Acceptable use policy

Use OCM lawfully, safely, and within your authority.

This policy applies to the website, hosted OCM services, APIs, trials, support channels, and related infrastructure. It is incorporated into the Terms of Use and Service.

Effective August 6, 2026 · Last updated August 6, 2026

01

Prohibited conduct

You may not use the service to:

  • Violate law, court order, professional obligation, intellectual-property right, privacy right, or another person’s rights.
  • Access, alter, disclose, or retain an account, system, or information without authorization.
  • Distribute malware; facilitate phishing, fraud, harassment, exploitation, or unlawful surveillance; or conceal malicious activity.
  • Send unlawful or unsolicited bulk communications, spoof identity, or use misleading routing or sender information.
  • Interfere with service availability, bypass rate limits or access controls, probe another customer, or impose unreasonable load.
  • Reverse engineer a proprietary hosted component except where law forbids restriction. This does not limit rights granted by the GPL for GPL-licensed OCM code.
  • Use the service to build or train a competing general-purpose model from data you lack authority to use.
02

Sensitive and regulated information

Customer must determine whether its use is permitted for confidential legal information, personal information, health information, criminal-justice information, payment data, government identifiers, information about minors, or other regulated data. Do not place payment-card authentication data, account passwords, or private cryptographic keys in ordinary OCM record fields. A contractual commitment such as a BAA, data-processing addendum, or specialized security term applies only when signed by authorized representatives.

03

Security research

Good-faith research conducted within the published Vulnerability Disclosure Policyis permitted. Testing outside that policy, accessing another customer, degrading service, social engineering, physical testing, persistence, or unnecessary access or retention of data is prohibited without advance written authorization.

04

Enforcement

We may investigate suspected violations and preserve relevant records. Where practical and safe, we will ask Customer to cure before restricting service. We may immediately block content, credentials, traffic, an integration, or access when reasonably necessary to stop material harm, comply with law, or protect customers or infrastructure. We will tailor action to the risk and restore access when the issue is resolved. Report abuse to alex@clarkmanagementconsulting.com.