Full Text Document
1stProtect Acceptable Use Policy
Effective Date: July 19, 2026
Last Updated: July 19, 2026
Version: 1.0
1. Introduction and Purpose
This Acceptable Use Policy ("AUP" or "Policy") governs the access to and use of the 1stProtect prevention-first endpoint security platform, on-host software agents (including their on-host artificial intelligence and machine learning capabilities), cloud console, APIs, portals, documentation, and any related products or services (collectively, the "Services") provided by 1st Protect Corp, a Delaware corporation ("1stProtect," "we," "us," or "our").
This AUP supplements, and is incorporated by reference into, the 1stProtect End User License Agreement ("EULA") and any master subscription agreement, order form, reseller or partner agreement, or other agreement between you and 1stProtect (together, the "Agreement"). By accessing or using the Services, you ("Customer," "you," or "your") agree to comply with this AUP. If there is a conflict between this AUP and the EULA, the EULA controls unless it expressly states otherwise.
You are responsible for ensuring that all of your users, administrators, employees, contractors, agents, and any other person or system that accesses the Services through your account or credentials (collectively, "Users") comply with this AUP. Your acts and omissions, and those of your Users, are treated as your own.
Capitalized terms not defined in this AUP have the meaning given in the EULA.
2. Scope
This AUP applies to:
• All use of the 1stProtect Services, including the on-host endpoint agent(s), their on-host AI/ML models, the management console, cloud services, and APIs.
• All Users who access the Services on your behalf.
• Any device, endpoint, network, system, or account on which the Services are deployed or through which the Services are accessed, whether the endpoint is online or operating offline.
You may deploy and use the Services only on endpoints, systems, and environments that you own, or that you are authorized to monitor and protect, and for which you have obtained all necessary rights, consents, and authorizations (including any employee, user, or legal notices and consents required by applicable law).
3. Acceptable Use
You may use the Services only:
• For your own lawful internal business purposes of preventing, detecting, investigating, responding to, and remediating security threats on endpoints and systems you are authorized to protect.
• In accordance with the Agreement, this AUP, all applicable documentation, and all applicable laws, regulations, and third-party rights.
• Within the license scope, entitlements, and usage limits set out in your order form or subscription (for example, the licensed number of endpoints, seats, or data volumes).
4. Prohibited Uses
You and your Users must not, and must not permit or enable any third party to, do any of the following.
4.1 Unlawful and Harmful Activity
• Use the Services in violation of any applicable law, regulation, sanctions regime, or export control requirement, or in any manner that facilitates illegal activity.
• Use the Services to monitor, access, intercept, or collect data from any device, system, network, or individual without proper authorization or the legally required consent.
• Use the Services to stalk, harass, surveil unlawfully, or otherwise violate the privacy or legal rights of any person.
4.2 Unauthorized Access, Resale, and Security Circumvention
• Access or attempt to access any part of the Services, accounts, systems, or data that you are not authorized to access, including the environments, tenants, or data of any other 1stProtect customer.
• Probe, scan, or test the vulnerability of the Services or any 1stProtect system or network, or breach or circumvent any authentication, security, or access-control measure, except as expressly authorized in writing by 1stProtect (see Section 5).
• Circumvent, disable, tamper with, or attempt to defeat any license key, entitlement limit, usage metering, or technical protection measure within the Services.
• Resell, distribute, sublicense, rent, lease, lend, transfer, or otherwise make the Services available to any third party unless you have a valid, current reseller, distributor, or partner agreement with 1stProtect and have obtained 1stProtect's prior written authorization for the specific distribution or resale. Any resale or distribution outside the scope of such an authorized agreement is strictly prohibited.
• Share or otherwise make the Services available to any third party except as expressly permitted in the Agreement.
4.3 Interference and Integrity
• Interfere with, disrupt, or degrade the integrity, security, or performance of the Services, or the data or infrastructure of 1stProtect or any other customer.
• Introduce or transmit any malware, ransomware, virus, worm, or other malicious code into the Services, except in a controlled manner within a sanctioned testing environment (see Section 5).
• Impose an unreasonable or disproportionately large load on the Services or attempt to overwhelm system resources (for example, through denial-of-service techniques).
4.4 Agent Integrity and Tamper Protection
• Disable, uninstall, stop, suspend, unload, quarantine, modify, or otherwise interfere with the 1stProtect agent, its self-protection features, its drivers or services, or its normal operation, except through the controls or procedures expressly provided or authorized by 1stProtect.
• Block, intercept, filter, or otherwise prevent the agent from communicating with 1stProtect services or from receiving updates, whether at the network, host, or firewall level, except as expressly permitted by the documentation.
• Tamper with, delete, alter, or falsify the agent's local logs, quarantine store, configuration, or protected data, whether the endpoint is online or operating offline.
• Take any action designed to conceal activity from the agent, evade its prevention or detection capabilities, or cause it to report false or misleading information.
4.5 On-Host AI and Machine Learning Models
• Extract, copy, export, or reverse engineer any on-host or cloud AI/ML model, model weights, parameters, features, training data, or detection logic within the Services.
• Perform, attempt, or facilitate adversarial attacks against the Services' AI/ML capabilities, including model evasion, adversarial input crafting, model inversion, membership inference, or data or prompt poisoning intended to degrade, bias, or defeat the models.
• Use any output, score, classification, or other result generated by the Services' AI/ML capabilities to develop, train, fine-tune, benchmark, or improve any competing or derivative model, product, or service.
• Rely on outputs of the Services' AI/ML capabilities as the sole basis for decisions with legal or similarly significant effects without appropriate human review (see Section 10).
4.6 Reverse Engineering and Intellectual Property
• Reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, underlying structure, algorithms, detection logic, or ideas of the Services, except to the limited extent this restriction is prohibited by applicable law.
• Modify, translate, adapt, or create derivative works based on the Services or documentation.
• Copy, reproduce, distribute, or republish any part of the Services except as expressly permitted.
• Remove, obscure, or alter any proprietary notices, trademarks, or labels contained in or on the Services or documentation.
• Use the Services to build, train, or improve a competing product or service, or to copy any feature, function, or user interface of the Services.
4.7 Benchmarking and Testing Disclosure
• Conduct or publish any benchmark, competitive analysis, penetration test, malware-efficacy test, prevention-efficacy test, or other evaluation of the Services, or disclose the results of any such test to a third party, without 1stProtect's prior written consent.
4.8 Misuse of the Platform and Data
• Use the Services for time-sharing, service-bureau, hosting, or managed-service purposes for third parties, except under a valid partner or MSP agreement with 1stProtect.
• Use the Services to collect, store, or process data of categories or in volumes not permitted by your subscription or by applicable law.
• Use the Services to develop, distribute, or operate malicious code, exploits, or offensive-security tooling against systems you are not authorized to test.
• Falsify, misrepresent, or manipulate telemetry, alerts, logs, or other data generated by the Services in a way that could mislead 1stProtect or defeat the purpose of the Services.
4.9 Account and Credential Misuse
• Share administrative or user credentials except as necessary and permitted, or fail to keep credentials confidential and secure.
• Impersonate any person or entity, or misrepresent your affiliation with any person or entity, in connection with the Services.
5. Authorized Security Testing
Nothing in this AUP is intended to discourage responsible security research. If you wish to perform vulnerability testing, penetration testing, malware detonation, or adversarial testing of the AI/ML capabilities involving the Services or 1stProtect infrastructure, you must obtain 1stProtect's prior written authorization and comply with any scope, rules of engagement, and safeguards we specify. Testing conducted solely within endpoints and environments you own or are authorized to protect, and that does not target 1stProtect's multi-tenant infrastructure or other customers, is generally permitted subject to the rest of this AUP.
To report a suspected security vulnerability in the Services, contact [email protected].
6. Automated Prevention Actions and Customer Tuning
The Services are prevention-first and, by design, may automatically and without prior notice block, quarantine, isolate, terminate, or otherwise remediate processes, files, scripts, network connections, or devices that the Services identify as malicious or suspicious, including based on on-host AI/ML decisions and including while the endpoint is offline.
You acknowledge and agree that:
• You are responsible for appropriately configuring, tuning, and testing the Services (including policies, exclusions, and prevention modes) in a representative environment before broad deployment, and for validating that prevention settings are appropriate for your systems.
• Automated prevention actions may affect the availability or operation of legitimate applications, processes, or systems, and you are responsible for maintaining exclusions and configurations suited to your environment.
• 1stProtect is not responsible for any disruption, loss, or damage arising from prevention actions taken in accordance with your configuration or from your failure to properly configure, tune, or test the Services, except as otherwise provided in the Agreement.
7. Software Updates and Connectivity
The Services are designed to protect endpoints even when offline. However, prevention and detection efficacy depends on the agent, its on-host models, and its threat intelligence being kept current.
• You must permit the agent to receive updates (including software, model, and content updates) with the frequency and connectivity described in the documentation, including for endpoints operated primarily offline.
• You must not indefinitely prevent an endpoint from connecting for updates. You acknowledge that operating materially outdated agents or models increases security risk, may reduce the effectiveness of the Services, and may constitute a violation of this AUP.
• You are responsible for maintaining supported operating system versions and any prerequisites identified in the documentation.
8. Endpoint Resource Usage
The on-host agent and its AI/ML capabilities consume endpoint resources, including CPU, memory, storage, and, where applicable, hardware acceleration. You acknowledge and agree that you will deploy the Services only on endpoints that meet the minimum and recommended hardware and operating-system specifications set out in the documentation, and that resource consumption consistent with the documentation is a normal and expected part of the Services.
9. Export Controls and Sanctions
The Services, including the software agents and any related technology, are subject to the export control and economic sanctions laws and regulations of the United States, including the U.S. Export Administration Regulations (EAR) and the sanctions programs administered by the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC), as well as any applicable laws of other jurisdictions.
By accessing or using the Services, you represent, warrant, and agree, on behalf of yourself and all of your Users, that:
• You and your Users are not located in, ordinarily resident in, organized under the laws of, or a national of, any country or region subject to comprehensive U.S. sanctions or embargoes (currently including, but not limited to, Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions), and this list may change as U.S. law is updated.
• You and your Users are not identified on any U.S. government restricted-party list, including OFAC's list of Specially Designated Nationals and Blocked Persons (SDN List), the U.S. Department of Commerce's Denied Persons or Entity Lists, or any equivalent list, and you are not owned or controlled by, or acting on behalf of, any such party.
• You will not access, use, export, re-export, resell, distribute, or transfer the Services, directly or indirectly, to any prohibited country, region, entity, or individual, or for any end use prohibited by applicable export control or sanctions laws.
Use, purchase, or resale of the Services by, or on behalf of, any sanctioned country, region, entity, or individual, or in any manner that would violate U.S. export control or sanctions laws, is strictly prohibited. This restriction applies to all Customers, Users, resellers, distributors, and partners. You are responsible for screening your own customers and end users against applicable restricted-party lists before any resale or distribution. 1stProtect may suspend or terminate access to the Services immediately, without liability, if it reasonably determines that continued provision would violate, or create a risk of violation of, applicable export control or sanctions laws.
10. Nature and Limitations of the Services
You acknowledge and agree that:
• No security product, including a prevention-first solution with on-host AI, can detect or prevent all threats, and the Services are not guaranteed to be error-free, uninterrupted, or fully effective against every attack.
• The Services are intended to be one component of a layered security program and must not be relied upon as your sole or exclusive security control. You are responsible for maintaining appropriate backups, incident response capabilities, and complementary controls.
• Outputs, scores, and classifications produced by the Services' AI/ML capabilities are probabilistic and may include false positives and false negatives. You are responsible for applying appropriate human review and judgment before taking actions with legal or similarly significant effects based on those outputs.
11. High-Risk Activities
The Services are not designed, intended, or authorized for use in hazardous or safety-critical environments requiring fail-safe performance, in which the failure of the Services could lead to death, personal injury, or severe physical or environmental damage (for example, the operation of nuclear facilities, aircraft navigation or communication systems, air traffic control, life-support systems, or weapons systems). You must not use the Services for any such high-risk activities, and 1stProtect disclaims any express or implied warranty of fitness for such purposes.
12. Telemetry, Data Collection, and Consent
To provide prevention, detection, and response capabilities, the on-host agent collects and processes security-relevant telemetry from protected endpoints (for example, process, file, script, network, and system events) and may transmit such telemetry to 1stProtect's cloud services, in accordance with the documentation and the applicable data-processing terms.
You are responsible for:
• Obtaining and maintaining all rights, consents, notices, and authorizations required for 1stProtect to collect, process, and transmit telemetry and other data from your endpoints and Users, including any employee or end-user notices and consents required under applicable privacy, employment, and communications laws.
• Ensuring that your deployment of on-host monitoring is lawful in each jurisdiction where endpoints are located.
• Not using the Services to collect or process categories or volumes of data beyond what is permitted by your subscription, the documentation, or applicable law.
13. Customer Responsibilities
You are responsible for:
• Obtaining and maintaining all rights, consents, notices, and authorizations required to deploy the Services on your endpoints and to have 1stProtect collect and process the associated telemetry and data.
• Configuring, deploying, tuning, and maintaining the Services in accordance with the documentation and 1stProtect's guidance.
• Maintaining the confidentiality and security of your account credentials and API keys, and promptly notifying 1stProtect of any suspected unauthorized access or use.
• The activity of all Users and of any content or data you or your Users submit to, or generate through, the Services.
• Complying with all applicable data-protection, privacy, employment, and communications laws in connection with your use of the Services.
14. Monitoring and Enforcement
1stProtect does not routinely monitor the content of Customer data but reserves the right, at its sole discretion and to the extent permitted by law, to monitor use of the Services and to investigate suspected violations of this AUP.
If 1stProtect reasonably believes that a violation of this AUP has occurred or that the Services are being used in a manner that threatens the security, integrity, or availability of the Services, 1stProtect, other customers, or any third party, 1stProtect may take any of the following actions, with or without notice depending on the severity and urgency:
• Investigate the suspected violation.
• Remove, disable access to, or quarantine offending content, configurations, or data.
• Suspend or throttle affected accounts, Users, or endpoints.
• Suspend or terminate the Services or the Agreement in accordance with the EULA.
• Cooperate with law enforcement and disclose information as required by law or legal process.
Where practicable and consistent with the security of the Services and applicable law, 1stProtect will use commercially reasonable efforts to notify you before or promptly after taking enforcement action and will limit any suspension to what is reasonably necessary.
You agree to cooperate with 1stProtect in investigating and remediating any suspected or actual violation of this AUP.
15. Reporting Violations
If you become aware of any actual or suspected violation of this AUP, or any misuse of the Services, please report it promptly to [email protected] with sufficient detail to allow 1stProtect to investigate.
16. Changes to This Policy
1stProtect may update this AUP from time to time to reflect changes in our Services, legal or regulatory requirements, or security practices. We will post the updated Policy and revise the "Last Updated" date above, and, where required, provide notice through the Services or by other reasonable means. Your continued use of the Services after an update takes effect constitutes your acceptance of the revised AUP.
17. Contact
Questions about this AUP may be directed to:
1st Protect Corp
108 W 13th St Ste 100, Wilmington, DE 19801, United States
Email: [email protected]
Security: [email protected]
Abuse: [email protected]