Legal
Acceptable Use Policy
Effective date: June 27, 2026 · Version 1.1
1. Purpose
This Acceptable Use Policy (“AUP”) describes permitted and prohibited uses of the OpsPilot platform and agent software provided by 911 DevOps LLC. This AUP is incorporated by reference into the OpsPilot Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service.
2. Authorization Requirement
The OpsPilot agent may only be installed on systems you own or for which you have received explicit, documented authorization from the system owner to install and operate automated software.
This includes but is not limited to:
- Physical servers you own or co-locate;
- Virtual machines or cloud instances under your account;
- Customer or client systems, only when you have a written service agreement granting you this right;
- Employer-owned systems, only when your employment agreement or a written authorization from your employer permits this.
Installing the agent on any system without this authorization is strictly prohibited and may constitute unauthorized computer access under applicable law.
3. Prohibited Activities
You must not use the Service to:
3.1 Unauthorized Access
- Access, scan, probe, or test systems, networks, or accounts without explicit owner authorization;
- Circumvent authentication, access controls, or security monitoring systems;
- Use credentials belonging to another person or entity without their permission;
- Conduct unauthorized vulnerability scanning, fuzzing, or penetration testing.
3.2 Malicious Software
- Deploy, distribute, or execute malware, ransomware, trojans, viruses, or any software designed to damage or gain unauthorized access to systems;
- Use the Service as a command-and-control channel for compromised systems;
- Modify the agent code to remove or bypass safety enforcement layers.
3.3 Harmful Operations
- Intentionally damage, destroy, or deny service on any system or network;
- Execute commands that could cause data loss, corruption, or service outages on production systems without proper change management procedures;
- Target critical infrastructure (power grids, water systems, financial systems, healthcare systems, emergency services).
3.4 Privacy and Data Violations
- Use the Service to collect, extract, or exfiltrate personal data without proper legal basis;
- Process personal data in ways that violate applicable privacy laws (GDPR, CCPA, HIPAA, etc.);
- Use the Service to surveil individuals without their knowledge and consent where required by law.
3.5 Service Abuse
- Attempt to overload, disrupt, or interfere with the Service or its infrastructure;
- Scrape, crawl, or systematically extract data from the Service beyond normal usage;
- Share, resell, or sublicense API keys or account access to third parties without our written consent;
- Create multiple accounts to circumvent plan limits or service restrictions.
3.6 Legal Violations
- Violate any applicable federal, state, local, or international law or regulation;
- Facilitate or encourage others to engage in any prohibited activity listed in this AUP.
4. Responsible Use in Production Environments
Given that OpsPilot operates on live production systems, you agree to:
- Test all AI-suggested commands in a non-production environment before executing them in production where feasible;
- Maintain proper backups and change management procedures independent of the Service;
- Review every AI-generated command before approving execution — the AI is an assistant, not an authority;
- Restrict agent API key access to personnel who are qualified and authorized to administer the target systems;
- Rotate API keys promptly if they are compromised or if personnel with access leave your organization.
5. Security Research Exception
Authorized security research (penetration testing, red team engagements, CTF competitions) on systems you own or have written authorization to test is permitted, subject to the following conditions:
- You have a signed authorization document from the system owner that explicitly permits automated tooling;
- You operate within the defined scope of the engagement;
- You do not use the Service to facilitate attacks on systems outside the authorized scope.
6. Reporting Violations
If you become aware of any violation of this AUP, or if you discover a security vulnerability in the Service, please report it immediately to legal@911devops.com. We take all security reports seriously and will respond within 48 hours.
7. Consequences of Violation
Violations of this AUP may result in:
- Immediate suspension or termination of your account without notice or refund;
- Reporting to appropriate law enforcement authorities;
- Civil action to recover damages;
- Notification to affected third parties.
We reserve the right to determine, in our sole discretion, whether a given use constitutes a violation of this AUP.
8. Changes to This Policy
We may update this AUP at any time with 30 days’ notice for material changes. Continued use of the Service constitutes acceptance of the updated policy.