Acceptable Use Policy
Effective date: 1 July 2025 · Last updated: 1 July 2025
1. Purpose and Scope
This Acceptable Use Policy ("AUP") sets out the rules that govern use of the SF Tether platform, including the token vault, OAuth orchestration layer, provider catalogue, SDK, API, and dashboard (collectively, the "Service").
This AUP applies to all Customers, account members, End Users, and AI agents ("Agents") that access the Service, and is incorporated by reference into the SF Tether Terms of Service.
SF Tether is a connection layer for the agentic world. The power to give AI agents authenticated access to any API at scale carries significant responsibility. This AUP reflects both our legal obligations and our values as builders of safe, governed agent infrastructure.
2. Guiding Principles
We built SF Tether to make safe agent access the easy path. Use of the Service must be:
- Lawful — compliant with all applicable laws and regulations
- Authorised — every API access must be authorised by the owner of the credentials being used
- Least-privilege — agents should request only the permissions they genuinely need
- Audited — access should be traceable and reviewable
- Humane — agents must not be used to harm, deceive, or manipulate people
3. Prohibited Conduct
3.1 Unauthorised Access
You must not use the Service to:
- Access any Third-Party API without valid, authorised credentials
- Use credentials belonging to another person or entity without their explicit authorisation
- Circumvent, bypass, or disable authentication mechanisms of any Third-Party API
- Use the Token Vault to store credentials you do not own or are not authorised to manage
- Harvest, scrape, or extract data from Third-Party APIs in violation of those APIs' terms or applicable law
3.2 Illegal Activities
You must not use the Service in connection with any activity that is unlawful under any applicable law, including laws concerning computer misuse, fraud, money laundering, terrorist financing, sanctions violations, data theft, and harassment.
3.3 Harmful or Dangerous Applications
You must not use the Service in any application or system that:
- Controls weaponry or instruments designed to cause physical harm
- Makes autonomous clinical or life-safety decisions without appropriate human oversight
- Operates safety-critical infrastructure without appropriate human-in-the-loop safeguards
- Facilitates manipulation, deception, phishing, social engineering, or non-consensual impersonation
- Enables unlawful surveillance or tracking of individuals without their knowledge and consent
3.4 Privacy Violations
You must not use the Service to process personal data without a lawful basis, transfer personal data in violation of applicable data transfer rules, or compile profiles of individuals without appropriate consent.
3.5 Overloading Third-Party Services
You must not use the Service to send traffic volumes that exceed a Provider's published rate limits, conduct denial-of-service attacks, or generate fraudulent API calls.
3.6 Abuse of the SF Tether Platform
You must not attempt to gain unauthorised access to other Customers' accounts, introduce malware, reverse-engineer the Service, use automated means to circumvent plan limits, or re-sell access without our consent.
3.7 AI and Autonomous Agents
- Attribution: Every API access must be attributable to an identifiable Agent authorised by an identified Customer.
- Rate limiting: Agents must respect all rate limits and implement exponential backoff.
- Credential isolation: An Agent may only access Credentials for the organisation that authorised it.
- Scope minimisation: Agents must request only the OAuth scopes necessary for their specific function.
- Human oversight: Where an Agent can take consequential actions, appropriate human oversight or confirmation mechanisms must be in place.
- No deceptive agent identities: Agents must not impersonate humans when interacting with people via Third-Party APIs.
4. Sensitive Use Categories
The following use categories require our prior written approval before deployment in production. Contact legal@sf-tether.saas-factory.ai:
- Financial services executing transactions without per-class user authorisation
- Healthcare and medical data including patient records or medical devices
- Children's services where End Users may be under 13 (or 16 in the EU/UK)
- Legal and justice system applications that inform bail, sentencing, or parole decisions
- Electoral and political processes at scale
- High-frequency financial trading exceeding 1 API call per second per user account
5. Consequences of Violation
We may immediately suspend your access if we reasonably believe you are violating this AUP. Material or repeated violations may result in permanent termination. To report an abuse concern, email abuse@sf-tether.saas-factory.ai.
6. Contact
Questions about this AUP: legal@sf-tether.saas-factory.ai
Abuse reports: abuse@sf-tether.saas-factory.ai