Acceptable use policy.
What Customer, Agent Operators, and anyone else using Facet must not do, enumerated by content, technical conduct, and data use, together with the enforcement ladder and appeal mechanism.
Scope and applicability.
1.1 Incorporation
This Acceptable Use Policy ("AUP") is incorporated into and forms part of the Terms of Service v2.1 by reference at Terms § 1.5 and governs all use of the Services by Customer, Customer's admin users, Agent Operators, and anyone else accessing the Services (collectively, "Users"). In the event of a conflict between this AUP and the Terms of Service v2.1 on a prohibited-use matter, this AUP governs.
1.2 Who this binds
Customers are responsible for ensuring that their admin users, contractors, and anyone using the Services under Customer's account comply with this AUP. Agent Operators are directly bound by the Agent Operator Supplemental Terms at Terms of Service v2.1 § 11, which incorporate this AUP. Facet's Services are provided for legitimate commercial use by businesses and their authorized personnel.
1.3 Interpretation
Examples listed under any prohibition are illustrative and not exhaustive. Where Users are uncertain whether conduct is prohibited, the safer reading is that it is prohibited, and Users should contact [email protected] for guidance before proceeding. Capitalized terms not defined in this AUP have the meaning given in the Terms of Service v2.1 and the Privacy Policy v2.1.
Prohibited content.
Users will not use the Services to transmit, store, distribute, or facilitate content that falls into any of the following categories:
2.1 Unlawful content
Content that violates any law applicable in any jurisdiction where the content is authored, stored, transmitted, or made available, including civil and criminal law, consumer-protection law, product-safety law, financial-services law, and sectoral regulations.
2.2 Intellectual-property infringement
Content that infringes a third party's copyright, trademark, patent, trade-secret, publicity, moral, or other intellectual-property right. The DMCA / Copyright Policy v2.0 at facet.llc/legal/copyright.html describes the takedown and counter-notification mechanism.
2.3 Fraud, deception, and impersonation
Content that is fraudulent, deceptive, or misleading, including phishing, scam pages, fake-review content, impersonation of a natural or legal person without authorization, and synthetic or deepfake content generated or distributed with intent to mislead.
2.4 CSAM, absolute zero-tolerance
Child sexual abuse material (CSAM) is categorically prohibited, including content that is apparent CSAM as defined in 18 U.S.C. §§ 2256(8). Facet reports apparent CSAM to the National Center for Missing & Exploited Children (NCMEC) in accordance with its reporting obligation under 18 U.S.C. § 2258A and preserves relevant content and metadata pursuant to 18 U.S.C. § 2258A(h). Facet cooperates with law enforcement as required by 18 U.S.C. § 2258A(e). A confirmed CSAM incident is grounds for immediate termination under Section 7.3 and for law-enforcement referral regardless of appeal.
2.5 Violence, harassment, stalking, doxxing
Content that threatens, incites, promotes, or facilitates violence against a person, group, or identifiable population; stalking, harassment, or coordinated group harassment; doxxing (publication of non-public personal information to facilitate harm); or targeted abuse based on protected characteristics.
2.6 Hate content and extremism
Content that promotes, glorifies, or incites hatred, discrimination, or violence against individuals or groups on the basis of race, ethnicity, national origin, religion, gender, gender identity, sexual orientation, disability, caste, or other protected classification. Content affiliated with foreign terrorist organizations designated under 8 U.S.C. § 1189, or equivalent domestic designations.
2.7 Adult and sexually explicit content
Services are not intended for adult entertainment or sexually explicit commerce. Users will not distribute sexually explicit content or operate adult-entertainment marketplaces through the Services without a separate written agreement. This prohibition does not affect legitimate Customer operation of content-warning flags or educational and medical content served in compliance with applicable law.
2.8 Dangerous goods and regulated substances
Content or commerce offers involving weapons, explosives, ammunition, hazardous materials, or controlled substances as defined by the U.S. Controlled Substances Act (21 U.S.C. § 801 et seq.), equivalent non-U.S. controlled-substances regimes, Schedule I through V substances, and pharmaceutical products requiring prescription or practitioner oversight in the destination jurisdiction. Where commerce touches these categories and is lawful in a specific jurisdiction (for example, licensed cannabis dispensaries under state law), Users must be properly licensed and must restrict availability to permitted jurisdictions.
2.9 FDA-regulated claims
Users will not use the Services to make claims that a product is intended to diagnose, mitigate, treat, cure, or prevent a disease, unless the product has been cleared or approved for that use by the U.S. Food and Drug Administration or the equivalent non-U.S. authority with jurisdiction. Users will comply with the U.S. Federal Food, Drug, and Cosmetic Act (21 U.S.C. § 301 et seq.) and its nutrition-labeling requirements (21 CFR Part 101), and, where applicable, FSMA 204 traceability requirements (21 U.S.C. § 2223; 21 CFR Part 1 Subpart S).
2.10 Public-safety threats
Content that constitutes bomb threats, incitement of mass-violence events, or operational instructions for attacks on critical infrastructure. Facet will report such content to law enforcement where reasonably believed to pose imminent risk.
2.11 Unauthorized collection of Personal Data
Content or conduct that collects Personal Data in violation of applicable law, without a lawful basis, or without required notices and consents. Users are responsible for compliance with GDPR, UK GDPR, Swiss FADP, CCPA/CPRA, the U.S. state comprehensive privacy laws listed in Privacy Policy v2.1 § 14, and sectoral laws (HIPAA, GLBA, FERPA, COPPA, CAN-SPAM, TCPA, VPPA) applicable to Customer's content and data practices.
Prohibited technical conduct.
Users will not, and will not permit any third party to:
- Identity forgery or impersonation. Forge, misuse, or replay Facet KYA tokens, KYAPay tokens, DID records, API keys, OIDC claims, or any other credential; impersonate another Customer, Agent Operator, or Facet employee; or represent in any material respect that the User is not the User.
- Signature and provenance integrity. Alter, remove, replay, or misrepresent payloads signed under RFC 9421; tamper with or misattribute Ed25519 signature artifacts; present a previously-issued signed response as if it were freshly issued; or misuse Provenance Artifacts (as defined in Terms of Service v2.1 § 11.6(b)) to assert claims not supported by the underlying signed data.
- Rate-limit abuse and denial-of-service. Circumvent rate limits or pricing through token rotation, IP address rotation, or identity fragmentation; launch denial-of-service or distributed denial-of-service attacks against the Services, a Customer Terminal, an Agent Operator, or a third-party system; or cause a sustained traffic pattern reasonably likely to cause performance degradation for other Users.
- Reverse engineering. Copy, modify, translate, reverse engineer, decompile, or disassemble the Services, except to the extent that (a) the law of Customer's jurisdiction expressly permits it notwithstanding contractual restriction (including EU Software Directive 2009/24/EC Art. 6 interoperability rights) or (b) Facet grants prior written consent.
- Scraping-laundering. Use a Facet Terminal or the Agent Identity Gateway to dress unconsented retrieval of third-party content in the trust signals of Facet-issued provenance, i.e., scrape a property that has not consented to agent-mediated access and present the harvested content as if it had been served through a legitimate Facet Terminal. This prohibition applies regardless of whether the underlying scrape would be lawful on its own; the specific prohibition is the misuse of Facet's identity and signing rails to mask the retrieval.
- Malware and security-control circumvention. Introduce or distribute malware, viruses, worms, trojans, spyware, ransomware, cryptojackers, or similar harmful code; circumvent access controls, authentication, or security measures of the Services, of a Customer's property, or of a third-party system.
- Security testing without consent. Benchmark, load-test, penetration-test, or stress-test the Services without Facet's prior written consent. Good-faith security research under the Facet vulnerability-disclosure program described in Security v2.0 § 9 is permitted on the scope and terms set out there.
- Competitive product creation. Access the Services to extract ideas, features, functions, or graphics for the purpose of building a competitive product or service, or to build a functional equivalent or derivative service.
- Tax, export, and sanctions evasion. Use the Services for structured transactions or identity fragmentation designed to evade tax reporting, export-control obligations, or the sanctions regimes identified in Terms of Service v2.1 § 9.10 (OFAC, EAR, ITAR, EU Regulation 2021/821, and equivalent).
Prohibited data uses.
4.1 No training of AI or ML models without written license
Users will not use Customer Data, supplier-catalog data, agent traffic, or any Service output to train, fine-tune, align, or otherwise improve foundational artificial-intelligence or machine-learning models, absent a separate written Data Licensing Agreement executed between the parties. This prohibition binds Customer, Agent Operators, and any third party accessing the Services through Customer's account.
4.2 No resale or redistribution of Service output
Users will not resell, redistribute, relicense, or make available to third parties any Service output (including Terminal responses, Provenance Artifacts, aggregated classifier counts, and reputation-registry signals) outside Customer's internal business operations, absent a separate written agreement.
4.3 No use of Service data to re-identify individuals
Users will not attempt to re-identify any natural person from aggregated, de-identified, or pseudonymized data served through the Services, and will not combine Service data with other data sources for the purpose of re-identification.
4.4 No supplier PII exfiltration
Users will not use the Services to extract Personal Data about Customer's end customers, employees, or other natural persons beyond what is necessary to fulfill a specific Customer-initiated transaction. The Services are engineered to minimize PII flow (see Privacy Policy v2.1 § 3); Users will not reverse this minimization.
4.5 No children’s data
Users will not use the Services to collect Personal Data from children under the applicable age of digital consent described in Privacy Policy v2.1 § 12 (COPPA 13 / GDPR 16 EEA default / UK 13) without verifiable parental consent and the additional protections required by the applicable law.
Agent-specific prohibitions.
In addition to the prohibitions in Sections 2, 3, and 4, Agent Operators will not:
- Operate agents that forge, misattribute, or omit the identity claims required by Terms of Service v2.1 § 11.1 (Facet KYA token, accepted KYAPay token, or accepted DID).
- Operate agents that take actions inconsistent with the Agent Operator's configured scope, including actions that cause unauthorized financial transactions (Terms of Service v2.1 § 11.6(d), autonomous-agent attribution to the Agent Operator).
- Operate agents that generate synthetic or deceptive traffic designed to distort supplier analytics or Agent Reputation Registry signals.
- Fail to implement the human-in-the-loop or supervision controls Facet provides when a competent authority has determined that a category of agent action requires supervision (Terms of Service v2.1 § 11.6(d) fallback position).
- Bypass, disable, or tamper with the Identity Gateway, rate limiter, or audit-log generator that supports Facet's platform-integrity commitments.
Reporting abuse.
6.1 Report channels
Anyone may report a suspected violation of this AUP by emailing [email protected]. Intellectual-property infringement claims should follow the DMCA / Copyright Policy v2.0 at facet.llc/legal/copyright.html. Security vulnerabilities should be reported per Security v2.0 § 9.
6.2 Contents of a report
To expedite review, reports should include: (a) the property or account allegedly in violation; (b) a description of the alleged violation with reference to the specific Section of this AUP; (c) the reporter's contact details and relationship to the subject matter; (d) any supporting evidence (URLs, request IDs, timestamps, screenshots, logs). Incomplete reports may delay review.
6.3 Response
Facet acknowledges reports within two (2) business days of receipt. Substantive response time depends on severity (see Section 7). Reporter identity is treated as confidential unless disclosure is required by law or reasonably necessary for the investigation; CSAM and imminent-public-safety reports may be escalated directly to law enforcement.
Enforcement ladder.
7.1 Warning (“notice and cure”)
For a low-severity or first-time violation, Facet may issue a written warning to the account owner describing the alleged violation and requiring cure within seven (7) days. Warnings are recorded on the account record.
7.2 Suspension
For a material or repeated violation, a failure to cure after a warning, or conduct reasonably believed to pose imminent risk to the Services or other Users, Facet may suspend the affected User's access to some or all of the Services for the duration reasonably necessary to contain the risk and complete review. Suspension does not relieve the User of payment obligations and does not extend the subscription period, consistent with Terms of Service v2.1 § 8.5.
7.3 Termination
For a severe violation, a pattern of violations, or a confirmed prohibited-content event (including CSAM, apparent CSAM, imminent public-safety threat, or confirmed violation of Section 2.8 or Section 2.9 with intent), Facet may terminate the Agreement under Terms of Service v2.1 § 8.2 immediately on written notice and without a cure period. Termination includes revocation of API keys, deletion of signing keys, removal from the Fingerprint Registry, and, where relevant, a final reputation-registry action under Section 7.4.
7.4 Network-wide reputation action
For violations that degrade platform integrity or that harm other Customers or Agent Operators, Facet may record a network-wide reputation action in the cross-site Agent Reputation Registry, which may cause other Customer Terminals to price, rate-limit, or deny traffic from the affected Agent Operator or account. Reputation actions are scoped to the specific violating conduct and are subject to appeal under Section 8.
7.5 Preservation and law-enforcement cooperation
Where a violation involves suspected criminal conduct, Facet will preserve relevant data under a litigation hold and cooperate with law enforcement as described in Section 9. Preservation is in addition to, and not in lieu of, any enforcement action under this Section 7.
7.6 Proportionality
Facet applies enforcement actions proportionate to the severity, intent, and impact of the violation. Facet may skip steps up the ladder where conduct reasonably warrants immediate suspension or termination (for example, CSAM, imminent-risk, confirmed signature forgery at scale). Facet may also pause enforcement where the User commits to a remediation plan and Facet's review confirms good-faith compliance.
Appealing an enforcement action.
8.1 Right to appeal
A User subject to a warning, suspension, termination, or reputation action under Section 7 may appeal by emailing [email protected] within fifteen (15) days after receiving written notice of the enforcement action. Appeals submitted after fifteen (15) days may be accepted at Facet's discretion.
8.2 Contents of an appeal
The appeal should state: (a) the enforcement action being appealed; (b) the specific grounds on which the User contends the action was wrongly imposed or wrongly scoped; (c) supporting evidence or documentation; and (d) the remedy requested.
8.3 Human review
Facet will conduct a human review of each timely appeal by a reviewer who was not involved in the original enforcement decision. The reviewer will assess the original record, the User's submitted materials, and any additional evidence the reviewer reasonably requests from the User. The reviewer may, on an anonymized basis, consult independent subject-matter experts.
8.4 Outcome
Facet will issue a written outcome within fifteen (15) business days of receiving a complete appeal, with one of the following outcomes: (a) upheld, the original action stands; (b) modified, the original action is reduced in severity, scope, or duration; (c) reversed, the original action is withdrawn and any reputation-registry entry removed; or (d) conditional, reinstatement subject to a documented remediation plan. The outcome identifies the factual and policy grounds for the decision.
8.5 Final determination
The appeal outcome is Facet's final administrative determination for purposes of this AUP. Nothing in this Section 8 limits a User's rights to pursue disputes under Terms of Service v2.1 § 9 (binding individual arbitration or, for excluded claims, Delaware courts).
8.6 No appeal for CSAM or imminent-risk actions
Appeals are not available for enforcement actions taken in response to CSAM, apparent CSAM, imminent public-safety threats, or confirmed violations of Section 2.4 generally. Such actions are irrevocable; affected Users may submit factual clarifications in writing to [email protected] for record only.
Law-enforcement cooperation.
9.1 Government request policy
Facet responds to law-enforcement requests in accordance with its Government Request Policy described in Privacy Policy v2.1 § 9.5 and DPA v2.1 § 7.4: review legal validity; challenge overbroad, facially invalid, or legally impermissible requests; narrow the scope of disclosure to what is legally required; and, where not legally prohibited, give prompt written notice to the affected Customer or data subject so they may challenge.
9.2 NCMEC reporting for CSAM
Facet reports apparent CSAM to NCMEC in accordance with 18 U.S.C. § 2258A and preserves relevant content and metadata pursuant to 18 U.S.C. § 2258A(h) regardless of User appeal status.
9.3 Emergency disclosure
In emergency circumstances involving an imminent threat of death or serious bodily injury, Facet may disclose User information to law enforcement in accordance with 18 U.S.C. § 2702(b)(8), (c)(4) without a subpoena or warrant, consistent with the governing standard for such disclosure.
9.4 Preservation
On receipt of a valid preservation request under 18 U.S.C. § 2703(f) or equivalent, Facet preserves identified data for up to ninety (90) days (renewable once). Preservation does not constitute disclosure and does not waive any challenge rights.
9.5 Transparency reporting
Facet will publish a periodic transparency report summarizing categories and volumes of law-enforcement requests received, challenged, and complied with, consistent with U.S. legal constraints. The report schedule is described in Security v2.0.
Changes to this AUP and how to contact us.
10.1 Changes
Facet may update this AUP from time to time. The version number and Effective Date in the eyebrow reflect the current version. For material changes, additions to prohibited categories, changes to the enforcement ladder, or changes to appeal mechanics, Facet will provide at least thirty (30) days prior written notice under the procedure in Terms of Service v2.1 § 1.3. Non-material changes (clarifications, formatting corrections, typographical corrections, contact-detail updates) may be made without notice.
10.2 Contact
Abuse reports: [email protected]
Appeals: [email protected]
Law-enforcement requests: [email protected]
Security disclosures: [email protected]
Postal: Facet, LLC, Attn: Legal, 1 Market St, Suite 100, San Francisco, CA 94105