply with this AUP, and any violation by an Authorized User is treated as a violation by Customer.

TFALKE may update this AUP from time to time by posting a revised version, consistent with the amendment provisions of the Agreement. Continued use of the Service after an update takes effect constitutes acceptance of the revised AUP.

2. Prohibited AI Agent Interactions

2.1 Prompt Injection and Jailbreaking

Customer and its Authorized Users must not, and must not attempt to, directly or indirectly:

  • submit prompts, payloads, or inputs designed to manipulate, confuse, override, or bypass the AI Agent's intended instructions, safety constraints, or operational boundaries ("prompt injection");
  • attempt to "jailbreak" the AI Agent, including through role-play framing, encoded or obfuscated instructions, nested or recursive prompts, or any other technique intended to cause the AI Agent to disregard its configured restrictions;
  • probe, fuzz, or systematically test the AI Agent's prompt-handling logic with the intent of discovering or exploiting a bypass, whether or not the attempt succeeds; or
  • instruct, induce, or assist any other person or automated system in performing any of the foregoing.

2.2 Single-Device Restriction

The AI Agent is architected to interpret and execute natural language instructions strictly within the scope of a single designated Endpoint. Customer and its Authorized Users must not attempt to:

  • circumvent, defeat, disable, or otherwise bypass the single-device restriction to cause the AI Agent to issue commands, queries, or configuration changes affecting any Endpoint other than the single Endpoint to which a given AI Agent session is bound;
  • chain, script, replay, or automate AI Agent sessions in a manner designed to achieve network-wide or multi-device execution that the single-device architecture is designed to prevent; or
  • exploit any bug, misconfiguration, or unintended behavior of the AI Agent to achieve unauthorized cross-device or network-wide effect.

Any successful or attempted circumvention of the single-device restriction by Customer or an Authorized User is a material breach of this AUP and the Agreement, regardless of Customer's stated intent or business justification.

2.3 Distinction from a TFALKE-Caused Scoping Failure

Section 2.2 governs attempts by Customer or its Authorized Users to defeat the single-device restriction. It does not apply where the restriction is instead defeated by a verified defect in TFALKE's own session-scoping architecture, occurring without any act described in Section 2.2. Liability for that distinct scenario is governed by Section 8 (Relationship to the Limitation of Liability) and by the Master Services Agreement, not by this Section 2, and is not excluded by this AUP.

Fix applied: the prior draft addressed only customer-side attempts to bypass the single-device restriction, leaving no clear treatment of the separate scenario where TFALKE's own architecture allows a scoping error with no customer misuse involved. This subsection draws that line explicitly, so a genuine product defect is not swept into — or confused with — the customer-misuse provisions of Section 2.2.

2.4 Malicious Use of the AI Agent

Customer and its Authorized Users must not use, or attempt to use, the AI Agent to generate, request, deploy, stage, or propagate:

  • malicious scripts, malware, ransomware, spyware, keyloggers, backdoors, or any code designed to damage, disable, encrypt without authorization, exfiltrate data from, or otherwise disrupt any Endpoint or system;
  • commands intended to cause denial of service, resource exhaustion, data destruction, or unauthorized configuration changes on any Endpoint, network, or system, whether belonging to Customer or any third party; or
  • any output that Customer knows or reasonably should know will be used for an unlawful purpose.

Drafting note: 2.1–2.3 are written to prohibit the attempt itself, not only a successful outcome, and to prohibit inducing a third party or automated tool to do it on Customer's behalf. This closes the obvious loophole of "the jailbreak didn't work" or "a script did it, not me" as a defense to a breach claim.

2.5 Mandatory Confirmation for Destructive Commands

Customer and its Authorized Users must not attempt to disable, suppress, auto-accept, script around, or otherwise circumvent the Accept/Reject confirmation step that the Service requires before executing any High-Risk Command, as described in the Agreement. Any Authorized User who Accepts a High-Risk Command is deemed, for purposes of the Agreement, to have reviewed and approved that specific command, and Customer bears responsibility for that Authorized User's decision to Accept.

3. System and Network Security

3.1 Prohibition on Penetration Testing, Scanning, and Attacks

Customer and its Authorized Users must not use the Service, directly or indirectly, to conduct, facilitate, or launch:

  • penetration testing, red-teaming, vulnerability scanning, port scanning, or security assessments of any kind against TFALKE's cloud infrastructure, the Service, or any system not owned by Customer, without TFALKE's prior written authorization under a separate, signed testing agreement;
  • penetration testing or vulnerability scanning against any third party's network, systems, or Endpoints without that third party's own prior written authorization, regardless of whether Customer separately authorizes it;
  • denial-of-service or distributed denial-of-service (DDoS) attacks, or any activity intended to degrade, overwhelm, or interrupt the availability of any network or system, whether belonging to TFALKE, Customer, or any third party; or
  • any unauthorized attempt to access, probe, or interfere with TFALKE's cloud infrastructure, backend systems, other customers' environments, or any non-public part of the Service.

3.2 Prohibition on Reverse Engineering

Customer and its Authorized Users must not, and must not permit or assist any third party to:

  • reverse-engineer, decompile, disassemble, or otherwise attempt to derive the source code, underlying algorithms, or architecture of the RTEM endpoint agent, the AI Agent, or any other component of the Service;
  • extract, copy, or attempt to extract any proprietary model, weights, configuration, or embedded credential from the Service or the endpoint agent binary; or
  • circumvent any technical protection measure, obfuscation, licensing control, or access restriction applied to the Service, except to the limited extent such restriction is expressly permitted by mandatory law that cannot be excluded by agreement (e.g., narrow interoperability rights under applicable software law), and then only after providing TFALKE with prior written notice and a reasonable opportunity to provide the necessary interoperability information itself.

4. Legal and Compliance Mandates

4.1 Authorization to Manage Endpoints

Customer represents and warrants, on a continuing basis for so long as any Endpoint is enrolled in the Service, that Customer either:

  • owns each Endpoint it enrolls in the Service; or
  • has obtained explicit, documented authorization from the legal owner or operator of each Endpoint to install, configure, and manage that Endpoint through the Service, including authorization sufficient to permit the AI Agent to issue commands to it.

Customer must maintain evidence of such ownership or authorization for the duration of enrollment and for a reasonable period thereafter, and must produce it to TFALKE promptly upon reasonable request, including in connection with any suspected AUP violation, regulatory inquiry, or legal proceeding. Enrolling any Endpoint without the requisite ownership or authorization is a material breach of this AUP.

4.2 Lawful Use

Customer must use the Service in compliance with all applicable laws, including without limitation computer misuse, data protection, and export control laws in every jurisdiction in which Customer operates or enrolls Endpoints. Customer is solely responsible for determining whether its use of the Service, including the AI Agent, complies with laws applicable to its industry, its Endpoints, and its Authorized Users.

4.3 Additional Prohibited Uses

Without limiting the foregoing, Customer and its Authorized Users must not use the Service to:

  • violate the privacy, intellectual property, or other legal rights of any third party;
  • transmit unsolicited bulk communications, or distribute content that is unlawful, defamatory, or infringing;
  • interfere with or disrupt the integrity or performance of the Service or any data contained therein; or
  • misrepresent Customer's identity or affiliation, or impersonate any person or entity, in connection with use of the Service.

5. Enforcement: Suspension and Termination

5.1 Immediate Suspension or Termination

TFALKE may, in its sole discretion and without prior notice, immediately suspend or terminate Customer's access to the Service, in whole or in part, upon any actual, suspected, or attempted violation of this AUP, including any violation by an Authorized User. TFALKE's exercise of this right does not waive any other right or remedy available to TFALKE under the Agreement or applicable law.

5.2 No Refund

Suspension or termination under this Section 5 is without refund of any fees paid or owed, including prepaid or unused subscription fees, and does not relieve Customer of its obligation to pay any outstanding fees accrued prior to suspension or termination.

5.3 No Obligation to Investigate; Reliance on Automated and Manual Detection

TFALKE has no obligation to monitor Customer's use of the Service, but may do so, and may rely on automated detection, Authorized User reports, third-party reports, or its own judgment in determining that a violation has occurred. TFALKE's decision to suspend or terminate under this Section need not be preceded by an investigation, hearing, or opportunity to cure, except where mandatory law requires otherwise.

5.4 Cooperation with Law Enforcement and Affected Third Parties

Where TFALKE reasonably believes that Customer's use of the Service has caused or may cause harm to a third party, or may constitute a violation of law, TFALKE may, at its discretion and where permitted by law, disclose relevant account and usage information to the affected third party, law enforcement, or a relevant regulator, in addition to exercising its suspension and termination rights.

5.5 Survival

This AUP survives termination of the Agreement with respect to any act or omission occurring prior to termination, and Sections 4.1, 5.2, and 5.4 survive indefinitely.

6. Relationship to the Limitation of Liability

This AUP is a condition of use of the Service. Any breach of this AUP by Customer or its Authorized Users falls within Customer's indemnification obligations under the Agreement, and TFALKE bears no liability for any Losses arising from Customer's or any Authorized User's violation of this AUP, including any harm to Customer's own Endpoints, network, or business resulting from a prohibited AI Agent interaction, an unauthorized attempt to bypass the single-device restriction, or the enrollment of an Endpoint without proper ownership or authorization.