Acceptable Use Policy
This policy applies to everyone who requests, is granted or uses access to the recuritylab platform, including through the API, the MCP server and AI agents. [It forms part of the customer agreement.] Use of the website is covered by our Terms of Use.
Definitions (shared with Privacy Policy and Terms of Use): “recuritylab”, “we”, “us” and “our” mean Recuritylab LLC. The “site” is the website at recuritylab.com. The “platform” is the recuritylab virtual-device service, including its API, MCP server and AI agents.
Summary
This summary is not a substitute for the full policy below.
- recuritylab is for authorized, lawful, defensive security work only.
- Test only apps, devices and systems you own or are explicitly authorized to test.
- No unauthorized access, no surveillance or spyware, no targeting of individuals, no weaponising or selling exploits against others, no abuse of the platform.
- A person reviews every customer before access is granted, and we may decline any request.
- Export-control and sanctions rules apply to who may use the platform.
- Misuse can lead to a warning, suspension or termination, and may be reported to the authorities.
- To report misuse, email [ABUSE CONTACT].
Our commitment
recuritylab exists to help security teams, researchers, developers and educators find and fix weaknesses in iOS and Android software. The same capabilities that make that possible — jailbroken and rooted virtual devices, deep inspection and AI agents that act on them — could cause harm in the wrong hands.
We are committed to lawful use of our technology and to respecting privacy and human rights.
This policy is owned by [POLICY OWNER].
Who this policy applies to
This policy applies to our customers and to everyone who uses the platform through them: employees, contractors, evaluation users, university-programme participants and trainees. Each customer is responsible for its users’ compliance.
It applies however the platform is reached — through any interface, the API, the MCP server or AI agents — and however it is deployed.
If this policy and the customer agreement conflict, [the customer agreement prevails].
Authorized use
You may use the platform for:
- security testing of apps you own, or that you have written authorization to test;
- vulnerability research and malware analysis for defensive purposes;
- mobile development, continuous integration and quality assurance;
- education and training, including our university program.
Authorization to test anything you don’t own must be documented, cover the work you are doing, and be current. Keep it on record and give it to us if we ask.
You must comply with all laws that apply to you, including laws on computer misuse, privacy and data protection, and intellectual property.
If your testing exposes personal data or other third-party data, access only what your engagement requires, protect it, and handle it lawfully and in line with your authorization.
Prohibited uses
You must not use the platform, or allow anyone else to use it, for any of the following.
Unauthorized access
- Accessing, testing or interfering with any device, app, account, network or service without its owner’s authorization.
Surveillance and targeting
- Developing, testing, deploying or distributing malware, spyware, stalkerware or surveillance tools for offensive or unlawful use.
- Targeting journalists, activists, human-rights defenders or any other individual.
Unlawful data
- Processing data that was obtained unlawfully, or accessing personal data outside a lawful, authorized engagement.
Exploits and disclosure
- Selling, brokering or weaponising vulnerabilities or exploits for use against third parties.
- Disclosing vulnerabilities outside coordinated or responsible disclosure practice.
Third-party rights
- Infringing third-party intellectual property, or breaching platform-vendor terms where applicable law makes that unlawful.
Platform abuse
- Getting around access controls, usage limits or isolation.
- Attacking the platform or other customers.
- Sharing credentials.
- Reselling, sublicensing or giving third parties access without our written consent.
- Using the platform to evade sanctions or export controls.
Anything unlawful
- Any use that breaks applicable law.
AI agents and automation
AI agents, MCP clients and API automation act on your behalf. Everything in this policy applies to them exactly as it applies to you.
You are responsible for the instructions you give agents and for keeping their actions within your authorized scope. Never use an agent to reach systems outside that scope. Prohibited uses stay prohibited when an agent or script performs them.
We expect a person to oversee consequential actions. We may apply technical safeguards to agent activity and log it for safety and abuse prevention, as described in the customer agreement [and the privacy notice that covers platform users].
Who we work with: customer vetting
A person reviews every request for access before it is granted. Nothing is approved automatically.
As part of that review, we may verify [CONFIRMED CHECKS — e.g. your identity, your organization, where you are based and how you intend to use the platform].
We may decline a request, or end a customer relationship, at our discretion — including when we cannot verify the information you give us.
We review these rules periodically.
Export controls and sanctions
The platform and related technology may be subject to export-control and sanctions laws, including those of [REGIMES — e.g. the United States, the European Union and the United Kingdom].
We do not provide access to people or organizations on those lists, or to anyone located or ordinarily resident in an embargoed country or region. You must not re-export the platform or transfer access in breach of these laws, and you remain responsible for your own compliance.
This section is consistent with our Terms of Use.
Enforcement
We may investigate any suspected breach of this policy, including by reviewing usage and logs as allowed by the customer agreement [and the privacy notice that covers platform users].
Depending on the seriousness of the breach, we may:
- warn you;
- suspend specific users, devices, or API or MCP credentials;
- terminate your access and the customer agreement [without refund, where the contract allows].
We may preserve relevant evidence. We cooperate with competent authorities and report to them where the law requires it or where we consider it appropriate.
If you learn that one of your users is misusing the platform, tell us promptly.
Reporting misuse
Anyone can report suspected misuse of recuritylab — customers, researchers, journalists or members of the public.
Email: [ABUSE CONTACT]
Please don’t use our sales contact form for this. A useful report says what you saw, when, and anything that helps us identify the account or activity involved.
We keep reporters’ identities confidential to the extent the law allows. We will not tolerate retaliation by a customer against its own staff for reports made in good faith.
To report a security vulnerability in our own site or platform, use our vulnerability disclosure channel instead: [SECURITY CONTACT / /.well-known/security.txt] — see also Security.
Changes and contact
We may change this policy. We update the date at the top, give customers notice of material changes [NOTICE PERIOD], and changes take effect on the date shown.
Report misuse: [ABUSE CONTACT] · Legal notices: [LEGAL NOTICES EMAIL] · General questions: contact form