Acceptable Use Policy
What the Service may not be used for. Most of it is what you would expect. The section that matters is the one on circumventing governance, the whole product rests on the record being true.
This document is published for review. Entity registration details and the designated EU and UK representatives are still to be supplied, and appear below as marked placeholders. Until they are filled in, treat this text as a draft rather than as the executed agreement, and ask legal@teleon.ai for the current signed position.
Purpose
This policy sets out what the Teleon Service may not be used for. It is incorporated into the Terms of Service and applies to every customer, user and Agent.
Teleon exists so that an AI agent’s behaviour can be governed and proved. Using it to do the opposite, to launder an ungoverned agent through a governance layer, or to produce evidence that misstates what happened, is the abuse this policy is most concerned with, and the part enforced most strictly.
The rest is ordinary: do not break the law, do not attack the platform or anyone else, do not hold data you have no right to hold.
Unlawful use
You may not use the Service to commit, facilitate, or conceal an act that is unlawful where you are, where your users are, or where the Service runs. Without limiting that:
- Fraud, deception for financial gain, money laundering, or sanctions evasion.
- Distributing or generating child sexual abuse material. This is reported to the authorities immediately and terminates the account without notice or refund.
- Trafficking in persons, weapons, controlled substances, or stolen data.
- Unauthorised access to any system, network or account, including using an Agent as a proxy for intrusion.
- Infringing another party’s copyright, trademark, patent or trade secret, or misappropriating their confidential information.
Harmful conduct
You may not deploy an Agent through the Service that is designed or knowingly permitted to:
- Produce material that sexualises minors, incites violence, or promotes self-harm.
- Harass, threaten, defame or stalk a specific person, or facilitate coordinated harassment.
- Generate targeted disinformation, impersonate a real person or organisation without authorisation, or produce synthetic media of a real person intended to deceive.
- Provide instructions for weapons capable of mass casualty, including chemical, biological, radiological, nuclear and high-yield explosive weapons.
- Make consequential decisions about a person, employment, credit, housing, insurance, healthcare, criminal justice, without the human review and disclosure that applicable law requires.
- Deceive a person into believing they are speaking with a human where the law requires them to be told they are not.
Platform abuse
- Do not attempt to gain unauthorised access to another tenant’s data, to the control plane, or to Teleon’s infrastructure.
- Do not probe, scan or test the security of the Service except under an authorised engagement, write to security@teleon.ai first, and we will usually say yes.
- Do not interfere with the Service or degrade it for others: denial of service, resource exhaustion, deliberate quota circumvention.
- Do not reverse engineer, decompile or disassemble the Service, or attempt to extract its models, policy engine or scoring methodology, except to the extent that law expressly permits despite a contractual restriction.
- Do not resell, sublicense or provide the Service to a third party as a service of your own without a written reseller agreement.
- Do not create accounts by automated means, evade a suspension, or use a free plan to avoid paying for production use.
Governance circumvention
This section is the reason the policy exists. Teleon’s value to your customers and auditors rests entirely on the governance record being an honest account of what your Agent did.
- Do not route production traffic around the Service while representing that Agent as governed.
- Do not tamper with, replay, backdate, suppress or selectively omit audit events.
- Do not modify, disable or spoof the middleware, sidecar or gateway to report decisions that were not made, or to conceal decisions that were.
- Do not configure a policy whose purpose is to produce a passing record rather than to govern behaviour.
- Do not present a compliance bundle, trust score or audit export as covering a period, a system or an agent it does not cover.
Falsifying a governance record is not a dispute between you and Teleon. It is a false statement to your customers, your auditors and their regulators, made with our product as the instrument. We will terminate for it and, where the law requires it or a regulator asks, we will say what we found.
Trust Badge misuse
The badge rules are set out in the Trademark and Badge Use Policy and are part of this policy. In short: display the live badge issued for your Agent, unmodified, linking to its Trust Report, only while your subscription is active, and never a badge state that does not match the live signature.
Badge misuse is the one category of breach that may terminate an account immediately, without the notice-and-cure period in section 9.
Data you may not send
- Personal data you have no lawful basis to process, or that you obtained in breach of a law, a contract or a site’s terms.
- Protected health information, before a Business Associate Agreement has been executed.
- Cardholder data outside a scope you have agreed with Teleon in writing.
- Government identity documents, biometric templates, or special-category data under GDPR Article 9, unless the corresponding Privacy Vault classification is enabled and configured.
- Another party’s confidential information that you are not entitled to disclose.
Where you send classified data, enable the classification. Teleon tokenizes what you tell it to tokenize; a field you never classified is a field that reaches the classifier as written.
Rate limits and fair use
Each plan carries a monthly event allowance and per-principal rate limits, published in the Documentation and in section 5 of the Terms. Requests beyond the limit are throttled, and events beyond the allowance are throttled or billed as overage depending on your configuration.
Enforcement never stops because a limit was reached. An Agent over quota is still governed and its decisions are still recorded; what changes is throughput and billing, never whether the policy applies.
Fair use: do not shard one workload across accounts to multiply an allowance, do not generate synthetic events to inflate a score or a badge, and do not use a trial or free account for sustained production traffic. If your legitimate load is unusual, tell us, we would rather raise a limit than argue about one.
Monitoring, enforcement and appeals
What Teleon monitors
Teleon monitors platform-level signals: request volumes, error rates, authentication anomalies, and abuse reports. Teleon does not read customer payload content to police this policy, and does not scan the ledger looking for violations. Investigation of specific content happens only on a credible report, a legal obligation, or a security incident, and access is break-glass and audited like any other.
What happens on a breach
- Notice describing the conduct and what has to change, with a reasonable period to cure, normally 30 days, shorter where harm is ongoing.
- Where the conduct continues or the harm is immediate, throttling or suspension of the affected Agent, feature or account.
- Termination under section 11 of the Terms for a material or repeated breach.
- Immediate termination without notice for child sexual abuse material, for an active attack on the platform or another customer, or for badge forgery.
Appeals
Any enforcement action may be appealed to legal@teleon.ai within 30 days. Appeals are reviewed by somebody who was not involved in the original decision, and answered within 10 business days. Where an action turns out to have been wrong, access is restored and any fees for the affected period are credited.
Reporting
Report abuse of the Service to legal@teleon.ai, a security vulnerability to security@teleon.ai, and a suspected forged badge to trademark@teleon.ai. Reports may be made anonymously; we will not disclose a reporter’s identity to the reported party.
Your responsibility for your Agents
Governing an Agent through Teleon does not transfer responsibility for it. You remain responsible for what it says, what it does, and whether deploying it is lawful where you deploy it.
- Determine whether your Agent falls within a regulated category, the EU AI Act’s high-risk classifications, sectoral financial or medical rules, or an equivalent, and meet those obligations. Teleon produces evidence; it does not perform your classification for you.
- Tell your end users they are interacting with an AI system where the law requires it, and give them the human escalation route the law requires.
- Keep a human in the loop wherever a decision has a legal or similarly significant effect on a person.
- Test your policies. A policy that permits something it should not will be enforced exactly as written.
Changes and contact
Material changes to this policy are notified to account administrators at least 30 days before they take effect, except where a change is needed immediately to address an unlawful or harmful use, in which case it takes effect on publication and is notified at once.
- Abuse and appeals
- legal@teleon.ai
- Security
- security@teleon.ai
- Badge misuse
- trademark@teleon.ai
| Version | Effective | What changed |
|---|---|---|
| 1.1 | 2026-08-30 | First publication on the website. Added the governance-circumvention rationale, the monitoring-limits statement, the appeals process and the EU AI Act responsibilities. |
| 1.0 | 2026-05-22 | Initial policy, maintained internally and never published. |