Acceptable Use Policy
This policy sets out what you can and can't do on OneNexus. It applies to everyone who uses the platform, including agents acting under your organization's configuration, analysts, reviewers, approvers and administrators alike, and it exists to protect the thing OneNexus actually sells: that a Sign means what it says.
01Scope and acceptance
All OneNexus Platform users must comply with this Acceptable Use Policy. This Policy places certain restrictions on the data you can upload, and how you use the OneNexus Platform, and applies to anyone with an account and to any agent, integration or API caller acting under your organization's OneNexus configuration.
Nexus reserves the right to determine whether content or use violates this Policy at its sole discretion. This Policy may be updated from time to time.
02Anti-discrimination
Nexus does not support and will not tolerate its Services being used to discriminate against others, especially when based on race, religion, sex, sexual orientation, age, disability, ancestry or national origin. You are not permitted to use the Services in a manner which would or would likely incite, promote or support such discrimination, and you must not use the Services to incite or promote hostility or violence. If we believe in our sole determination that your use of the Services is being used to discriminate, especially if based on race, religion, sex, sexual orientation, age, disability, ancestry or national origin, we may permanently or temporarily terminate or suspend your access to the Service without notice and liability for any reason.
03General use
You agree not to upload data or use the OneNexus Platform, directly or indirectly, in any manner that:
- Promotes, encourages or creates a risk of physical or mental harm, violence, emotional distress, death, disability, or disfigurement to yourself, any person, or animal;
- Promotes or creates a risk of harm, loss, or damage to any property;
- Seeks to or otherwise harms, grooms, abuses, sexualizes or exploits children (anyone under the age of 18);
- Is harassing, abusive, racially or ethnically offensive, defamatory, invasive of personal privacy or publicity rights, libelous, bullying, or threatening;
- Discriminates, incites, or promotes discrimination or is otherwise abusive against others based on race, religion, sex, sexual orientation, age, disability, ancestry, national origin, or any other basis;
- Is sexually explicit or pornographic, or contains intimate images shared without consent;
- Involves the sale or promotion of illegal activities, products, or services;
- Is fraudulent or promotes fraudulent activity;
- Violates the rights of any individual or third party, including their intellectual property and data privacy rights;
- Contains any information or content that you do not have a right to make available under any law or due to confidentiality, contractual, or fiduciary duties;
- Contains any information or disinformation that is false, deceptive, or misleading or otherwise promotes, endorses, encourages, or facilitates the spread of false information;
- Violates any applicable law or promotes activities that are illegal in nature, including terrorism;
- Threatens or undermines democratic processes or institutions.
04AI and agent-specific restrictions
OneNexus's whole premise is that a named party stands behind AI-produced work. That only holds if the platform's agent behavior isn't abused. You may not:
- Bypass the authorization-level model. Configure or use OneNexus so that AI-level output reaches a client, regulator or auditor represented as reviewed or approved at a human level, when it was not.
- Automate signing beyond delegated authority. Script, batch or otherwise automate an approval- or acceptance-level signature so that no human at that level actually reviewed the specific work being signed.
- Attempt prompt injection or model manipulation intended to make an agent misrepresent its confidence, skip a required correction step, or sign work outside the scope of its grant.
- Feed OneNexus data your organization isn't authorized to process, for example a client's data submitted without that client's consent where consent is required.
- Misrepresent a Sign's provenance by editing, forging or fabricating a SignChain record, or presenting a Sign as coming from a different signer, authorization or agent than the record shows.
05Signing and accountability integrity
A signer's authorization (their professional designation, certification, authorization level, and the warrant they sign against) is personal to them. You may not sign, or cause a system to sign, using authorization you don't hold or aren't entitled to act under. If your organization revokes someone's signing authority, it's your organization's responsibility to remove their access promptly. A Sign made after authority is revoked but before access is removed is still attributed to that person on SignChain.
06Enforcement
Violations may result in suspension or termination of access, for the individual user or, where the violation is systemic, for the organization's account, without notice and liability for any reason, at our sole discretion. We'll notify your organization's administrator where we take action, except where doing so would itself create a security or legal risk. Nothing here limits Nexus Frontier Tech's other rights under your Master Service Agreement or applicable law.
07Reporting a violation
If you believe OneNexus is being misused, whether by another user at your organization, by a counterparty, or by anyone else, report it to dpo@nexusfrontier.tech. Include what you observed and, where possible, the relevant Sign or SignChain entry ID. SignChain's audit trail makes most misuse traceable to a specific action.
08Changes to this policy
This Policy may be updated from time to time. We'll update the "Last updated" date above when it changes, and notify account administrators directly where a change is material.