Skip to content

    Acceptable Use Policy

    What you may and may not do with Opafra.

    Last updated: August 2026

    This Acceptable Use Policy (the “Policy”) applies to all use of the Opafra platform, websites, applications, APIs, and integrations (the “Service”), and to everyone who accesses it — customers, users, administrators, invitees, contractors, and anyone using the Service through a customer account. It is part of, and supplements, the Terms of Service. Because the Service runs automation and commands against remote infrastructure, this Policy sets clear limits. Violations may result in suspension or termination.

    Authorized use only

    • You may only connect the Service to, and run automation against, infrastructure that you own or are explicitly authorized to administer.
    • You are responsible for obtaining all necessary permissions before adding a server, credential, or target, and before executing any plan against it.
    • Keep credentials scoped to least privilege and only store credentials you are authorized to use.

    Prohibited uses

    You may not use the Service to:

    • Target systems you are not authorized to access — access, scan, probe, penetration-test, or attack any system, network, or account you do not own or have explicit authorization to manage.
    • Break the law — engage in or facilitate any activity that is unlawful, or that infringes or misappropriates the rights of others.
    • Abuse security — bypass or attempt to bypass authentication, tenant isolation, access controls, or rate limits; probe for vulnerabilities except under an authorized program; or create a material security or availability risk to the Service or others.
    • Distribute malicious code — introduce malware, ransomware, worms, trojans, or other harmful or deceptive code.
    • Interfere with the Service — conduct denial-of-service activity, or overload, degrade, or disrupt the Service or the infrastructure of others.
    • Send spam or run abusive automation — transmit unsolicited bulk messages, or run automation designed to harass, defraud, or overwhelm third parties.
    • Scrape or harvest — collect personal data without authorization, or create fake or fraudulent accounts.
    • Mine cryptocurrency or otherwise consume disproportionate resources without authorization.
    • Reverse engineer or resell — reverse engineer, decompile, or attempt to derive the source code or underlying ideas of the Service; build a competing product from it; or resell, sublicense, or provide it to third parties except as your plan permits.
    • Impersonate or mislead — impersonate any person or entity, or misrepresent your affiliation.
    • Access other tenants — attempt to access another customer's organization, data, or credentials.
    • Use AI features to cause harm — use the plan composer or any AI feature to generate or execute automation against systems you are not authorized to access, or to produce unlawful or deceptive output.

    Credentials & secrets

    You are responsible for the security of credentials and secrets you provide to the Service, for scoping them to least privilege, and for revoking them when appropriate.

    Responsibility for users

    You are responsible for all activity under your account and for compliance with this Policy by anyone who uses the Service with your permission, including your Users, invitees, and any automation or API integrations you configure.

    Monitoring & enforcement

    We may investigate suspected violations and may deny access, suspend, or terminate use of the Service — including for unintentional violations — where we believe it is necessary to protect the Service, other customers, or third parties. Where feasible we will provide notice, but we may act immediately for serious or ongoing violations, and without refund. We may cooperate with law enforcement where required by law.

    Reporting abuse

    Report suspected abuse or security issues to [email protected] (abuse) or [email protected] (vulnerabilities).