Aneo B.V.

Acceptable Use Policy

This Acceptable Use Policy explains what customers, account users, visitors, and integration users may and may not do when using aneo websites, products, APIs, AI features, support, and related services. It has applied since 19 November 2025 and was last updated on 24 June 2026.

Last updated: 24 June 2026

1. Scope and related terms

This policy applies to aneo.io and all subdomains, aliases, product surfaces, APIs, and future subdomains operated by Aneo B.V., including examples such as www.aneo.io, app.aneo.io, api.aneo.io, docs.aneo.io, and status.aneo.io.

This policy is part of our legal terms and should be read together with the Terms of Service, Privacy Policy, Data Processing Agreement, Responsible AI page, Sub-processors page, Security Overview, Responsible Disclosure policy, and any applicable order form or written agreement.

2. Definitions

Offerings means aneo software products and services, including cloud applications, public website features, APIs, support, documentation, and related services.

Customer Content means content, documents, tickets, questionnaire answers, prompts, outputs, policies, reports, evidence notes, incident records, uploads, and similar material submitted to or generated through the Offerings by or for a customer organization.

3. Your responsibilities

You must use the Offerings only for lawful internal business purposes and in accordance with applicable law, these terms, product documentation, plan limits, security instructions, and any written agreement with Aneo B.V.

AI features are designed to assist security and governance teams. Human review is required before using AI output for material actions, security decisions, policy approval, incident handling, legal obligations, compliance evidence, customer-facing communication, or operational decisions.

  • Keep account information, billing details, business contact details, and administrator contact details accurate and current.
  • Protect passwords, API keys, tokens, session credentials, and administrator accounts, and enable multi-factor authentication where offered.
  • Configure roles, permissions, integrations, retention settings, and sharing settings responsibly.
  • Supervise your users, contractors, administrators, integrations, and any third parties acting through your account.
  • Review Customer Content, generated outputs, exports, and AI-assisted recommendations before use.

4. Prohibited content

You must not upload, submit, generate, store, transmit, or cause the Offerings to process content that is unlawful, harmful, abusive, or outside the intended business security and governance use of aneo products.

  • Content that violates applicable law, regulation, sanctions, export controls, court orders, or third-party rights.
  • Malware, exploit code, destructive payloads, phishing material, credential theft material, or instructions intended to disrupt, damage, evade, or gain unauthorized access to systems.
  • Content that infringes intellectual property, privacy, confidentiality, trade secret, publicity, or contractual rights.
  • Defamatory, harassing, hateful, violent, threatening, abusive, discriminatory, exploitative, or deceptive content.
  • Sexual content involving minors, content that exploits or harms others, or personal data about minors without verified parental consent where required.
  • Content that is not lawfully obtained, not permitted to be processed, or not permitted to be transferred to aneo or its subprocessors.

5. Prohibited activities

You must not misuse, disrupt, attack, copy, bypass, or interfere with the Offerings, related infrastructure, other users, or third-party systems.

  • Attempt unauthorized access to accounts, Customer Content, data, systems, networks, APIs, infrastructure, source code, or administrative functions.
  • Probe, scan, test, attack, or benchmark security controls without written permission or outside the Responsible Disclosure policy.
  • Interfere with service availability, degrade performance, overload systems, abuse support channels, or bypass rate limits, quotas, plan restrictions, usage limits, or security controls.
  • Scrape, harvest, crawl, bulk extract, or copy data except through documented exports, supported APIs, or written permission.
  • Misrepresent identity, impersonate another person or organization, hide attribution, or use the Offerings for fraudulent or deceptive activity.
  • Send spam, bulk unsolicited messages, phishing messages, deceptive communications, or messages that violate email, privacy, telecom, or consumer protection laws.
  • Resell, sublicense, rent, lease, white-label, redistribute, or provide access to the Offerings without written permission.
  • Reverse engineer, decompile, disassemble, copy, create derivative works from, or attempt to discover source code except where applicable law expressly permits it.

6. Data restrictions

Do not submit highly sensitive, regulated, classified, or restricted data unless the processing is lawful, necessary for the agreed use case, and covered by an appropriate written agreement with Aneo B.V. If you are unsure, contact legal@aneo.io before submitting the data.

Because IncidentAI may be used to document security incidents, customers remain responsible for limiting incident records to necessary information and for configuring workflows, permissions, and retention settings appropriately.

  • Special category personal data under GDPR, including health, biometric, genetic, religious, political, trade union, sex life, or sexual orientation data, unless expressly agreed.
  • Criminal-offence data, government identifiers, national identity numbers, passport numbers, social security numbers, or similar high-risk identifiers unless expressly agreed.
  • Payment card data subject to PCI DSS, full card numbers, CVV codes, bank credentials, payment secrets, private keys, passwords, authentication secrets, or production credentials.
  • Government classified information, export-controlled technical data, military data, sanctions-restricted data, or data subject to strict localization requirements unless expressly agreed.
  • Data that you are not legally permitted to collect, process, upload, disclose, transfer, or instruct Aneo B.V. to process.

7. AI-specific rules

You must use aneo AI features responsibly, with human supervision, and only for lawful business security, governance, documentation, and incident response workflows.

AI output can be incomplete, incorrect, outdated, or unsuitable for your context. It is not legal advice, not a security guarantee, and not a compliance certification.

  • Do not attempt to bypass safety filters, abuse prompts, override policy controls, extract system prompts, or force generation of prohibited content.
  • Do not use AI features to generate malware, phishing, credential theft, exploit instructions, evasion techniques, unauthorized surveillance, illegal discrimination, or other harmful conduct.
  • Do not rely on AI alone for decisions with legal, regulatory, security, privacy, financial, safety, employment, customer, or operational impact.
  • Clearly label or disclose AI-generated text where required by law, platform policy, customer policy, or professional obligation.
  • Use zero-retention, EU data residency, access control, and retention settings appropriately where available and required by your risk profile or agreement.

8. High-risk uses

The Offerings are intended for business use by adults. You must not use aneo products for life-critical systems, emergency services, medical diagnosis or treatment, autonomous weapons, critical infrastructure control, or other high-risk uses where failure, delay, incorrect output, or misuse could cause death, personal injury, severe environmental damage, severe property damage, major financial loss, or other serious harm.

9. API and fair use

Where APIs, integrations, exports, or automated access are available, you must use documented and supported endpoints only and must respect technical and contractual limits.

  • Do not share API keys, tokens, integration secrets, or service credentials outside your organization or with unauthorized users.
  • Do not create unreasonable load, attempt to avoid throttling, chain accounts to evade limits, or interfere with service reliability.
  • Do not use undocumented endpoints, private APIs, automated browser scraping, or unsupported automation unless Aneo B.V. gives written permission.
  • Do not use the Offerings to build a competing product or to extract product functionality, workflows, templates, or generated formats except as allowed by law or written agreement.

10. Email and communications

Transactional, security, billing, product, and support messages may be sent as part of providing the Offerings. If you control recipient lists or use any communication feature, you are responsible for lawful notices, consent, opt-outs, and suppression lists.

  • Do not use the Offerings to send unsolicited commercial messages, deceptive messages, phishing messages, or messages that violate anti-spam, privacy, telecom, or consumer protection laws.
  • Honor opt-outs promptly where you control the recipient relationship.
  • Do not use aneo names, marks, domains, or systems to imply sponsorship, endorsement, or authorization where none exists.

11. Intellectual property

You must respect Aneo B.V. intellectual property and third-party rights. Except for Customer Content and rights expressly granted by agreement, the Offerings, website, software, workflows, product names, generated formats, designs, documentation, templates, and related materials remain owned by Aneo B.V. or its licensors.

  • Do not upload, submit, or use content unless you have the necessary rights and permissions.
  • Do not remove proprietary notices, copy product materials outside permitted use, or imply ownership of aneo materials.
  • Follow third-party component, model, integration, and open-source license terms where they apply.

12. Export controls and sanctions

You must comply with applicable export control, sanctions, anti-boycott, and trade compliance laws. You must not use or access the Offerings if you are located in, organized under the laws of, or ordinarily resident in an embargoed or comprehensively sanctioned region, or if you are a restricted party under applicable sanctions lists.

You must not use the Offerings to process or transfer export-controlled technical data, sanctions-restricted data, or restricted-party data unless expressly permitted by law and by a written agreement with Aneo B.V.

13. Security testing

Security testing must follow the Responsible Disclosure policy or a separate written authorization. Do not perform testing that affects availability, accesses data that is not yours, exfiltrates data, modifies data, disrupts service, weakens controls, or harms other users.

14. Enforcement

Aneo B.V. may investigate suspected violations and may remove or restrict Customer Content, throttle use, suspend access, disable integrations, terminate accounts, preserve evidence, or notify authorities where needed to protect customers, the Offerings, legal compliance, platform security, or third-party rights.

Where reasonable and lawful, we will try to notify the relevant customer and provide an opportunity to remediate. Immediate action may be taken where there is risk of harm, legal exposure, security compromise, service disruption, or repeated violation.

15. Reporting abuse

Report suspected abuse, unlawful content, platform misuse, account compromise, spam, phishing, or acceptable-use concerns to report-abuse@aneo.io. Include the relevant URL, account, product area, timestamps, screenshots, headers, logs, and any other details that help us investigate.

Security vulnerabilities should be reported through the Responsible Disclosure process at https://www.aneo.io/responsible-disclosure/.

16. Changes

We may update this Acceptable Use Policy to reflect legal, technical, security, product, or operational changes. The Last updated date shows the latest version. Continued use of the Offerings after changes means you accept the updated policy.

17. Contact

Questions about acceptable use can be sent to hello@aneo.io. Legal questions can be sent to legal@aneo.io.