Last updated: 2026-08-16. Governing law: Israel.
Acceptable Use Policy (AUP)
This Acceptable Use Policy ("AUP") governs your use of the EyalSec / es2 Service and the
EyalSec agents (the es-python runtime, the es-chromium browser,
and the es-c, es-cpp, es-rust, es-node, es-solidity, es-bash and es-php agents, each an "Agent") (together, the "Service"), provided by Eyal Gabay,
trading as "EyalSec", sole proprietor (osek murshe) no. 211868450, Israel
("EyalSec"). It is incorporated by reference into the Terms of Service (/legal/terms).
Capitalized terms have the meanings given in the Terms. Violating this AUP may result in
suspension or termination (Section 7).
The EyalSec agents are defensive security-monitoring tools: they run on your own machines, browsers and services, observe your own data, and exercise only their own inputs. The rules below keep that use lawful and within scope. Every rule in this AUP applies to every Agent, whether or not a particular Agent is named in it.
1. Authorized monitoring only
- Install and run an Agent only on systems you own or are expressly authorized to monitor. You must have the right to inspect the runtime data of the monitored programs, browsers and services.
- Obtain all consents, notices and authorizations required by law before monitoring begins, including from device owners, employees, contractors, worker representatives, and any individuals whose data may appear in Event Payloads. Section 7 of the Terms sets out this obligation in full and it is a condition of your license.
- Do not use the Service to surveil third parties or third-party systems without authorization. Do not deploy an Agent on any system, browser, profile or account you do not control or have not been authorized, in writing where appropriate, to monitor.
2. Browser-specific rules (es-chromium)
es-chromium reports the pages visited on the machines you monitor and values present in those pages. That makes the rules below non-negotiable:
- Managed deployments only. Deploy es-chromium only on browsers, profiles and devices that you own or administer as an organization, or that you are expressly and lawfully authorized to monitor.
- No covert monitoring. Do not deploy es-chromium in a way that hides the monitoring from the people being monitored where the law requires that it be disclosed.
- No personal or BYOD devices without consent. Do not install es-chromium on a personal or bring-your-own device without the device owner's informed consent.
- No consumer or public deployment. Do not distribute es-chromium to consumers or the general public, install it on shared, public, kiosk or library machines, or make it available as a general-purpose browser download.
- No redistribution or rebranding. Do not repackage, re-sign, mirror, bundle or republish es-chromium, with or without charge, and do not remove or alter its branding, product name or version identifiers.
- Not for high-risk browsing. es-chromium is a monitoring and testing instrument, not a hardened consumer browser. Do not make it the default or primary browser for general-purpose browsing, and run only the current published version (Terms, Sections 9 and 10).
- Extension reports are observations, not verdicts. Any automated report an Agent produces about a browser extension or other third-party component is an observation. Do not present it as a certification, a finding of fact, or an accusation against the component's author, and do not republish it as one.
2a. Contract-compiler rules (es-solidity)
- Never deploy an es-solidity build to a public network. A contract compiled with es-solidity is instrumented for testing: its gas costs and code hash differ from your production build. es-solidity produces development builds only, for development, test and staging.
- You are responsible for keeping instrumented build artifacts out of any production or public deployment pipeline, and for the consequences, including loss of funds, if one reaches a public network.
2b. An empty result is not a finding of safety
Some agents report nothing unless the monitored project is configured for them, and an agent reporting nothing looks exactly like an agent that has found nothing. Configure each agent as our documentation describes, and verify it is actually reporting, before relying on its output or representing the result to anyone else. Do not present an absence of findings as a certification that a system, contract or program is secure.
3. No offensive or malicious use
You must not use the Service to:
- develop, test, store, stage, or deliver malware, ransomware, exploits, or attack tooling against third-party systems without authorization;
- conduct unauthorized penetration testing, intrusion, or "red-team" activity against systems you do not own or are not authorized to test;
- exfiltrate, intercept, or collect data you are not authorized to access, or intercept the communications of any person without the consent required by law;
- harvest credentials, session tokens, payment details or other secrets belonging to any person other than through lawful monitoring of your own authorized systems;
- circumvent security controls, access controls, or authentication of any system without authorization;
- monitor, profile or investigate an individual for a purpose unrelated to securing your own systems, including harassment, stalking, or suppression of lawful activity; or
- engage in any activity that is unlawful, infringing, defamatory, or harmful to others.
Authorized security research and testing on your own or authorized systems is permitted; that is the intended use of the Agents' monitoring, fuzzing, and code-load detection features.
4. Export controls and sanctions
You represent, warrant, and covenant that:
- You will comply with all applicable export-control and economic-sanctions laws, including those of Israel, the United States (EAR/OFAC), the European Union, and the United Kingdom.
- You will not access, use, download, export, re-export, or transfer the Service or any Agent, directly or indirectly, in or to any comprehensively embargoed or sanctioned destination, currently including Iran, North Korea, Cuba, Syria, and the sanctioned regions of Ukraine (including Crimea and the so-called Donetsk and Luhansk regions), or any other destination subject to comprehensive sanctions.
- You are not a denied, restricted, or sanctioned party (for example on the US SDN, Entity, or Denied Persons lists, the EU/UK consolidated sanctions lists, or any equivalent Israeli list), and you are not owned or controlled by, or acting on behalf of, any such party.
- You will not use the Service for any prohibited end-use, for example weapons of mass destruction, or military or intelligence end-uses that require a license you do not hold.
- You will not use the Service, and in particular es-chromium, as part of any programme of covert surveillance of natural persons, or supply it or its output to anyone for that purpose.
See the export-control notice at /legal/export for EyalSec's self-classification.
5. Fair use of the platform
- Do not attempt to gain unauthorized access to the Service, other customers' data, or EyalSec's infrastructure.
- Do not probe, scan, or test the vulnerability of the Service except with EyalSec's prior
written authorization, or in accordance with the coordinated vulnerability disclosure
policy at
/legal/vulnerability-disclosure. - Do not overload, disrupt, or abuse the ingestion API or dashboard, for example by denial-of-service or by excessive automated requests beyond your plan limits.
- Do not interfere with, disable or circumvent any metering, quota, credential, integrity or anti-tamper mechanism, or run an Agent under a credential issued to another account.
- Do not misrepresent your identity or your authorization to monitor a machine.
6. No reverse engineering or competitive use
Do not reverse engineer, decompile, disassemble or attempt to derive the source code, internal design or detection logic of the Service or any Agent, and do not use the Service or any Agent to build, train, or assist a competing product, except to the extent that applicable mandatory law or an applicable open-source license gives you that right. See Section 3 of the Terms.
7. Consequences of violation
EyalSec may investigate suspected violations and may suspend or terminate your access to the Service or any Agent, remove offending content, and report unlawful activity to authorities, with or without notice depending on the severity and applicable law. EyalSec may also take these steps where required to comply with law or sanctions. Termination for an AUP violation does not entitle you to a refund and does not limit EyalSec's other remedies, including under Section 13 of the Terms.
8. Reporting
Report suspected violations to eyal@eyalsec.com. Report suspected security
vulnerabilities to security@eyalsec.com under the policy at
/legal/vulnerability-disclosure.