Legal
Acceptable Use Policy
What customers may and may not do when using Shieldra. Violations may result in suspension or termination of your account, and may be reported to law enforcement where appropriate.
By the Shieldra Compliance Team · Last updated July 2026
Key takeaways
- Do not upload PHI without an executed Business Associate Agreement.
- Do not represent AI-generated outputs as professional legal, medical, or audit advice.
- Security testing requires prior written authorization; responsible disclosure is welcome at security@shieldra.ai.
- Report suspected abuse to abuse@shieldra.ai.
Prohibited activities
- Violating any applicable law, regulation, or third-party right
- Uploading, storing, or transmitting malicious code, viruses, worms, ransomware, or other harmful software
- Attempting to gain unauthorized access to the services, other customers, or the underlying infrastructure
- Probing, scanning, or testing the vulnerability of the services without prior written authorization
- Reverse engineering, decompiling, or otherwise deriving source code, except where applicable law permits it
- Using the services to develop a competing product or to benchmark for a competitor
- Reselling, sublicensing, or commercially exploiting the services without written consent
- Sending unsolicited bulk communications or harvesting contact information
- Uploading data of children under 13 — or 16 in applicable jurisdictions — without verifiable parental consent
- Uploading protected health information without an executed Business Associate Agreement
- Making automated decisions producing legal effects on individuals without appropriate human review
- Using the services in any country or by any person subject to U.S. embargo, sanctions, or export controls
AI and machine-learning outputs
You may not represent AI-generated outputs as professional legal, medical, or audit advice. You may not use them as the sole basis for material regulatory submissions, audit reports, or attestations made to third parties without independent professional review.
This is not a disclaimer of convenience. AI-assisted gap analysis is a drafting and prioritization aid; the accountable Privacy Officer, Security Officer, auditor, or counsel remains responsible for what gets filed or attested.
Customer responsibilities
You agree to upload only data you have the right to upload, keep your access credentials secure, enforce least-privilege access among your users, and remove personal data that is no longer necessary.
Reporting and enforcement
If you believe someone is using the services in violation of this policy, report it to abuse@shieldra.ai. Security vulnerabilities should go to security@shieldra.ai under our coordinated disclosure policy.
Shieldra may investigate suspected violations and may suspend or terminate access without prior notice where necessary to protect the services, other customers, or third parties, and may cooperate with law enforcement and regulators. Material changes to this policy are communicated through the in-product banner system and by email to account owners.
Frequently asked questions
Can I upload PHI to Shieldra?
Not without an executed Business Associate Agreement. The standard platform is a No-PHI service intended for compliance documentation, policies, risk assessments, and audit evidence.
Can I use Shieldra AI output in an audit report or regulatory filing?
Not as the sole basis. AI-generated outputs may not be represented as professional legal, medical, or audit advice, and may not be used as the sole basis for material regulatory submissions, audit reports, or third-party attestations without independent professional review.
Is security testing of Shieldra allowed?
Only with prior written authorization. Probing, scanning, or vulnerability testing without it is prohibited, but responsible disclosure is welcome — report findings to security@shieldra.ai under the coordinated disclosure policy.