Legal
Acceptable Use Policy
MCP Guard checks AI-agent tool calls before they run. These are the uses we do not allow.
Last updated ·
1. Agent-specific rules
- Using the Service to develop, test or refine attacks (including prompt injection, data exfiltration or destructive actions) against systems, agents, accounts or data you do not own or are not authorised to test.
- Systematically probing the Service to find inputs that evade it in order to help an agent carry out harmful actions undetected, or to build tools that do so. Good-faith evaluation of the guard on your own deployment, and research you report to us, are welcome.
- Operating agents that, with or without the Service, take unlawful actions: unauthorised access to computer systems, fraud, sending spam or phishing, or harvesting personal data.
- Representing a verdict from the Service as a guarantee of safety, a security certification or an audit, to your users or anyone else.
- Relying on the Service as the only safeguard for actions that could cause death, injury, significant financial loss or damage to critical infrastructure.
- Sending other people’s secrets or credentials in request content when a redacted placeholder would serve the same purpose. Checks work on the shape of an action; you rarely need to send live secrets.
2. General prohibited uses
- Unlawful surveillance, profiling of protected characteristics, or discrimination.
- Processing data you have no right to process.
- Attempting to disrupt the service, circumvent rate limits or billing, or access other customers’ data.
- Attempting to extract the model’s weights, or using the Service’s output to train a competing guard model.
- Reselling raw API access without a written agreement.
- Any unlawful purpose, or processing content whose possession or distribution is illegal (such as child sexual abuse material).
- Violating others’ rights, including privacy, intellectual-property and confidentiality rights.
- Uses that breach applicable sanctions or export-control laws, or use by or for sanctioned persons.
- Security testing, load testing or vulnerability scanning of the Service’s infrastructure without our prior written permission (report vulnerabilities to support@mcp-guard.ai).
- Creating multiple accounts to obtain additional free requests, or sharing API keys outside your organisation.
3. Sensitive data
Tool calls and context can contain personal data. Send only what the check needs, and send sensitive data (such as health or financial data) only if you have a valid legal basis, have informed the people concerned as the law requires, and have assessed whether our processing (see the Privacy Policy) is appropriate.
4. Enforcement
We may rate-limit, suspend or terminate access that violates this policy, and report illegal activity to the competent authorities where required. Report abuse to support@mcp-guard.ai.