PolicyLast updated Sep 6, 2026

Acceptable Use Policy

What you may and may not do with LaunchSafe. You must only test systems you own or are explicitly authorized to test; offensive capabilities may not be used against third parties.

This Acceptable Use Policy applies to everyone who uses LaunchSafe and forms part of the Terms of Service. We have written it plainly because the stakes are real: our products find and exercise vulnerabilities, and in the wrong hands that is an attack.

The rule that matters most

Only test systems you own or are explicitly authorised in writing to test. Authorisation has to come from someone with the authority to give it, cover the specific targets and techniques, and be current. Keep a record of it. If you could not show us your authorisation on request, do not run the test.

Where a target is hosted by someone else — a cloud provider, a SaaS vendor, an app store, a payment processor — their testing rules apply on top of ours. Follow them.

You must not

  • Test, scan or exploit systems, accounts, models or data you do not own and are not authorised to test.
  • Use LaunchSafe to develop, stage or deliver malware, ransomware, botnets or command-and-control infrastructure for use against third parties.
  • Run denial-of-service or volumetric attacks, or any test whose purpose is to degrade availability rather than find a defect.
  • Exfiltrate, sell or publish data obtained during testing, or access more data than is needed to demonstrate a finding.
  • Target critical infrastructure, medical devices, safety systems, or anything where a failed test could cause physical harm, unless we have agreed the engagement with you in writing beforehand.
  • Use the Service to build a competing product, to benchmark it for publication without our consent, or to train another model on its outputs.
  • Circumvent our safety controls, rate limits, scope restrictions or approval gates, or try to make our models produce capability they are designed to refuse.
  • Do anything unlawful, breach export-control or sanctions law, or use the Service from a sanctioned jurisdiction.
  • Resell, sublicense or share access outside your organisation without our written agreement.

Scoping and safety

Scope is enforced in the product, not only in this policy, but you are still responsible for setting it correctly. Keep production tests inside agreed windows, keep destructive actions behind the approval gate, and give us a contact we can reach if a test goes wrong.

Enforcement

If we believe use breaches this policy we may restrict features, suspend the account, or terminate it — immediately where there is an ongoing risk to others. We will tell you what we found and give you a chance to fix it where the situation allows. Serious abuse is reported to the appropriate authorities.

Reporting abuse

Email hello@launchsafe.com with what you saw, when, and any evidence you can share. To report a vulnerability in LaunchSafe itself, use the Vulnerability Disclosure Policy.