Legal
Acceptable Use Policy
What customers may and may not do when using Shieldra. Violations may result in suspension or termination of your account, and may be reported to law enforcement where appropriate. Version 2026-09-16, effective September 16, 2026.
Key takeaways
- The standard service is No-PHI: do not upload PHI unless Shieldra expressly authorizes that processing in writing under a BAA.
- Do not fabricate, falsify, backdate, or manipulate compliance evidence or integrity records, or misrepresent generated artifacts as certifications or independent audit outcomes.
- Do not use the services to plan, operate, or document AI practices prohibited by law, such as those under Article 5 of the EU AI Act.
- Do not represent AI-generated outputs as professional legal, medical, or audit advice.
- Security testing requires prior written authorization; responsible disclosure is welcome at security@shieldra.ai. Report suspected abuse to abuse@shieldra.ai.
Prohibited activities
- Violating any applicable law, regulation, or third-party right
- Uploading, storing, or transmitting malicious code, viruses, worms, ransomware, or other harmful software
- Attempting to gain unauthorized access to the services, other customers, or the underlying infrastructure
- Probing, scanning, or testing the vulnerability of the services without prior written authorization
- Reverse engineering, decompiling, or otherwise deriving source code, except where applicable law permits it
- Using the services to develop a competing product or to benchmark for a competitor
- Reselling, sublicensing, or commercially exploiting the services without written consent
- Sending unsolicited bulk communications or harvesting contact information
- Uploading data of children under 13 — or 16 in applicable jurisdictions — without verifiable parental consent
- Uploading protected health information — including within documents, monitoring feeds, or access logs from connected systems — without express written authorization from Shieldra
- Making automated decisions producing legal effects on individuals without appropriate human review
- Fabricating, falsifying, backdating, or manipulating compliance evidence, questionnaire answers, or integrity records, or attempting to alter or spoof recorded integrity chains
- Misrepresenting Shieldra-generated artifacts, evidence packs, scores, or trust-center pages as government-issued certifications, accreditations, or the outcome of an independent audit or conformity assessment
- Using the services to plan, operate, or document artificial-intelligence practices prohibited by applicable law — for example, practices prohibited under Article 5 of the EU AI Act
- Using the services in any country or by any person subject to U.S. embargo, sanctions, or export controls
AI and machine-learning outputs
You may not represent AI-generated outputs as professional legal, medical, or audit advice. You may not use them as the sole basis for material regulatory submissions, audit reports, or attestations made to third parties without independent professional review.
This is not a disclaimer of convenience. AI-assisted gap analysis is a drafting and prioritization aid; the accountable Privacy Officer, Security Officer, auditor, or counsel remains responsible for what gets filed or attested.
Customer responsibilities
You agree to upload only data you have the right to upload, keep your access credentials secure, enforce least-privilege access among your users, and remove personal data that is no longer necessary.
Reporting and enforcement
If you believe someone is using the services in violation of this policy, report it to abuse@shieldra.ai. Security vulnerabilities should go to security@shieldra.ai under our coordinated disclosure policy.
Shieldra may investigate suspected violations and may suspend or terminate access without prior notice where necessary to protect the services, other customers, or third parties, and may cooperate with law enforcement and regulators. Material changes to this policy are communicated through the in-product banner system and by email to account owners.
Frequently asked questions
Can I upload PHI to Shieldra?
The standard platform is a No-PHI service intended for compliance documentation, policies, risk assessments, and audit evidence. PHI may be uploaded only with Shieldra’s express written authorization, in which case a Business Associate Agreement governs that processing.
Can I use Shieldra AI output in an audit report or regulatory filing?
Not as the sole basis. Outputs of the services — AI outputs, deterministic classifications, generated answers, and evidence artifacts — may not be represented as professional legal, medical, or audit advice, and may not be used as the sole basis for material regulatory submissions, audit reports, procurement responses, or third-party attestations without independent professional review.
Can I edit or backdate compliance evidence in Shieldra?
No. Fabricating, falsifying, backdating, or manipulating compliance evidence, questionnaire answers, or integrity records is prohibited, as is misrepresenting Shieldra-generated artifacts, scores, or trust-center pages as certifications or the outcome of an independent audit or conformity assessment.
Is security testing of Shieldra allowed?
Only with prior written authorization. Probing, scanning, or vulnerability testing without it is prohibited, but responsible disclosure is welcome — report findings to security@shieldra.ai under the coordinated disclosure policy.