---
title: "Acceptable Use Policy"
description: "This Acceptable Use Policy sets out what you may and may not do with Caveman Cloud and the caveman.so website, how to report abuse or a vulnerability, and how we enforce it. It forms part of the Terms"
canonical: https://caveman.so/legal/acceptable-use
last-updated: 2026-10-06
status: "draft, not yet in effect"
version: "2026-10-06"
publisher: "Caveman Labs, Inc."
contact: "contact@caveman.so"
---

# Acceptable Use Policy

This Acceptable Use Policy sets out what you may and may not do with Caveman Cloud and the caveman.so website, how to report abuse or a vulnerability, and how we enforce it. It forms part of the Terms of Service.

## Summary

This summary is for convenience only. The full policy below governs.

Send only lawful traffic you have the right to send, and follow your Model Providers' usage policies. Do not use the service to cause harm, attack it or other customers, fake savings figures, or get around governance controls. Report vulnerabilities to [contact@caveman.so](mailto:contact@caveman.so). If your use puts people, the platform, a Model Provider or other customers at risk, we may restrict or suspend it.

## 1. Scope

This Acceptable Use Policy (the "Policy") applies to your use of Caveman Cloud (the hosted gateway, dashboard and control API, together the "Services") and of the Website (caveman.so and docs.caveman.so). It forms part of the [Terms of Service](/terms), and words defined in the Terms have the same meaning here. "You" means the Customer and every User of its Workspace. You are responsible for your Users' compliance and for traffic sent with your credentials or through your Workspace.

The Open-Source Tools are governed by their own licences, listed in section 12 of the [Terms of Service](/terms). This Policy applies to them only when they connect to the Services. A Self-Hosted Deployment is governed by your written agreement with Caveman.

The examples below are not a complete list. If you are unsure whether a use is allowed, ask us first.

## 2. Unlawful and infringing use

You may not use the Services to:

- break any law that applies to you, your Users, the people whose data you process, or Caveman;
- create, store, send or distribute content that is illegal where you or your users are;
- infringe or misappropriate anyone's intellectual property, privacy, publicity or other rights;
- send traffic, data or content that you do not have the right to send.

## 3. Model Provider usage policies

Caveman Cloud is "bring your own key". Each request reaches a Model Provider under your own agreement with that provider, using your own Provider Key. Those agreements and usage policies apply to your traffic whether or not this Policy repeats them. You must:

- comply with the terms, usage policies and rate limits of every Model Provider you use;
- not use the Services to do anything through a Model Provider that the provider's own terms forbid;
- not use the Services to disguise, relabel, split or launder traffic so that it evades a Model Provider's safety systems, rate limits, geographic restrictions or account controls;
- not use the Services to share one Provider Key with people or organisations the provider has not authorised.

If a Model Provider tells us your traffic breaches its policies, we may restrict that traffic while the issue is resolved.

## 4. Harmful content and conduct

You may not use the Services to generate, store, send or facilitate:

- **Child sexual abuse material.** We have zero tolerance for child sexual abuse material and for any content that sexualises minors. We will terminate the accounts involved, preserve relevant information, and report it to the National Center for Missing & Exploited Children and other competent authorities as the law requires.
- **Violent extremism and terrorism.** Content that promotes, supports, recruits for or plans terrorist or violent extremist acts or organisations.
- **Violence and weapons.** Content that incites or threatens violence, or that gives meaningful help to develop or use biological, chemical, nuclear or radiological weapons or other weapons capable of mass casualties.
- **Non-consensual intimate imagery.** Sexual or intimate images or video of a real person shared or created without their consent, including synthetic images.
- **Harassment and hate.** Content that harasses, bullies, threatens, defames or doxes people, or that attacks people on the basis of a protected characteristic.
- **Malware and intrusion.** Malware, ransomware, exploits or tools designed to gain unauthorised access to systems, or instructions to do so against systems you do not own or have permission to test.
- **Fraud, phishing and spam.** Scams, phishing, fraudulent transactions, fake reviews, unsolicited bulk messages, or content designed to deceive people into giving up money, credentials or personal data.
- **Self-harm.** Content that encourages or instructs people to harm themselves.

## 5. Prohibited AI practices

### EU AI Act prohibited practices

You may not use the Services to develop, place on the market, put into service or use any AI system for a practice prohibited by Article 5 of the EU AI Act (Regulation (EU) 2024/1689), wherever you are. These include:

- subliminal, manipulative or deceptive techniques that materially distort a person's behaviour in a way that causes or is likely to cause significant harm;
- exploiting the vulnerabilities of people due to their age, disability or social or economic situation;
- social scoring that leads to unjustified or disproportionate detrimental treatment;
- assessing the risk that a person will commit a crime based solely on profiling or personality traits;
- creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage;
- inferring emotions in the workplace or in education, except for medical or safety reasons;
- biometric categorisation to infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation;
- real-time remote biometric identification in publicly accessible spaces for law enforcement, except as the law strictly allows.

### Other high-risk misuse

You may not use the Services:

- to make decisions that produce legal or similarly significant effects on individuals, for example in employment, credit, insurance, housing, education, essential services, migration or law enforcement, without meaningful human review and compliance with the laws that apply to those decisions, including the requirements for high-risk AI systems;
- to operate or attack critical infrastructure in a way that could endanger life or safety;
- to interfere with elections or democratic processes, including through coordinated deceptive campaigns.

### Impersonation and undisclosed AI

You may not use the Services to:

- impersonate a real person or organisation, or falsely imply an affiliation with or endorsement by them, including Caveman or a Model Provider;
- deploy a chatbot or other AI system that interacts with people without telling them they are interacting with AI, where the law requires that disclosure or where they would otherwise be misled;
- publish deepfakes or other synthetic image, audio, video or text content without the labelling the law requires, or present AI-generated content as human-made in order to deceive.

## 6. Privacy abuse

You may not use the Services to:

- track, monitor or surveil people unlawfully, or stalk anyone;
- process personal data without a lawful basis, the required notices or the required consents;
- collect personal data by scraping or other means in breach of law or of the source's terms;
- send special categories of personal data, criminal-offence data or children's personal data through a Workspace where Product Data Sharing applies (always the case on the Free plan);
- send protected health information under HIPAA or payment card data under PCI DSS on any Plan, unless an Order Form allows it.

## 7. Attacks on the Services and other tenants

You may not:

- access, or try to access, another customer's Workspace, data, keys or traffic. Tenant isolation is a hard rule;
- probe, scan or test the vulnerability of the Services, or run penetration tests, load tests or automated scans against them, without our prior written permission, except as the safe harbour below allows;
- bypass or try to bypass authentication, authorisation, role-based access control, rate limits or other security controls;
- introduce malware, or interfere with or disrupt the Services, their networks or the infrastructure of our vendors;
- exploit a vulnerability for any purpose other than reporting it to us.

### Security testing and vulnerability reports

Load tests, automated scans and penetration tests need our written permission, given in advance at [contact@caveman.so](mailto:contact@caveman.so) and limited to the scope we agree. Other good-faith research is covered by the safe harbour below.

If you find a vulnerability, report it privately to [contact@caveman.so](mailto:contact@caveman.so). For the open-source toolkit you may also use [GitHub private vulnerability reporting](https://github.com/JuliusBrussee/caveman/security/advisories/new). Do not include customer Payloads, API keys, tokens, cookies, private keys, database URLs or Provider Keys in a report. Give us reasonable time to fix the issue before you disclose it publicly. We do not run a paid bug bounty.

If you act in good faith, access only the data you need to show the vulnerability, do not access other customers' data, do not degrade the Services, delete nothing, and report promptly without making demands, we will not take legal action against you or ask law enforcement to investigate you for that research. Research that meets these conditions is treated as authorised under this Policy.

## 8. Abuse, overload, rate limits and quotas

Your Plan sets usage limits, such as request rates, volumes and quotas for compute features. You may not:

- send traffic designed to overload, degrade or deny service to the Services or to a Model Provider;
- run uncontrolled retry storms or automated loops that generate abnormal volume without backoff;
- exceed your limits or engineer traffic to evade them, including by splitting traffic across multiple Workspaces or accounts;
- use agent runs or other compute features for cryptocurrency mining or other compute unrelated to the purpose of the feature.

We may throttle, queue or reject requests that exceed limits, or that we reasonably believe threaten the stability of the Services or a Model Provider.

## 9. Integrity of measurements

Caveman Cloud keeps measured, inferred and verified savings as separate labels, and only provider-causal evidence enters the verified-savings ledger. You may not:

- manipulate traffic, data or settings to make savings appear that were not earned on real traffic;
- tamper with, forge or replay receipts, statements, telemetry, usage metering or cost records;
- game or manipulate evaluation gates, graders, judges or rollout controls;
- present inferred savings as verified savings, or misrepresent any figure from the Services, in material you publish or give to others.

## 10. Governance controls

You may not circumvent or try to circumvent the governance and security controls of the Services, whether for your own Workspace or anyone else's. These include zero data retention (`x-cave-retention: zdr`), retention windows, redaction, Product Data Sharing settings, tenant and project isolation, role-based access control and the audit log.

## 11. Sharing, reselling and white-labelling

- Each User must have their own login. Do not share login credentials between people.
- You may use the Services to power your own products for your own customers.
- You may not resell, sublicense, rent or provide the Services themselves (the gateway, dashboard or control API) to third parties, or offer them under your own brand, without a written agreement with Caveman.

## 12. Reverse engineering

You may not decompile, disassemble, reverse engineer or otherwise try to derive the source code, models or underlying structure of the hosted Services, except to the extent that an open-source licence covering the relevant code or mandatory law allows it. Your rights under the licences of the Open-Source Tools are not affected.

## 13. Sanctions and export controls

You may not use the Services in breach of the export-control and sanctions laws of the United States, the European Union, the United Kingdom or any other applicable jurisdiction. This includes use by or for a sanctioned person, from a country or region subject to comprehensive sanctions, or for a prohibited end use such as developing weapons of mass destruction.

## 14. Reporting violations

To report a suspected violation of this Policy, write to [contact@caveman.so](mailto:contact@caveman.so). Please include what happened, where (a URL, Workspace or request identifier if you have one), when, and any evidence. To report illegal content under the EU Digital Services Act, follow the notice requirements in the "Illegal content and the Digital Services Act" section of the [Terms of Service](/terms).

## 15. Enforcement

We may investigate suspected violations using the information available to us under the Terms, to the extent needed and permitted by law and your settings.

If we find a violation, we may take one or more of these steps:

- warn you and ask you to fix the problem;
- restrict a feature, a project or a Provider Key's traffic, or throttle requests;
- remove or disable access to content;
- suspend your Workspace or a User;
- terminate your account under the Terms;
- report the matter to law enforcement or other authorities where the law requires it or where people are at risk.

Our response will be proportionate to the seriousness of the violation. Where practical and lawful, we will tell you before we act, explain why, and give you a chance to fix the problem. For serious or ongoing harm, such as child sexual abuse material, attacks on the Services or threats to other customers, we may act immediately and tell you afterwards. When we restrict your content or account, we will give you a statement of reasons unless the law prevents us.

If you believe we made a mistake, reply to our notice or write to [contact@caveman.so](mailto:contact@caveman.so). A person will review your appeal and tell you the outcome.

## 16. Changes

We may update this Policy, and the version tag at the top of this page changes with each update. We will give at least 30 days' advance notice of material changes by email to Admins and by a notice on this page, except where the law or security requires a change to take effect immediately. Questions go to [contact@caveman.so](mailto:contact@caveman.so).
