Effective date: 2 August 2026
This policy is part of the Terms of Service. It applies to every user, organization member, and integration that touches SpendTensor.
1. Prohibited activity
You may not use SpendTensor to do any of the following, or help anyone else do them.
- Probe, scan, or test the vulnerability of the platform outside our vulnerability reporting process, or bypass authentication, rate limits, or tenant isolation.
- Access data belonging to another organization, or attempt to escalate your role beyond what your organization owner assigned.
- Upload malware, run automated attacks, or use the platform to relay unsolicited email or messages.
- Reverse engineer, decompile, scrape at scale, or resell access to the platform without written permission.
- Connect provider credentials you are not authorized to use, or use SpendTensor in a way that breaches the terms of any AI provider (OpenAI, Anthropic, Google, Microsoft Azure, AWS, or others).
- Submit unlawful content, infringe intellectual property, or process data you have no legal basis to process.
- Use the platform for high-risk decisions about individuals (credit, employment, housing, health, or legal outcomes) based on its cost or recommendation output.
2. Credentials and connections
Provider API keys must be issued to your organization with the minimum scope needed for usage and cost reporting. Use read-only or usage-scoped keys where your provider supports them. Rotate keys immediately if you suspect exposure, and remove connections for providers you no longer use.
You are responsible for activity performed with keys you connect, including any provider charges triggered by health checks or sync jobs.
3. Fair use, rate limits, and automation
API and sync usage must stay within the limits of your plan. We may throttle, queue, or temporarily suspend sync jobs that place a disproportionate load on the platform or on an upstream provider. Automated access must identify itself honestly and respect returned rate-limit headers.
4. Multi-user organizations
Organization owners are responsible for the conduct of their members and for keeping role assignments current. Remove members promptly when they leave. Invitations must only be sent to people authorized to see your organization's spend data.
5. Enforcement
We may investigate suspected violations and take proportionate action: warning, rate limiting, disabling a connection, suspending a member, or terminating the account. Serious or repeated violations, and anything that threatens the security of other customers, may result in immediate suspension without notice. Where the law requires it, we cooperate with valid legal requests.
6. Reporting abuse and vulnerabilities
Report abuse or a suspected security vulnerability to cyberprosoftware@gmail.com with enough detail to reproduce it. Please do not exfiltrate other customers' data, degrade the service, or publicly disclose an unpatched issue while we investigate. We aim to acknowledge reports within three business days.
This document is maintained by SpendTensor, Inc. and is provided for information only. It is not legal advice and is not an independent certification. Questions: cyberprosoftware@gmail.com.