Legal / safe infrastructure

Acceptable Use Policy

Archived draft

Last updated July 28, 2026. Written for the current prelaunch product.

Version
2026-07-28
Effective
Not yet effective
Review by
Before public signup

This Policy applies to every User Profile, account, project, API key, connected provider, sandbox, and workload used through Wildflower.

1. Use only what you are authorized to use

You may use Wildflower only with systems, accounts, data, networks, provider credentials, and workloads that you own or are expressly authorized to use. Authorization must cover both the activity and its scope.

2. Prohibited activity

You may not use the Services to:

  • Break applicable law or violate another person’s rights.
  • Access, scan, probe, exploit, or interfere with systems, accounts, data, or networks without authorization.
  • Create, distribute, deploy, or control malware, ransomware, credential stealers, botnets, destructive code, or unauthorized persistence.
  • Conduct phishing, impersonation, fraud, spam, credential stuffing, or deceptive collection of authentication material.
  • Launch denial-of-service attacks, abusive automated traffic, or activity intended to evade provider or Wildflower safeguards and limits.
  • Mine cryptocurrency, proxy traffic for unrelated third parties, or consume resources primarily to impose cost or degradation on Wildflower, a provider, or another customer.
  • Process or distribute content that is illegal, exploitative, or created through an unlawful invasion of privacy.
  • Resell access to Wildflower or a connected provider unless a written agreement expressly permits it.

3. Security research

Security research must be limited to accounts, projects, sandboxes, and infrastructure you own or have written authorization to test. Do not test Wildflower, another customer, or a provider outside an announced security program or specific written permission.

If you discover a suspected vulnerability, stop before accessing additional data, preserve only the minimum safe evidence, and follow the security reporting guidance. Never include live credentials or Customer Content in an initial report.

4. High-risk and regulated use

The prelaunch service is not approved for safety-critical systems, emergency services, protected health information, payment-card data, production regulated workloads, or decisions that create legal or similarly significant effects for people. Written enterprise terms may identify supported regulated uses later.

5. Customer safeguards

You are responsible for applying least-privilege credentials, limiting network access, validating untrusted input, patching code you run, deleting unused sandboxes, and monitoring your applications. Wildflower’s isolation and limits do not replace application security.

6. Investigation and enforcement

Wildflower may investigate reliable abuse reports and safe operational signals. We may rate-limit, block an operation, revoke credentials, suspend access, preserve relevant records, contact a provider, or terminate service when reasonably necessary to prevent harm, comply with law, or enforce this Policy.

Where practical and safe, Wildflower will provide notice and an opportunity to correct a violation. Immediate action may be taken for urgent security risk, unlawful activity, provider requirements, or threats to people, infrastructure, or other customers.

7. Changes and questions

Material updates will be dated on this page. Questions about whether a planned workload is permitted should be raised through the current support channel before running it.