Skip to content

Legal

Acceptable Use Policy

Rules for using nox.markets: illegal content, ePHI, children’s data, tenant isolation, automation limits, and enforcement when a workspace is misused.

Last updated: 16 September 2026
Operator: NOX AETERNA GROUP LLC, a Wyoming limited liability company, trading as nox.markets, 5830 E 2nd St, Ste 7000 #34506, Casper, WY 82609, USA
Related documents: Terms of Service, Privacy Policy, DPA

This Acceptable Use Policy (AUP) applies to every workspace and user on nox.markets. It is part of the Terms. We may suspend or terminate for breach, as the Terms describe.

nox.markets sells tools, agents, workflows, and packs. Customer is the operator of those products. We are not the decision-maker of record for Customer’s hiring, credit, lending, housing, insurance, or similar legally restricted automated decisions.


1. Lawful use only

Customer may not use the Service to:

  • Violate US federal law, the law of the State of Wyoming, or the law of any jurisdiction where Customer operates
  • Infringe intellectual property or privacy rights
  • Process or transmit illegal content, including child sexual abuse material
  • Commit fraud, phishing, or social-engineering against third parties
  • Distribute malware, or operate a botnet, from or through the Service

2. Security and tenancy

Customer may not:

  • Attempt to break tenant isolation, access another customer’s workspace, or scrape other customers’ data
  • Probe, scan, or load-test the Service except as agreed in writing or under the Security Disclosure Policy
  • Bypass authentication, spend ceilings, or the circuit breaker
  • Share credentials, or resell the Service, except as an authorized affiliate under Customer’s own account
  • Reverse engineer the Service, except where Wyoming or other applicable law gives a right to do so that cannot be waived
  • Use the Service to mine cryptocurrency or to run unrelated high-volume compute

Good-faith security research must follow /legal/security-disclosure. DoS, social engineering of staff or customers, and exfiltration beyond a minimal proof of isolation failure are forbidden.


3. Forbidden data classes

Until a signed BAA is in force, Customer must not submit ePHI (protected health information) into run_payload, workspace_config, support tickets, or connected pipelines that land in our regions. HIPAA is not offered on Starter, Growth, or Scale. A BAA is Planned for Enterprise only, target 2027-06-30, status on /trust. “HIPAA certified” is not a status we claim.

Customer must not submit personal data about children under 16, biometric identifiers for unique identification, or other classes the product page or DPA Exhibit A excludes.

Customer must not paste card PAN, CVV, or bank-login passwords into the app. Payments go through Stripe. Bank connections, when a product lists Plaid, go through Plaid.

self-hosted does not authorize forbidden classes on our license service; it only keeps Customer documents off our production datastore.


4. Models, automation, and finance approval

Customer may not use the Service to make fully automated decisions that Customer is legally forbidden to automate without a human (including, where applicable, certain credit, employment, housing, or similarly significant decisions). Customer is the operator. We are not the decision-maker of record.

For finance-backoffice agents and workflows, human approval exists and is the default. Customer must not disable approval where law or Customer’s own controls require a human. We log the setting. Disabling approval is Customer’s instruction and Customer’s risk; we do not describe model output as “human reviewed” unless a human actually clicked.

Customer may not prompt products to invent late fees, legal threats, credit-bureau reporting, payroll filings, tax returns, or payments that Customer’s contracts and systems do not authorize. Product refusals on catalog pages are part of this AUP.

Customer may not attempt to use model calls to train a competing model on our system prompts, eval sets, or other customers’ content.


5. Integrations and third parties

OAuth grants must be scoped to Customer’s own tenants. Customer may not connect another organization’s systems without authority.

Customer remains responsible for content written back to QuickBooks, HubSpot, mailboxes, Slack, payroll, and banks.

Abuse of connected APIs (spam email at scale, harassment, unsolicited marketing in violation of CAN-SPAM/CASL/GDPR) is a breach even if a product can technically send the message.


6. Resource abuse

Customer must stay within published concurrency, integration, workspace, and credit limits for its tier. Circumventing metering, creating shims to hide overage, or running a single logical workload across sock-puppet accounts is a breach.

The 3× grant circuit breaker may pause runs until we talk. That is a contract control, not only a dashboard banner.


7. Enforcement

We may investigate reasonably suspected breaches, including reviewing run_metadata and, under break-glass rules, run_payload. We may notify Customer’s owner, suspend products or the workspace, revoke integrations, and preserve data for legal hold.

We will not pay a ransom. We may report criminal activity to authorities.


8. Changes

Material AUP changes follow the Terms’ change process (email to owner, 30 days where required).