This Acceptable Use Policy (“AUP”) describes conduct that is prohibited when using mashin, Inc.’s products and services, including the mashin platform, the Koda intelligent development environment, and the Kura package registry (collectively, the “Services”). This AUP is incorporated into and forms part of the applicable Terms of Service, End User License Agreement, or Enterprise Subscription Agreement.
Violation of this AUP constitutes a material breach of your agreement with mashin, Inc. and may result in immediate suspension or termination of your access to the Services without prior notice.
1. Prohibited Content
You may not use the Services to store, transmit, distribute, or make available content that:
(a) Is unlawful, defamatory, libelous, obscene, pornographic, or otherwise objectionable under applicable law.
(b) Infringes or misappropriates any third party’s intellectual property rights, privacy rights, publicity rights, or other legal rights.
(c) Contains malware, viruses, ransomware, trojans, worms, logic bombs, or other harmful or malicious code.
(d) Contains personal information of third parties collected without their informed consent or in violation of applicable data protection law.
(e) Constitutes or facilitates fraud, identity theft, phishing, or deceptive practices.
(f) Promotes or facilitates violence, terrorism, hate speech, or serious harm to individuals or groups.
(g) Constitutes, depicts, promotes, or facilitates child sexual abuse material or the exploitation of minors in any form.
(h) Contains non-consensual intimate imagery or synthetic intimate media (deepfakes) of real individuals.
2. Prohibited Conduct
You may not:
(a) Use the Services for any unlawful purpose or in violation of any applicable law or regulation, including export control laws, sanctions, anti-money laundering laws, and data protection regulations.
(b) Attempt to gain unauthorized access to the Services, other accounts, computer systems, or networks connected to the Services through hacking, password mining, credential stuffing, or any other means.
(c) Interfere with or disrupt the integrity, performance, or availability of the Services or the data contained therein, including through denial-of-service attacks, flooding, or deliberate overloading.
(d) Reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code of the Services, except to the extent expressly permitted by applicable law.
(e) Use the Services to develop a product or service that competes with the Services, or systematically copy features, functions, or user interfaces of the Services.
(f) Resell, sublicense, share access credentials for, or redistribute the Services except as expressly permitted by your Subscription Plan.
(g) Circumvent or attempt to circumvent any usage limits, rate limits, access controls, or other technical restrictions of the Services.
(h) Use automated means (bots, scrapers, crawlers) to access the Services other than through published APIs used in accordance with their documentation and applicable rate limits.
(i) Use the Services as infrastructure for stolen data, malware command-and-control operations, or credential harvesting.
(j) Create multiple accounts to circumvent enforcement actions, evade usage limits, or abuse free-tier offerings.
3. AI-Specific Restrictions
When using AI features of the Services (:reason steps, model routing, governed inference), you additionally may not:
3.1 Autonomous High-Stakes Decisions
Use AI features to make fully autonomous decisions in high-stakes domains, including healthcare diagnosis or treatment, legal determinations affecting individual rights, financial lending or insurance underwriting, employment hiring or termination, criminal justice sentencing or risk assessment, or critical infrastructure operations, without meaningful human oversight and review of AI outputs before they are acted upon.
3.2 Safety Measure Circumvention
Attempt to bypass, disable, undermine, or circumvent safety measures, content filters, guardrails, or usage restrictions implemented by mashin, Inc. or its third-party AI model providers. This includes prompt injection attacks, jailbreaking, systematic probing for model vulnerabilities, and techniques designed to extract model weights, training data, or system prompts. Authorized security research conducted in compliance with our Security Policy is excluded from this restriction.
3.3 Illegal Content Generation
Use AI features to generate content that is illegal under applicable law, including child sexual abuse material, non-consensual intimate imagery, content that facilitates the commission of violent crimes, content that violates export control regulations, or instructions for creating weapons of mass destruction, biological agents, or chemical weapons.
3.4 Impersonation and Deception
Use AI features to impersonate real individuals without their consent, create synthetic media (deepfakes) of real individuals without consent, generate misleading content presented as human-authored in contexts where the distinction matters, engage in social engineering attacks, or create deceptive content for search engine manipulation or fake social proof.
3.5 Mass Surveillance
Use AI features for mass surveillance, unauthorized monitoring of individuals, facial recognition or biometric identification without a lawful basis and individual consent, or behavioral tracking and profiling in violation of applicable privacy laws.
3.6 Elections and Political Campaigns
Use AI features to generate personalized political advertising, create synthetic media for political campaigns without clear disclosure, or produce content designed to suppress voter participation or mislead voters about election procedures.
4. Registry-Specific Restrictions
When using the mashin package registry (Kura), you additionally may not:
4.1 Malware and Exploits
Publish packages (krates) containing malware, exploits, backdoors, rootkits, or code designed to damage, disrupt, or gain unauthorized access to systems. This includes obfuscated code designed to conceal malicious intent.
4.2 Name Squatting
Register package names with no intention of publishing meaningful content. Packages must have substantive content published within 30 days of name registration, or the name may be reclaimed. You may not register names that are confusingly similar to existing popular packages with intent to deceive.
4.3 License Violations
Publish packages that violate the terms of their upstream licenses, including incorporating GPL-licensed code under an incompatible license without authorization.
4.4 License Key Generators
Publish packages that generate, crack, bypass, or circumvent software license keys, activation systems, or digital rights management protections, including for mashin, Inc.’s own products or any third-party software.
5. Network Abuse
You may not use the Services to:
(a) Launch, facilitate, or participate in denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks against any target.
(b) Send unsolicited bulk communications (spam) via email, messaging, or any other medium.
(c) Operate open proxies, open mail relays, or anonymizing services (such as Tor exit nodes) through the Services without prior written authorization.
(d) Conduct network scanning, port scanning, or vulnerability scanning of systems you do not own or have written authorization to test.
(e) Use the Services for cryptocurrency mining unless expressly permitted by your Subscription Plan.
6. Regulated Activities
You may not use the Services for activities requiring specific licenses or regulatory approvals that you do not hold, including but not limited to: unregulated gambling or lottery operations, illegal substance trafficking, card fraud or payment fraud, and operation of critical systems (nuclear facilities, air traffic control, life support) where Service failure could result in death or serious injury without appropriate redundancy and human oversight.
7. Compliance with Laws
You must comply with all applicable laws and regulations when using the Services, including export control laws, sanctions regulations, data protection laws, and industry-specific regulations. You are solely responsible for ensuring that your use of the Services, and any content you create, store, or transmit, complies with laws applicable to you and your end users.
8. Enforcement
mashin, Inc. reserves the right to investigate suspected violations of this AUP. Upon determining a violation, mashin, Inc. may take any action it deems appropriate, including:
- Issuing a warning with a deadline for remediation
- Removing or disabling access to content that violates this AUP
- Temporarily suspending access to the Services
- Permanently terminating the account and all associated data
- Reporting suspected illegal activity to appropriate law enforcement authorities
mashin, Inc. will make reasonable efforts to notify you before taking enforcement action, except where: (a) immediate action is necessary to prevent ongoing harm to the Services, other users, or third parties; (b) notification would compromise an investigation; (c) we are legally prohibited from providing notice; or (d) the violation involves content described in Section 1(g) (child exploitation material).
mashin, Inc.’s determination of whether conduct violates this AUP is final. Enforcement of this AUP is at mashin, Inc.’s sole discretion, and failure to enforce against a particular instance does not constitute a waiver.
9. Reporting Violations
If you become aware of any violation of this AUP, please report it to [email protected]. Include: the nature of the violation, the account or content involved (URLs, usernames, package names), the date and time of the observed violation, and any supporting evidence. Reports may be submitted anonymously. mashin, Inc. will not retaliate against good-faith reporters.
10. Changes to This Policy
mashin, Inc. may update this AUP at any time. Material changes will be announced with at least 30 days’ notice. Continued use of the Services after the effective date constitutes acceptance.
Questions? Contact mashin, Inc. at [email protected].