You may not use Truvyo to
- Process regulated data outside an Enterprise contract — including Protected Health Information (PHI), payment card data subject to PCI-DSS, or financial data subject to GLBA — without a signed addendum covering that category.
- Deploy the Service to sanctioned parties or in countries subject to comprehensive US or EU embargoes (currently: Cuba, Iran, North Korea, Syria, the Crimea region of Ukraine, the so-called DNR/LNR regions). Customer warrants it is not on any restricted-party list.
- Process data of minors under 13 (or under 16 in the EEA) without an executed COPPA / GDPR compliance addendum.
- Generate or facilitate harassment, threats, harmful misinformation, malware, fraud, or unauthorized impersonation of any person or organization.
- Attempt to extract Truvyo's Shared Library content via prompt injection, repeated retrieval probing, automated scraping, or any other circumvention. The lack of an extract endpoint is by design; attempts to exfiltrate are an AUP violation.
- Reverse-engineer the Service beyond what is permitted by mandatory law, or use the Service to build a competing AI support engine.
- Benchmark or publish performance data about the Service without written consent. (We're happy to consent for honest benchmarks — email legal@truvyo.ai before publication.)
- Resell or sublicense the Service except as expressly permitted in a signed reseller agreement.
- Send unsolicited bulk messages through Truvyo. The Service is inbound-only by design; using it for outbound messaging violates this Policy.
- Interfere with or disrupt the Service, including rate-evasion, key-sharing across organizations, or unauthorized load testing. Coordinate any load testing with us at security@truvyo.ai.
Enforcement
We monitor for AUP violations through abuse signals (high error rates, suspicious traffic patterns, third-party complaints). Suspected violations may trigger a warning, suspension, or immediate termination per the severity. We notify the Customer's primary contact unless prohibited by law or unless notification would impede an investigation.
Reporting
To report suspected abuse of the Service by a Truvyo Customer, email abuse@truvyo.ai. To report a security vulnerability, see the Security Overview.