Acceptable Use Policy — Security Research
The Security Research tier provides unrestricted models for authorized, lawful security work. Access is granted to verified security professionals and is governed by this policy. Misuse results in immediate revocation.
סולם Assurance
האסמכתאות (evidence) הנדרשות בכל שלב, וכמות הטוקנים היומית שהוא פותח. שלב כרטיס האשראי פותח את מכסת המחקר החינמית; בדיקות זהות וממשל מעלות את התקרה מעבר לכך.
-
Payment method on file
Evidence: a live credit/debit card (prepaid rejected) verified with a $0 check
מכסה: 102400 tokens/day · תקרה 102400
-
Identity verified
Evidence: Stripe Identity document + selfie check bound to the principal
מכסה: 50000 tokens/day · תקרה 200000
-
Business verified
Evidence: a company on a public registry, a proven domain claim, clean screening
מכסה: 2000000 tokens/day · תקרה 8000000
-
Contracted researcher
Evidence: named researchers, a signed authorized-scope statement, a contract
מכסה: 8000000 tokens/day · תקרה 32000000
שימושים מותרים
- Vulnerability research
- Exploit and proof-of-concept (PoC) development
- Malware analysis and deobfuscation
- Reverse engineering
- Authorized phishing and social-engineering assessments
אסור באיסור מוחלט
- Child sexual abuse material (CSAM)
- Chemical, biological, radiological, nuclear weapons or other weapons of mass destruction (CBRN/WMD)
- Large-scale fraud-as-a-service
CSAM and CBRN/WMD content is strictly blocked; confirmed cases are handled through our incident and abuse process.
יכולת התקפית, בתנאים
Payload and shellcode development, command-and-control (C2) tooling and weaponized exploits are permitted only inside a live engagement you have attested to — a named client, a named scope and an end date — at the contracted rung, on top of this policy.
פרטיות
- Designed for zero data retention
- Request content is screened in memory
- When zero-data-retention is enabled, your content is not used for training
גבול הרצה מקומי
- The service never executes tools, code, commands or network actions server-side; a tool call the model emits is returned to the caller as data (tool_calls) and runs, if at all, on the caller's own machine
- Tool use, command execution and automation stay entirely on the user's local machine, driven by the user's own agent
- Generated exploit or payload text is data returned to the caller — it is never run by kotoba.cloud