Acceptable Use Policy
This Acceptable Use Policy (the “Policy”) governs access to and use of ManagedDEX, including Talon and the related software, components, support, and services provided by RavenTek Solution Partners, LLC (“RavenTek”) (collectively, the “Service”). It applies to each customer or licensee (“Customer”) and each person who accesses or uses the Service through or on behalf of a Customer, including Authorized Users, administrators, employees, contractors, agents, and service providers. Where an applicable Order Form and MSP Scope Addendum authorize MSP, partner, multi-tenant, or Managed Client use, this Policy also applies to the Customer’s use for each Managed Client and to each person permitted to access or use the Service in connection with that Managed Client. The Customer is responsible for their compliance. This Policy supplements the ManagedDEX End User License Agreement (“EULA”), Software Support Services Agreement (“SSSA”), applicable Order Form, applicable MSP Scope Addendum, Authorized User Terms, Data Protection Exhibit, and their applicable schedules, annexes, and incorporated terms (collectively, the “Governing Agreements”). Capitalized terms not defined in this Policy have the meanings given in the Governing Agreements. This Policy does not expand the license or services, create a separate acceptance or amendment mechanism, or grant any Managed Client or other third-party rights against RavenTek. If this Policy conflicts with a Governing Agreement, the Governing Agreement controls, with the Data Protection Exhibit controlling as to its subject matter and any more specific applicable Order Form or MSP Scope Addendum controlling as to its specific scope. RavenTek may update this Policy as permitted by the Governing Agreements and applicable law, including as reasonably necessary to address security threats, legal or regulatory requirements, or changes to the Service. An update does not retroactively modify the Governing Agreements or materially reduce Customer rights except through a mechanism they permit.
Use Restrictions
The Customer and each person bound by this Policy may not use the Service to:
Use for an unlawful or harmful purpose: use the Service for any unlawful, fraudulent, deceptive, abusive, or harmful purpose, or in violation of applicable law, sanctions, export controls, or third-party terms.
Violate rights: infringe, misappropriate, or otherwise violate any intellectual property, privacy, publicity, confidentiality, contractual, or other right of any person.
Compromise security: access or attempt to access any system, network, endpoint, tenant, data, account, API, model, rule, script, or non-public functionality without authorization; probe, scan, benchmark, or test vulnerabilities or performance; conduct penetration testing; or bypass security, authentication, logging, telemetry, rate limits, or access controls, except testing expressly authorized in writing by RavenTek and conducted within the approved scope.
Disrupt or damage: interfere with, disable, overload, or degrade the Service or any connected system, including through denial-of-service activity, excessive or automated requests, destructive instructions, or the introduction or distribution of malware, ransomware, malicious code, or harmful content.
Misuse or submit prohibited data: access, collect, upload, process, disclose, or transmit data without all required rights, notices, consents, and authority. Unless RavenTek has signed a written addendum expressly permitting the data and the Customer handles it under the controls required by that addendum and the Governing Agreements, do not submit protected health information subject to HIPAA; cardholder data subject to PCI DSS; non-public personal information subject to the Gramm-Leach-Bliley Act; biometric or genetic identifiers; government-issued identification numbers, including Social Security numbers, driver’s license numbers, and passport numbers; personal information of children under sixteen; special-category or sensitive data under applicable Data Protection Laws; classified information; Controlled Unclassified Information (CUI); export-controlled information; or other regulated or government data requiring contractual, security, residency, authorization, or handling controls not expressly covered by the Governing Agreements.
Misuse artificial intelligence: use the Service, its outputs, or automated access to train, fine-tune, validate, benchmark, or improve a general-purpose or competing artificial intelligence or machine-learning model without RavenTek’s prior written authorization; scrape or systematically extract models, prompts, outputs, rules, or datasets; use AI features for malware, evasion, fraud, impersonation, exploitation, unlawful surveillance, or other malicious purposes; or submit prohibited data, RavenTek Confidential Information, third-party confidential information, credentials, or secrets to an AI tool or provider not authorized under the Governing Agreements. Customers and users must review, test, and validate AI-assisted or generated recommendations, scripts, remediations, configurations, and other outputs before relying on or deploying them. RavenTek does not warrant the accuracy, completeness, or fitness of any AI-generated or AI-assisted output, and the Customer assumes all risk of reliance on such output.
Reverse engineer or scrape: reverse engineer, decompile, disassemble, decode, or attempt to derive or extract source code, non-public APIs, models, model weights, prompts, rules, scripts, logic, algorithms, architecture, or datasets from the Service, except to the extent the restriction is prohibited by law or RavenTek expressly authorizes the activity in writing.
Resell or exceed scope: rent, resell, sublicense, distribute, white-label, provide service-bureau access to, or otherwise make the Service available beyond the scope expressly authorized by the Governing Agreements, including for a Managed Client not covered by an applicable Order Form and MSP Scope Addendum.
Misrepresent, harass, or abuse: impersonate a person or entity; misstate affiliation or authority; use another person’s credentials; facilitate credential sharing, phishing, stalking, threats, harassment, discrimination, exploitation, or unsolicited communications; or generate or distribute unlawful, deceptive, malicious, or abusive content.
Your Responsibilities
- Maintain unique credentials, protect credentials, API keys, tokens, and secrets against unauthorized use, promptly revoke access when no longer needed, apply least-privilege access, and periodically review user, administrator, contractor, integration, and Managed Client access.
- Obtain and maintain all rights, licenses, subscriptions, notices, consents, authorizations, credentials, and lawful bases required for each endpoint, environment, data source, Third-Party Platform, instruction, and data set connected to or used with the Service, including those of Managed Clients.
- Ensure Authorized Users, administrators, employees, contractors, agents, service providers, and, where applicable, Managed Clients comply with this Policy, the Authorized User Terms, and applicable third-party requirements; impose written downstream obligations at least as protective as the Governing Agreements where required; and remain responsible for their acts and omissions.
- Configure and use the Service in accordance with the Documentation, the Governing Agreements, applicable law, and contractual data-handling restrictions, and do not exceed licensed endpoints, territories, tenants, use cases, or other scope limitations.
- Promptly report, and in no event later than forty-eight (48) hours after discovery, suspected or actual unauthorized access, credential compromise, security vulnerabilities, misuse, or security incidents involving the Service, preserve relevant information, and reasonably cooperate with investigation and remediation. This reporting obligation supplements and does not replace any notice, timing, content, cooperation, or other duty under the Governing Agreements or applicable law.
Enforcement
RavenTek may investigate reasonably suspected violations and may request information, records, cooperation, or corrective action as permitted by the Governing Agreements and applicable law. RavenTek may suspend or restrict affected access when and to the extent permitted by the Governing Agreements, including where reasonably necessary to address an actual or threatened security risk, unlawful use, material service disruption, or risk to the Service, RavenTek, a Customer, a Managed Client, or a third party. Where practicable and consistent with security, law, and the Governing Agreements, RavenTek will provide notice and a reasonable opportunity to cure, and will use commercially reasonable efforts to restore affected access within a reasonable time after the grounds for suspension have been remedied to RavenTek’s reasonable satisfaction, subject to verification and any conditions permitted by the Governing Agreements. Any suspension, cure period, restoration, or termination will be governed exclusively by the Governing Agreements; this Policy creates no independent termination right.
Reporting
Report suspected abuse to manageddexlegal@raventek.com, and suspected security issues or vulnerabilities to managedexsecurity@raventek.com. Do not include passwords, private keys, access tokens, prohibited data, or unnecessary personal or confidential information in an initial report. Follow any additional incident-notification method required by the Governing Agreements.
This Policy supplements and is subject to the Governing Agreements. It does not expand any license, service commitment, remedy, or right, and the applicable Governing Agreements control in the event of conflict.