Liskov Acceptable Use Policy
Version 1.0 — effective 1 September 2026
This Acceptable Use Policy (AUP) forms part of the Liskov Contract. It applies to Customer, Authorised Users, Applications, Distributed Workloads, Marketplace submissions and anyone to whom Customer makes an Application available.
The examples below are illustrative. Conduct with a substantially similar harmful purpose or effect is also prohibited. PROOF will interpret and enforce the AUP reasonably, taking account of context, authorisation, intent, safeguards and actual risk.
1. General rule
You must not use, attempt to use, or allow the Services to be used:
(a) unlawfully or to facilitate unlawful conduct;
(b) to infringe or misappropriate another person’s rights;
(c) to harm or create an unreasonable risk to people, systems, Networks, property or the Services;
(d) deceptively, fraudulently or without required authorisation; or
(e) contrary to the Contract, Documentation or a reasonable security instruction.
2. Prohibited workload data
A Distributed Workload runs on independently operated nodes, not on PROOF systems. PROOF cannot see its contents and does not process them for you. You are responsible for any Personal Data you choose to process in an Application, including its lawful basis, notices, minimisation, encryption, transfers and residency. You must not place in a Distributed Workload:
- payment-card data, bank credentials or regulated financial account data;
- private keys, seed phrases, unrestricted API keys, passwords or authentication secrets;
- data that must, by contract or law, be processed only in a named location or only in the United Kingdom; or
- classified or export-controlled technical data that may not lawfully be handled in an unknown country.
Encryption or pseudonymisation does not by itself take data outside these rules.
3. Security abuse
You must not, without clear legal authority and the informed permission of the system owner:
(a) gain or attempt to gain unauthorised access to an account, system, wallet, network, device or data;
(b) scan, probe, enumerate or test a vulnerability beyond the scope of a published vulnerability disclosure programme or written authorisation;
(c) bypass authentication, rate limits, isolation, spending controls, sanctions controls or other security measures;
(d) intercept, monitor, alter, replay or inject traffic or transactions without authority;
(e) deploy malware, ransomware, spyware, credential stealers, botnets, rootkits, cryptojackers or destructive code;
(f) generate, host, distribute or facilitate phishing, pharming, spoofing or credential harvesting;
(g) conduct denial-of-service or resource-exhaustion activity;
(h) compromise a Network Participant or use compromised infrastructure;
(i) conceal the origin or control of malicious activity through obfuscation, fast flux, domain generation, open proxies or similar techniques; or
(j) publish an unremediated vulnerability in a way that foreseeably creates avoidable harm.
Good-faith defensive security research is permitted only within written authorisation, law and applicable programme rules. It must use proportionate rates, safe data, prompt reporting and no extortion, persistence or unnecessary access.
4. Harmful communications and content
You must not use the Services to create, host, distribute, promote, solicit or materially facilitate:
(a) child sexual abuse material, child sexual exploitation or grooming;
(b) terrorist content, instruction or support prohibited by law;
(c) credible threats, incitement to violence or targeted harassment;
(d) non-consensual intimate images or sexually exploitative content;
(e) content that unlawfully promotes suicide, self-harm, eating disorders or dangerous acts;
(f) trafficking, slavery, coercion or sexual exploitation;
(g) unlawful hate content or unlawful discrimination;
(h) fraud, scams, impersonation, forged documents or deceptive schemes;
(i) doxxing or unlawful publication of private/confidential information; or
(j) any other illegal content.
A technical tool with legitimate uses is not prohibited solely because it could be misused. You remain responsible for reasonable safeguards, customer screening and response to abuse.
5. Intellectual property and confidentiality
You must not:
(a) use content, code, data, models, marks or secrets without sufficient rights;
(b) remove or falsify copyright, licence, attribution or provenance information;
(c) circumvent effective rights-management controls unlawfully;
(d) disclose trade secrets or confidential information without authority;
(e) use a Marketplace listing to distribute code in breach of its open-source or third-party licence; or
(f) knowingly train, fine-tune or operate a model using unlawfully obtained content.
6. Network, messaging and platform abuse
You must not:
(a) send unsolicited bulk messages or facilitate spam in breach of law or recipient/provider rules;
(b) operate an open mail relay, open proxy, public VPN exit, Tor exit, traffic relay, anonymous abuse infrastructure or public resolver without PROOF’s prior written approval and appropriate abuse controls;
(c) spoof source addresses, headers, caller identity or routing information deceptively;
(d) scrape or crawl a service in breach of law, access controls or a binding restriction, or at a rate causing harm;
(e) manipulate ratings, reviews, referrals, usage, proofs, node selection, rewards or Marketplace ranking;
(f) create accounts, Workspaces or identities to evade a restriction, charge, suspension or spending limit;
(g) resell or share access contrary to an Order;
(h) interfere with service metering, logs, billing or attribution; or
(i) consume resources in a manner materially disproportionate to the purchased plan or designed to degrade others’ service.
7. Cryptoasset and blockchain misuse
You must not use the Services to:
(a) steal, drain, launder, conceal or unlawfully transfer cryptoassets;
(b) compromise wallets, private keys, bridges, exchanges, protocols or smart contracts;
(c) conduct market manipulation, wash trading, front-running or another prohibited trading practice;
(d) evade sanctions, asset freezes, transaction monitoring or lawful reporting;
(e) issue, promote or distribute an unlawful financial product or unlawful financial promotion;
(f) provide regulated exchange, brokerage, custody, money transmission, payment or investment activity without all required authorisations and PROOF’s prior written approval;
(g) operate a mixer/tumbler or materially similar obfuscation service without PROOF’s express written approval following legal review; or
(h) mine proof-of-work cryptocurrency unless the Order expressly permits it.
Running lawful blockchain infrastructure is not prohibited merely because it processes cryptoasset data. Customer must assess and comply with its own regulatory perimeter.
8. Sanctions, export controls and restricted territories
You must not use the Services:
(a) by, for, through or for the benefit of a person or territory with whom PROOF is prohibited from dealing;
(b) to evade or facilitate evasion of sanctions, export controls, asset freezes or trade restrictions;
(c) to export, re-export or transfer controlled software, technology or services without required authorisation; or
(d) in a way that makes PROOF or a Network Participant breach applicable restrictions.
You must provide accurate compliance information on request. The Standard Service does not guarantee execution in a particular geography; do not use it for location-restricted data.
9. Weapons, surveillance and dangerous activity
Without PROOF’s prior written approval following legal review, you must not use the Services for:
(a) development, targeting, operation or deployment of weapons or autonomous lethal systems;
(b) nuclear, missile, chemical or biological weapons activity;
(c) unlawful interception, surveillance, facial recognition, biometric tracking or location tracking;
(d) spyware or stalkerware;
(e) evasion of lawful safety controls in vehicles, industrial systems or critical infrastructure; or
(f) instructions intended to cause physical harm, illegal manufacture or dangerous release.
General-purpose research, simulation or defensive work may be approved where lawful and appropriately controlled.
10. Regulated and high-impact uses
The Standard Service is not designed for a use in which failure or an incorrect result could reasonably cause death, personal injury, material property/environmental damage or deprivation of a person’s legal rights. Without a written Enterprise Order addressing the specific risk, you must not use it as the sole or determinative system for:
- medical diagnosis, treatment or emergency response;
- credit, insurance, employment, housing, education or benefits eligibility;
- legal adjudication, law-enforcement decisions or immigration decisions;
- operation of critical infrastructure, utilities, transport or industrial safety systems;
- biometric identification or high-impact profiling;
- regulated gambling;
- custody or transfer of customer funds/assets; or
- any safety-critical control loop.
Where approved, Customer must implement qualified human oversight, validation, fail-safe operation, auditability and sector compliance.
11. Marketplace integrity
Any person that submits or publishes a Marketplace item must not:
(a) submit malicious, materially insecure or deceptively described code;
(b) conceal material external charges, telemetry, permissions or dependencies;
(c) include a secret or live credential;
(d) impersonate another publisher or misuse a mark;
(e) manipulate reviews, installs or ranking;
(f) publish abandoned or unsupported content as actively maintained;
(g) use a free-only listing to require an undisclosed payment for the listed core functionality; or
(h) evade a suspension by republishing substantially the same item.
Publishers must respond reasonably to vulnerability, licence and rights reports.
12. Protecting the Services
You must not:
(a) reverse engineer proprietary PROOF Technology except where law gives a non-excludable right;
(b) copy or scrape non-public service data outside documented APIs;
(c) use the Services to develop or train a competing platform using confidential or non-public information;
(d) remove proprietary notices;
(e) benchmark the Services publicly in a misleading manner or without disclosing material methodology; or
(f) misuse support, reporting or appeal channels.
This section does not override open-source rights or lawful interoperability rights.
13. Enforcement
13.1 Investigation
PROOF may investigate a suspected breach using Account Data, logs, public content, technical indicators, reports and proportionate inspection permitted by the Contract and law. PROOF does not promise to monitor all content or prevent every breach.
13.2 Measures
Depending on severity, history and urgency, PROOF may:
- warn and require remediation;
- rate-limit or isolate a workload;
- remove or delist content;
- disable a credential or feature;
- preserve evidence;
- suspend or terminate access;
- block a payment or wallet before acceptance;
- notify an affected party, Network, regulator or law-enforcement body where lawful; or
- take another proportionate protective step.
Immediate action may be taken for serious illegality, security threats, sanctions, child safety, terrorism, fraud or material harm.
13.3 Notice and reasons
Where lawful and reasonably practicable, PROOF will give the Workspace administrator notice and a general statement of reasons. PROOF may withhold detail that would expose detection methods, facilitate evasion, prejudice an investigation, identify a reporter unlawfully or create risk.
13.4 Appeal
Customer may appeal a non-emergency enforcement decision within 14 days through the route stated in the notice. The appeal should identify the decision, explain the error and provide supporting information. A person not materially involved in the original decision should review significant appeals where practicable. Enforcement remains in place during appeal unless PROOF decides otherwise.
13.5 Restoration
PROOF will restore access or content when the ground is resolved and restoration is lawful and safe. PROOF may require remediation, verification, a revised architecture or an Enterprise Order.
14. Reporting abuse
Report abuse to abuse@proof.computer, and a security vulnerability or active malicious package to security@proof.computer. Include, where available:
- URL, listing ID, Workspace or transaction hash;
- description and legal/safety basis;
- timestamps;
- screenshots or headers;
- steps to reproduce safely;
- whether there is imminent danger; and
- reliable contact details.
Do not send illegal content itself where a URL/hash and description are sufficient. For an immediate threat to life, contact emergency services first.
Marketplace reports are handled under the Notice-and-Action Policy.
15. Changes
PROOF may update this AUP under the Master Business Terms. Urgent additions addressing new abuse or legal requirements may take effect sooner than 30 days where reasonably necessary.
MOOSE LABS LTD trading as PROOF · Version 1.0 · effective 1 September 2026 · previous versions are archived by PROOF and available on request from legal@proof.computer.