Legal

CrescendoLabs Acceptable Use Policy

Effective date: August 23, 2026 · Version: 1.0


1. Introduction & Scope

This Acceptable Use Policy (this "AUP") sets out the activities that are prohibited when accessing or using the Crescendo Agentic Platform and all related applications, surfaces, APIs, and features (the "Services"). It supplements, and is incorporated by reference into, the Terms of Service between you and Crescendo Labs AI, Inc. ("CrescendoLabs," "we," "us," "our"). Capitalized terms used but not defined here have the meanings given in the Terms of Service.

If there is a conflict between this AUP and the Terms of Service, the Terms of Service control; this AUP adds detail to, and does not narrow, your obligations under ToS §7 (Customer Responsibilities; Acceptable Use).

We may update this AUP as described in Section 8. Violating this AUP is a material breach of the Terms of Service and may result in the actions described in Section 6.

2. Who This Policy Applies To

This AUP applies to you (the Customer) and to every Authorized User you permit to access the Services under your account.

Two layers of acceptance. The Customer accepts the Terms of Service, which binds the Customer (the company or individual account holder) to the full commercial agreement. Each Authorized User, when accepting an invitation to the Services, accepts this AUP directly and acknowledges that the Customer's Terms of Service govern their use of the Services. An Authorized User does not separately accept the commercial terms — the Customer has already accepted those on the organization's behalf — and does not thereby become a party to them (see Section 9).

Customer responsibility (independent of any user acceptance). You are responsible for your Authorized Users' compliance with this AUP and for all activity that occurs under your account or credentials, as provided in ToS §4 (Account Security). You must ensure that each Authorized User is bound by, and complies with, terms at least as protective as this AUP. An act or omission by an Authorized User that would breach this AUP if taken by you is deemed a breach by you.

3. Prohibited Activities

You and your Authorized Users must not, and must not permit or enable any third party to:

(a) Break the law or violate others' rights. Use the Services in violation of any applicable law, regulation, or third-party right, including intellectual-property, privacy, publicity, contract, export-control, or sanctions laws.

(b) Upload harmful, infringing, or objectionable content. Submit to the Services any content or data that is unlawful, infringing, defamatory, fraudulent, or that contains malware, ransomware, or other malicious or destructive code, or that you do not have the right to submit.

(c) Breach security or tenant isolation. Attempt to access, read, or modify any data, account, or tenant that is not yours; circumvent, disable, or probe authentication, authorization, tenant-isolation, or other security or access-control mechanisms; or conduct penetration testing, vulnerability scanning, or security research against the Services without our prior written authorization.

(d) Disrupt or overburden the Services. Exceed documented rate limits or usage limits; interfere with, degrade, or disrupt the integrity or performance of the Services or the infrastructure that hosts them (including denial-of-service activity); or use bots, scrapers, or other automated means to access the Services except through interfaces and API credentials we provide for that purpose. You must not use the Services' automated or agentic capabilities to generate abusive volumes of outbound actions against third-party platforms connected to the Services (for example, accounting, payment, or messaging providers), to circumvent those platforms' rate limits, or to violate their terms of service.

(e) Reverse-engineer, resell, or build a competing product. Reverse-engineer, decompile, or disassemble the Services or attempt to derive their source code, models, prompts, or underlying methods (except to the extent this restriction is prohibited by law); rent, lease, resell, sublicense, time-share, or operate a service bureau with the Services; or use the Services to develop, train, or improve a competing product, model, or service.

(f) Misuse the AI and automated features. In connection with the analysis, Insights, Recommendations, and other AI or automated features:

  • attempt to extract, reconstruct, or reverse-engineer the underlying AI Models, system prompts, weights, or training data, or to circumvent safety, content, or usage guardrails;
  • use outputs of the Services to train or improve a competing AI model, or to build a dataset for that purpose;
  • submit inputs — directly, or through content, documents, or connected sources you bring into the Services — that are designed to cause the Services to generate unlawful content, defeat tenant isolation, circumvent guardrails, take unauthorized agentic actions, or exfiltrate another customer's data or our confidential information (if you become aware that content from your sources contains such material, you must promptly notify us and cooperate to remove it); or
  • present Insights or Recommendations to third parties as guaranteed outcomes or as professional advice in a manner inconsistent with ToS §11(b) (Recommendations are information, not advice).

(g) Bring in data you lack rights or consent to use, or that is off-limits. Submit or connect data — including your end-customers' or employees' Personal Information, financial data, or health data — without the rights and consents required for that data and for our processing of it as permitted under the Terms of Service (ToS §7, §8). In addition, and regardless of any consent you may hold, you must not submit to the Services:

  • payment card data (full card numbers, magnetic-stripe data, or CVV) other than through the designated third-party payment processor;
  • protected health information subject to HIPAA, unless CrescendoLabs has signed a Business Associate Agreement with you covering that data; or
  • personal information of children under 13, or other data subject to COPPA.

This restriction does not limit the ordinary business and financial data the Services are built to process (for example, transactions, invoices, bills, payroll amounts, and the employee records you are authorized to maintain).

(h) Provide regulated professional advice without a license. Use the Services, or their Insights or Recommendations, to provide financial, investment, legal, tax, accounting, insurance, or other regulated professional advice to third parties in a manner that violates applicable licensing, registration, or professional-conduct laws. You are solely responsible for your own regulatory and licensing compliance. CrescendoLabs' provision of the Services does not make CrescendoLabs a participant in, or supervisor of, any advice you provide, and creates no advisory, fiduciary, or professional relationship between CrescendoLabs and you or your clients (see ToS §11(b)).

(i) Abuse accounts, access, or identity. Share or transfer credentials in violation of the Terms of Service; misrepresent your identity or affiliation; create accounts by automated means or to evade a suspension, termination, or usage limit; or use the Services to send unsolicited or unlawful communications (spam).

4. Third-Party and AI Provider Acceptable Use

The Services rely on third-party sub-processors, including AI Service Providers (disclosed in our sub-processor list, per ToS §11(e)). Your use of the AI features must also comply with the acceptable-use or usage policies of those AI Service Providers, as made available in or linked from our sub-processor list at https://crescendolabs.ai/legal/subprocessors. You must not use the Services in a way that would cause CrescendoLabs to violate any sub-processor's terms. Those providers may change their usage policies, access, or terms at any time; continued use of the affected features after such a change is subject to the updated policy, and CrescendoLabs may modify or discontinue affected features in response (ToS §9). You are responsible for losses, penalties, or fees a sub-processor imposes on CrescendoLabs to the extent caused by your or your Authorized Users' violation of this Section.

5. Your Responsibilities

You are responsible for: (a) all activity under your account and credentials; (b) your Authorized Users' compliance with this AUP; (c) obtaining and maintaining the rights and consents required for the data you or your connected sources bring into the Services (ToS §7); and (d) promptly notifying us if you become aware of any violation of this AUP or any unauthorized access to your account.

6. Monitoring and Enforcement

We are not obligated to monitor use of the Services, but we may review activity, content, and logs as needed to operate, secure, and improve the Services and to enforce this AUP and the Terms of Service.

If we determine, in our reasonable discretion, that you or an Authorized User has violated this AUP, we may — with or without notice, as the circumstances warrant — take any of the following actions, consistent with ToS §15 (Term; Termination; Suspension):

  • investigate the suspected violation;
  • remove, disable, or quarantine offending content or configurations;
  • throttle, suspend, or terminate access to the Services (in whole or in part), including immediate suspension for security threats, unlawful use, non-payment, or attempts to extract, misappropriate, or reverse-engineer the Services' models, prompts, or methods (§3(e)–(f); ToS §15);
  • report activity to, and cooperate with, law enforcement or other authorities where legally required or appropriate; and
  • pursue any other remedy available under the Terms of Service or at law.

How and when we apply these actions is governed by the notice, cure-period, and immediate-suspension framework in ToS §15 (Term; Termination; Suspension) — a material violation is subject to the notice-and-cure period stated there before suspension or termination, and security threats, unlawful use, non-payment, or attempts to extract, misappropriate, or reverse-engineer the Services' models, prompts, or methods may result in immediate suspension. This AUP does not create a separate or conflicting enforcement ladder.

7. Reporting Abuse

To report a suspected violation of this AUP, a security vulnerability, or abuse of the Services, contact us at security@crescendolabs.ai.

8. Changes to This Policy

We may update this AUP from time to time to reflect changes in the Services, our AI Service Providers' requirements, or applicable law. For material changes we will provide advance notice (e.g., by email or in-product) before they take effect, consistent with ToS §21 (Changes to These Terms); non-material changes are effective when posted. Your continued use of the Services after the effective date constitutes acceptance of the updated AUP.

9. Relationship to Other Agreements

This AUP is part of, and governed by, the Terms of Service, including its provisions on governing law and venue (ToS §20), dispute resolution (ToS §19), and limitation of liability (ToS §17). Our handling of Personal Information is described in the Privacy Policy. Nothing in this AUP grants any right not otherwise granted under the Terms of Service.

Where an Authorized User accepts this AUP without being the Customer, that acceptance binds the Authorized User to this AUP individually and constitutes their acknowledgment that the Customer's Terms of Service govern their use of the Services; it does not make the Authorized User a party to the commercial terms, which remain between CrescendoLabs and the Customer.