Acceptable Use Policy
Last updated: 6 April 2026
1. Permitted use
The Gravitas platform is provided for the following legitimate purposes:
- Internal security operations and incident response
- Credential monitoring for your own organisation's domains and employees
- Security posture assessment and compliance reporting
- Due diligence and supply chain risk assessment (where authorised)
- Integration with your organisation's security toolchain via the API
All use must be conducted by authorised personnel acting within the scope of their organisation's subscription.
2. Prohibited conduct
The following activities are strictly prohibited. Violations may result in immediate account termination and, where applicable, referral to law enforcement.
Misuse of breach data
- Using exposed credentials to access any account, system, or service — whether or not you believe the account belongs to your organisation
- Reselling, redistributing, or publicly disclosing raw breach data, stealer log contents, or any other Threat Intelligence Data obtained through the Platform
- Using Threat Intelligence Data to harass, stalk, blackmail, extort, or target any individual
- Using Threat Intelligence Data for employment discrimination, insurance underwriting, credit assessment, or any decision that adversely affects an individual outside of legitimate security response
Unauthorised monitoring
- Submitting seed data for domains or organisations you are not authorised to monitor
- Conducting surveillance of individuals outside the scope of your organisation's legitimate security operations
Platform abuse
- Bulk extraction, scraping, or automated harvesting of data beyond normal platform and API use
- Circumventing platform access controls, rate limits, or usage restrictions
- Attempting to access other users' data or accounts
- Reverse-engineering, decompiling, or disassembling the Platform
Unlawful activity
- Any activity that violates the Computer Misuse Act 1990
- Any activity that violates the Data Protection Act 2018 or UK GDPR
- Using the Platform to facilitate, plan, or support any criminal activity
3. Monitoring and enforcement
Laneden Ltd reserves the right to:
- Monitor platform usage patterns and API access for compliance with this policy
- Investigate suspected violations, including reviewing access logs and usage records
- Suspend or restrict account access immediately where a severe violation is suspected, without prior notice
- Terminate accounts for confirmed violations
- Report illegal activity to relevant law enforcement authorities
4. Reporting misuse
If you become aware of any misuse of the Gravitas platform or Threat Intelligence Data, report it immediately to security@withgravitas.io.
All reports are treated confidentially and investigated promptly.