Devoku Acceptable Use Policy
Effective: 18 September 2026 Last updated: 16 September 2026
This Policy applies to all Devoku users, content, agents, workspaces, APIs, and integrations. Examples are illustrative. You must comply with law, the Terms of Service, provider rules, and reasonable safety limits communicated in the product.
1. Safety and rights
Do not use Devoku to:
- exploit, sexualize, groom, endanger, or facilitate abuse of a child; create, possess, solicit, or distribute child sexual abuse material;
- threaten, stalk, harass, dox, extort, incite violence, promote terrorism or violent extremism, or facilitate human trafficking or self-harm;
- unlawfully discriminate or deny a person a right or essential service;
- infringe privacy, publicity, copyright, trademark, trade-secret, database, confidentiality, or other rights;
- impersonate a person or organization, misrepresent affiliation, or deceptively present AI content as authentic human content;
- create or distribute non-consensual intimate imagery, sexual deepfakes, or biometric impersonation;
- collect, infer, publish, or trade personal or highly sensitive data without a lawful basis and appropriate notice, consent, and security; or
- provide regulated professional advice or make high-impact decisions about employment, housing, credit, insurance, education, healthcare, legal services, migration, policing, or access to essential services without legally required qualified human review, testing, explanation, and appeal.
2. Systems, malware, and security
Do not:
- access or test systems, accounts, models, networks, or data without the owner’s explicit authorization;
- deploy malware, ransomware, spyware, credential theft, destructive payloads, botnets, denial-of-service attacks, or mechanisms to evade detection;
- bypass rate limits, payment controls, approvals, safety filters, isolation, access controls, geographic restrictions, or provider policies;
- obtain, disclose, or use credentials, secrets, tokens, or vulnerabilities without authorization;
- operate an open relay, abusive proxy or VPN exit, command-and-control infrastructure, unsolicited port scanner, brute-force system, traffic amplifier, or mechanism for tenant escape;
- conduct security research outside a written scope or continue after consent is withdrawn; or
- use Devoku infrastructure for cryptomining, unsolicited scanning, proxy resale, or unrelated sustained compute unless expressly permitted by your plan.
Authorized defensive research, testing, and administration are permitted only within the authorization and safeguards of the system owner.
3. Fraud, deception, and abuse
Do not facilitate phishing, spam, scams, market manipulation, fake reviews, counterfeit goods, academic fraud, forged evidence, evasion of sanctions or law enforcement, deceptive political influence, or unlawful weapons or drug activity.
You may not generate or distribute synthetic media intended to deceive about a matter of public interest. Apply clear disclosure and preserve provenance metadata where required.
4. Messaging and communications
Do not send bulk or automated messages without lawful consent, required identification, and a working opt-out. Do not scrape users, add people to groups deceptively, evade blocks, or repeatedly contact a person after being asked to stop.
You must follow telecommunications, marketing, recording, workplace monitoring, and platform API rules. Devoku does not authorize unofficial automation of Signal, WhatsApp, Slack, Discord, or another provider.
5. AI and agent operation
Use safeguards proportionate to an agent’s access and potential impact. For agents affecting production, other people, sensitive data, external systems, or paid resources, you must where applicable:
- tell people when they are interacting with AI unless it is obvious, and label synthetic or materially altered media where law or context requires;
- maintain meaningful human control over consequential and high-risk actions;
- test code and actions in appropriately isolated environments;
- use least privilege, spending limits, backups, review gates, and monitoring; and
- stop an agent when its behavior becomes unsafe, unauthorized, or unpredictable.
Do not use agents to replicate prohibited conduct at scale, conceal the source of activity, defeat CAPTCHAs or access controls, create self-propagating code, or make prohibited autonomous high-impact decisions.
6. Resource and account abuse
Do not create accounts to evade enforcement, resell accounts or credits without permission, interfere with service operation, impose unreasonable load, exploit pricing errors, manipulate referrals, or use stolen payment methods.
If you administer a cloud workspace or enable root/SSH access, keep access keys restricted, follow applicable infrastructure-provider rules, and apply security and backup measures proportionate to the workload. Do not disable metering, security telemetry, abuse controls, or management access required to provide the workspace. Coded may isolate a workspace presenting an urgent threat while a report is investigated.
7. Enforcement and reporting
Report suspected violations to abuse@devoku.com. For imminent danger, contact local emergency services first. Reports should identify the content or account, explain the concern, and include supporting information. Do not submit unlawful material itself when a link or identifier is sufficient.
Coded may investigate; preserve evidence; limit tools, content, or distribution; remove content; suspend accounts; and notify affected parties, providers, or authorities where proportionate and lawful. We consider context, severity, intent, recurrence, impact, and remediation. Where law requires, we provide reasons and an appeal route.
We may update this Policy to address new abuse patterns. Material changes follow the notice rules in the Terms.