# Kaabist Acceptable Use Policy

*Version 1.0, effective 10 October 2026. Part of the [Terms of Service](terms-of-service.md).*

Kaabist runs automated browsers and HTTP clients on your behalf, from Kaabist's infrastructure and
proxies. What those visits do is your responsibility, and some uses are never allowed.

## 1. You may not use Kaabist to

1. **Stuff credentials or take over accounts** (credential stuffing). No trying lists of usernames and passwords, no
   password spraying, no guessing one-time codes, against any site. Login programs may only use
   credentials you or your end users are entitled to use, for accounts they own.
2. **Bypass access controls you are not entitled to pass.** No getting past a login, paywall,
   rate limit, geofence or technical protection measure that the site uses to keep *you* out.
   Automating access you legitimately have (your own account, a service you subscribe to, a portal
   your customer authorised) is the product; breaking into access you do not have is not.
3. **Collect personal data without a legal basis.** If your programs collect information about
   people, you must have a lawful basis for it (for example under GDPR or KVKK), respect the
   purpose limits that apply, and honour the people's rights. Kaabist processes that data for you
   under the [Data Processing Agreement](dpa.md); you remain its controller.
4. **Reach blocked targets.** The platform refuses targets on its blocklist (government and
   military domains, Kaabist's own infrastructure, names that only ever point inward), and may add
   to it. Do not try to reach them by other means (redirects, alternative names, proxies you bring).
5. **Attack or overload anything.** No denial-of-service, vulnerability scanning without the
   owner's written permission, exploitation, spam, or traffic designed to exhaust a site's
   resources. Kaabist limits the rate per hostname for every customer together; do not work around
   it.
6. **Break the law or others' rights.** No fraud, phishing, malware distribution, infringement of
   copyright or database rights, collection of special-category or children's data without a
   specific legal basis, or anything sanctions law prohibits.
7. **Abuse Kaabist itself.** No reselling access without an agreement, no attempts to reach other
   customers' data or the platform's internal network, no testing the platform's security outside
   the [security disclosure policy](../../SECURITY.md).

## 2. Your obligations

- Respect the sites you automate: their terms where they bind you, and reasonable load.
- Keep your API keys, sessions and stored credentials secret, and revoke them when they leak.
- Tell us at abuse@kaab.ist if you find your account being used against this policy.

## 3. Reports and takedowns

- Anyone can report abuse to **abuse@kaab.ist**: what was affected, when, and any request
  identifiers or IP addresses seen.
- We acknowledge reports and act on credible ones within seven business days.
- You must cooperate with takedown and preservation requests: stop the reported activity, tell us
  what the programs involved do, and keep the information we ask you to keep.
- Kaabist cooperates with valid legal requests from authorities.

## 4. Enforcement

Depending on severity we may, without prior notice where the harm is ongoing:

1. stop running jobs, pause schedules, or refuse certain targets for your organisation;
2. revoke API keys or OAuth grants;
3. disable the organisation (no new jobs; data kept);
4. terminate the account under the [Terms of Service](terms-of-service.md).

We tell you what was done and why, unless the law or an investigation prevents it. Decisions can be
appealed to abuse@kaab.ist.
