1. Scope and Applicability
This Acceptable Use Policy ("AUP") is issued by Bitscaled LLC ("Bitscaled," "we," "us," or "our"), a Florida limited liability company operating from Tampa, Florida. It applies when you visit https://bitscaled.tech, use Client Workspace, run VaultTools checks, use VaultSandbox when that service is offered, or access Bitscaled-managed client environments.
This AUP is incorporated into the Terms of Service. A signed Master Service Agreement (MSA), Statement of Work (SOW), Business Associate Agreement (BAA), Non-Disclosure Agreement (NDA), or Data Processing Agreement (DPA) controls over this AUP where they conflict for contracted services.
This is the public customer and visitor AUP at /legal/aup. It is separate from the staff-only intranet AUP at /intranet/legal/aup. Public users, Workspace members, and customers are not asked to use or acknowledge that internal staff policy.
2. Prohibited Activities
You may not, and may not permit others to:
- Scan, probe, spoof, or otherwise test third-party domains, IP addresses, email addresses, or tenants without authorization from the owner or operator.
- Send bulk unsolicited email or SMS (spam) through Bitscaled systems, Workspace, or any mailbox or number we administer.
- Create, distribute, host, or attempt to deploy malware, ransomware, worms, trojans, or other harmful code.
- Share, sell, publish, or reuse another person's credentials, MFA devices, session cookies, Client Workspace tokens, or hosted MCP keys.
- Conduct phishing, smishing, vishing, or other social-engineering attacks, or impersonate Bitscaled, a customer, or a third party.
- Launch or participate in denial-of-service (DDoS) or other attacks intended to disrupt networks, services, or security controls.
- Use VaultTools, VaultSandbox, or any other Bitscaled tool against systems you do not own and are not authorized to test.
- Scrape, harvest, or systematically copy websites or APIs beyond robots.txt, a written license, or applicable law.
- Use Bitscaled AI features to process protected health information (PHI) unless a signed BAA is in place for that work.
- Engage in unlawful, fraudulent, or unauthorized access activity of any kind.
3. VaultTools and VaultSandbox
VaultTools public assessment tools (including DNS/SSL, footprint, Microsoft 365 snapshot, breach check, ransomware scorecard, and BIMI) may be used only on domains, IP addresses, email addresses, and tenants you are authorized to test. Submit only assets you own or for which you have written authorization.
The VaultTools gateway path `/api/email-spoof` returns HTTP 410. Email spoof testing is not part of the VaultTools API. When VaultSandbox is offered, spoof testing is available at spooftest.bitscaled.tech and via the website /tools/email-spoof flow, and only for systems you are authorized to test.
Tool output is a point-in-time technical snapshot. It is not a penetration test, audit, certification, or guarantee that a system is secure. We do not claim SOC 2, ISO 27001, PCI DSS, or similar certifications on these pages.
4. Data Handling, Accounts, and AI
- Keep Client Workspace credentials, organization tokens, and hosted MCP keys confidential. Do not share them with unauthorized people or embed them in public repositories or prompts.
- Handle data in Bitscaled-managed environments according to your contract and applicable law. Do not export, copy, or retain data outside authorized systems.
- Do not send secrets, payment-card data, or PHI into AI prompts unless the feature is contracted and a BAA or similar agreement covers that processing.
- AI output can be wrong or incomplete. Review it before relying on it for production changes, legal conclusions, or customer communications.
5. Incident and Violation Reporting
Report suspected security incidents, credential exposure, unauthorized access, or AUP violations immediately to emergency@bitscaled.tech and legal@bitscaled.tech, or call +1 (813) 419-0419.
If you believe you have found a vulnerability in a Bitscaled system, follow the Vulnerability Disclosure Policy rather than exploiting or publicly disclosing the issue.
6. Enforcement
We may suspend or terminate access, investigate activity, restrict tools, and pursue contractual or legal remedies for AUP violations. We may report unlawful activity to law enforcement. Managed-service customers remain subject to any additional remedies in their MSA or SOW.
7. Related Policies
Read this AUP together with the Terms of Service, Privacy Policy, Data Processing Agreement, and Vulnerability Disclosure Policy.
8. Contact
Questions about this AUP: legal@bitscaled.tech. Emergencies: emergency@bitscaled.tech or +1 (813) 419-0419.