Acceptable Use & Security Policy

Effective: August 31, 2026 · Last reviewed: August 31, 2026 · Calculated Ventures, LLC

Core rule: Use the Service only for systems, files, and customer environments you are authorized to assess or support.

1. Authorized Use

You may use the Service for legitimate internal cybersecurity, RMF, vulnerability-management, remediation-planning, and authorized client-support work. You are responsible for obtaining any authorization required from the system owner, client, or contracting authority.

2. Prohibited Data

Do not upload classified information, CUI, export-controlled technical data, credentials, passwords, private keys, PHI, payment-card data, malware samples, or other regulated/high-risk data unless Calculated Ventures has expressly authorized that data type in writing for the specific service environment.

3. Prohibited Activity

4. Account Security

Protect credentials, use available MFA when required or offered, limit access to authorized personnel, and notify us promptly of suspected compromise or unauthorized use.

5. Vulnerability Data

Scan results may contain sensitive infrastructure information. Limit uploads to the data necessary for the work, sanitize demonstrations, and remove unrelated secrets or identifying details when practical.

6. Remediation Safety

Generated remediation commands, scripts, registry changes, configuration instructions, or other technical steps can alter system behavior or availability. Review and test them before execution. Use qualified personnel, backups, approved change control, maintenance windows, and rollback plans appropriate to the target system. Do not execute generated remediation automatically on safety-critical, operational-technology, medical, life-safety, weapons, industrial-control, or other high-impact systems without system-specific engineering review and authorization.

7. Security Testing of the Service

If you believe you found a vulnerability in CalculatedIT RMF Accelerator, do not exploit it or access other customers' data. Stop testing and report the issue to inquiry@calculatedit.com. We may provide written authorization for further testing on a case-by-case basis.

8. Export Controls and Sanctions

Do not use the Service, provide access, or transfer related technical information in violation of applicable U.S. export-control or economic-sanctions laws. You are responsible for the legality of your users, locations, end uses, end users, and Customer Content.

9. Enforcement

We may investigate suspected violations and suspend, restrict, or terminate access when reasonably necessary to protect the Service, customers, third parties, or legal obligations. Serious suspected unlawful activity may be reported to appropriate authorities when required or permitted by law.

10. Contact

Questions or security reports: inquiry@calculatedit.com.