Product: VettiGuard Product owner and provider: Ikemba Tech (ABN 82 565 415 510) Effective date: 25 September 2026 Version: 1.3
1. Purpose
This Acceptable Use Policy protects individuals, customers, VettiGuard infrastructure and the wider internet from misuse of VettiGuard services.
2. Lawful and authorised use
You may use VettiGuard only for lawful purposes and only for systems, data and verification journeys you own, operate or are authorised to protect or process.
3. Prohibited surveillance and biometric misuse
You must not use VettiGuard to conduct covert or unlawful biometric surveillance; identify people in public or private spaces without a lawful basis; create watchlists for discriminatory, intimidating or unrelated purposes; infer protected characteristics from faces; or collect biometric information where the use is not reasonably necessary and proportionate to the stated purpose.
You must not use a failed or uncertain biometric result as the sole basis for a high-impact adverse decision where applicable law, fairness or the configured policy requires human review.
4. Credential, malware and security abuse
You must not use VettiGuard to facilitate credential theft, phishing, malware, ransomware, unauthorised access, destructive testing, denial-of-service attacks, botnet activity or evasion of another service's access controls.
You must not probe, enumerate or attempt to access another customer's workspace, credentials, logs, identity evidence, tokens or private configuration.
5. Platform and quota abuse
You must not deliberately exhaust shared resources, circumvent rate limits, automate account creation to avoid restrictions, manipulate usage metering, replay proofs, forge verification outcomes, resell or sublicense access without authorisation, or use test and sandbox credentials as production proof.
6. Identity and document misuse
You must not submit identity documents, biometric material or personal information without appropriate authority. You must not use VettiGuard to impersonate another person, create fraudulent identities, facilitate identity theft or falsely represent a native screening result as government verification.
7. Unlawful discrimination and high-impact decisions
You must not use VettiGuard for unlawful discrimination or configure a rule that intentionally denies access based on a protected attribute where prohibited by law. Risk, identity and device signals must be used only for legitimate, proportionate purposes connected to the protected operation.
8. Spam and communications abuse
Where VettiGuard triggers communications through a communications provider or another channel, you must not use the integration for spam, unlawful marketing, harassment, deceptive sender identity or messages that breach applicable communications laws or provider rules.
9. Harmful or unlawful content
You must not upload or transmit content that is unlawful, malicious, infringing, deceptive, designed to exploit minors, or intended to cause material harm to people or systems.
10. Regulated and sensitive uses
Healthcare, NDIS, financial services, employment, government, education and other regulated uses must comply with applicable sector rules. VettiGuard does not authorise a use merely because a technical feature can be configured for it.
11. Security testing
Good-faith security research must follow the Security & Responsible Disclosure Policy. Do not perform destructive tests, access other customers' information, persist after confirming a vulnerability, or publish exploitable details before VettiGuard has had a reasonable opportunity to respond.
12. Enforcement
VettiGuard may use proportionate measures including warning, rate limiting, feature restriction, credential revocation, quarantine, suspension or termination where necessary to address a breach, legal requirement or material risk.
Where practicable, VettiGuard will consider the severity, intent, repetition and impact of the activity before taking enforcement action.
13. Reporting misuse
Suspected abuse can be reported to support@vettiguard.com. Do not send unnecessary biometric material, identity documents, passwords or private keys with the initial report.