1 Purpose and scope
This Acceptable Use Policy ("AUP") applies to all persons and entities that access or use Submersion AI's hosted models, application programming interfaces (APIs), and related hosted services (collectively, the "Services"), including access through authorized resellers or passthrough arrangements.
Submersion AI develops specialized models for cybersecurity applications. Those capabilities are dual-use. This AUP is designed to permit lawful, authorized security research and defensive use while prohibiting criminal, abusive, and unauthorized activity.
By accessing or using the Services, you agree to comply with this AUP. This AUP is incorporated into the applicable Terms of Service or customer agreement (the "Terms"). Capitalized terms used but not defined in this AUP have the meanings given in the Terms.
Submersion may update this AUP as the Services and associated risks evolve. Material changes will be reflected by an updated Effective Date.
2 Permitted use
You may use the Services only for lawful purposes, including without limitation:
- (a)Authorized Security Testing and Vulnerability Research. Security testing and vulnerability research directed at systems, applications, networks, cloud resources, accounts, or data that you own or for which you have express written authorization from the owner or other party with lawful authority.
- (b)Defensive Security Activities. Detection, triage, remediation planning, threat modeling, and security architecture review for environments you are authorized to assess or protect.
- (c)Training and Education. Use in controlled laboratory, capture-the-flag (CTF), cyber range, or classroom environments that you are authorized to use.
- (d)Product and Research Development. Development of security tools, workflows, or research that does not violate Section 3 or applicable law.
- (e)Ordinary Business Use. Other legitimate business purposes consistent with this AUP and applicable law.
Authorization Requirements. Before conducting any offensive testing or similar activity against a target, you must obtain clear authorization from the system owner or other party with legal authority, define an appropriate scope, and comply with applicable Rules of Engagement and law. You must retain authorization records and provide them to Submersion upon reasonable request.
Customer Responsibility. Outputs of the Services may be incomplete, inaccurate, or unsafe if relied upon without review. You remain solely responsible for verifying findings, configuring scope, safeguarding credentials, and ensuring that your use is lawful and authorized.
3 Prohibited use
You must not use the Services, including any Inputs or Outputs, to engage in any of the following activities.
3.1Unauthorized Cyber Activity
- (a)Test, scan, probe, exploit, access, disrupt, or otherwise affect any system, network, application, account, or data without authorization of the owner or other lawful authority;
- (b)Exceed approved scope, intensity, credentials, accounts, targets, or Rules of Engagement;
- (c)Cause denial of service, destructive activity, data corruption, or unnecessary disruption;
- (d)Steal, exfiltrate, or disclose data except for the minimal evidence reasonably necessary for an authorized finding and lawful disclosure;
- (e)Establish unauthorized persistence, backdoors, or covert long-term access;
- (f)Conduct phishing, social engineering, or physical security testing unless expressly authorized in writing for that engagement;
- (g)Extort, threaten, or sell or publish unremediated vulnerability information except through responsible disclosure to the owner or a coordinated vulnerability disclosure process; or
- (h)Create, distribute, or operate malware, ransomware, botnets, or similar tooling outside authorized defensive testing or research you are permitted to perform.
3.2Critical Infrastructure and High-Harm Targets
Without Submersion's prior written approval and lawful authorization from the relevant owner or authority, you must not use the Services to facilitate destruction, disruption, or unauthorized access targeting:
- (a)Power, water, telecommunications, air traffic control, medical devices or life-safety systems, voting systems, or similar critical infrastructure;
- (b)Military bases or related operational infrastructure; or
- (c)Healthcare clinical systems, financial-market infrastructure, or other environments where misuse could cause disproportionate harm.
Even where authorization is claimed, Submersion may require additional verification or decline high-risk targets.
3.3Violence, Weapons, and Mass Harm
- (a)Critically harm, or promote critically harming, human life; engage in or support terrorism or violent extremism; or provide material support to such organizations or individuals;
- (b)Design, produce, modify, or acquire weapons of mass destruction or their precursors (biological, chemical, radiological, or nuclear), high-yield explosives, or related delivery systems; or
- (c)Incite or facilitate violence, intimidation, or hateful targeting of persons.
3.4Child Safety
- (a)Create, seek, distribute, or promote child sexual abuse material, including AI-generated material; or
- (b)Groom, exploit, traffic, sextort, sexualize, or otherwise harm minors (any person under 18 years of age), including through fictional depictions or roleplay.
Submersion reports suspected child sexual abuse material and related exploitation to the National Center for Missing and Exploited Children (NCMEC) and other appropriate authorities as required.
3.5Fraud, Scams, and Deception
- (a)Engage in fraud, scams, phishing for criminal gain, identity theft, or social-engineering attacks outside authorized security testing;
- (b)Produce counterfeit goods or forged government identification, currency, credentials, or other falsified legal documents for unlawful purposes;
- (c)Generate spam, fake accounts, fake reviews, or deceptive campaigns intended to mislead at scale; or
- (d)Impersonate a real person or entity to deceive others regarding identity or the origin of communications, except as expressly authorized in a scoped security engagement.
3.6Privacy and Intellectual Property Rights
- (a)Violate applicable privacy, intellectual property, publicity, or other third-party rights;
- (b)Collect, solicit, or access private personal data (including health, biometric, or non-public contact information, or confidential proprietary data) without a lawful basis;
- (c)Alter a real person's likeness into intimate or sexual contexts without legal right (including non-consensual intimate imagery or deepfakes); or
- (d)Stalk, dox, or harass individuals.
3.7Illegal Activity and Regulated Misuse
- (a)Violate applicable law in the relevant jurisdiction(s);
- (b)Acquire or trade illegal controlled substances, or facilitate human trafficking;
- (c)Operate in a regulated activity without complying with applicable regulations; or
- (d)Violate United States or other applicable export-control or sanctions rules, including use of the Services for or on behalf of prohibited parties or restricted territories under applicable OFAC, EAR, ITAR, EU, UK, or UN rules.
3.8Platform Abuse
- (a)Jailbreak, prompt-inject, or bypass safety controls in order to pursue a use prohibited by this AUP;
- (b)Circumvent rate limits, geographic restrictions, bans, billing, or access controls;
- (c)Create accounts or automate access to evade detection or a prior ban; or
- (d)Offer the Services in regions or to persons that Submersion does not support.
3.9Model Training, Distillation, and Extraction
Without Submersion's prior written consent, you must not:
- (a)Use the Services, or any Inputs, Outputs, embeddings, logits, probabilities, hidden states, system prompts, tool schemas, or other model or Service artifacts, to train, fine-tune, adapt, distill, evaluate, benchmark for replication, or otherwise improve any machine learning model, foundation model, agent, or automated system;
- (b)Perform model distillation, student-teacher training, synthetic data generation for training, preference collection, reinforcement learning from Service Outputs, or any similar technique intended to transfer capability from the Services into another model or system;
- (c)Scrape, harvest, crawl, bulk-collect, or systematically record Inputs or Outputs for the purpose of building or improving a model, dataset, or competing product or service;
- (d)Reverse engineer, decompile, disassemble, or attempt to extract, reconstruct, or discover non-public model weights, parameters, architectures, system prompts, safety mitigations, or other proprietary Service components, except to the extent such restriction is prohibited by applicable law; or
- (e)Assist, enable, or provide access to any third party for any activity described in this Section 3.9.
Permitted Internal Use. Nothing in this Section 3.9 prohibits you from using Outputs in the ordinary course of an authorized security engagement or internal business workflow (for example, incorporating a finding into a report), provided you do not use such Outputs to train or distill a model or to build a competing model or hosted service.
4 High-risk non-cyber uses
If you use the Services for advice or decisions that directly affect individuals in legal, healthcare, insurance, finance, employment, housing, or similar domains, you must:
- (a)Maintain a qualified human in the loop before acting on outputs that materially affect a person; and
- (b)Disclose artificial intelligence involvement when outputs are presented to end users, at least at the beginning of each session.
You must not use the Services as the sole basis for criminal justice determinations (including parole or sentencing), unlawful surveillance, or biometric categorization that infers protected characteristics.
5 Verification, monitoring, and enforcement
Submersion may request identity, business, authorization, Rules of Engagement, or domain-verification evidence for risk users, risk features, or risk-based triggers. You must respond accurately and promptly. Providing false documentation or refusing to cooperate may result in suspension or termination of access.
Subject to Submersion's Privacy Policy and applicable customer agreements, Submersion may monitor use of the Services (including prompts, outputs, account signals, and related telemetry) to detect AUP violations, abuse, and security incidents.
If Submersion reasonably believes you have violated this AUP or pose a risk to Submersion, its customers, third parties, or the public, Submersion may throttle, suspend, or terminate access; revoke API keys; block or modify outputs; pause workflows; preserve evidence; and report matters to law enforcement where required or appropriate. Refunds following suspension or termination for material breach of this AUP may be denied where permitted by law and the applicable Terms.
6 Government and specially contracted customers
Submersion may enter into written agreements with governmental or enterprise customers that tailor use restrictions to that customer's legal authorities and public mission, if in Submersion's judgment the contractual restrictions and safeguards adequately address the harms this AUP is intended to mitigate.
7 Reporting
Report suspected AUP violations, unsafe outputs, or security concerns to: security@submersion.ai (or the contact published at submersion.ai/legal).
Legal notices: legal@submersion.ai (or as specified in the Terms).
8 Relationship to other documents
This AUP does not replace your obligation to comply with applicable law, customer contracts, Rules of Engagement, export and sanctions rules, or professional standards. If this AUP conflicts with a negotiated enterprise agreement between you and Submersion, that enterprise agreement controls to the extent of the conflict.