Legal
Acceptable Use
What you may not do with the KRAGOS surfaces and products, and what happens if you do it anyway.
In one line
Do not use KRAGOS to break the law, to get around the release gate or someone else's seat authority, to attack the system, to scrape it, or to load personal information you are not entitled to process. If you do, we can suspend you.
1. Scope
This Acceptable Use Policy governs the use of the KRAGOS surfaces and products by every customer and every authorised user. It is incorporated into the Terms of Service by clause 1.9 of those Terms, and defined terms in those Terms have the same meaning here.
It applies to kragos.ai, to kragos.app, to every API and integration we expose, and to any communication rail we operate on a customer's behalf.
A customer is responsible for its authorised users' compliance with this policy, as clause 5.2 of the Terms of Service provides.
2. Prohibited uses, generally
You must not use the Services to do, attempt, facilitate or encourage any of the following.
- Anything unlawful under South African law, or under the law of any country where you or your recipients are.
- Anything that infringes a third party's intellectual property, confidentiality, privacy or personality rights.
- Uploading, generating, storing or transmitting content that is unlawful, defamatory, harassing, threatening, hateful, or that constitutes incitement, propaganda for war, or advocacy of hatred as contemplated in section 16(2) of the Constitution.
- Uploading, generating, storing or transmitting child sexual abuse material or non-consensual intimate images. We report this to the South African Police Service and we do not warn the account first.
- Fraud, misrepresentation, phishing, impersonation of a person or entity, or the creation of a document or a record intended to deceive.
- Distributing malware, ransomware, a logic bomb, or any code intended to damage, disable or gain unauthorised access to a system.
- Sending unsolicited bulk commercial communication, whether by email, SMS or WhatsApp, in breach of section 45 of the Electronic Communications and Transactions Act 25 of 2002 or section 69 of the Protection of Personal Information Act 4 of 2013.
- Money laundering, sanctions evasion, or terrorist financing.
- Using the Services to compete with KRAGOS, to benchmark them for publication without our written consent, or to build a substantially similar product.
3. The release gate and seat authority
This is the one that matters most
The release gate and the seat authority model are the architecture. Attempting to get around them is a material breach of the Terms of Service, and it is the one thing that will get an account suspended without a warning period.
You must not attempt to cause an act to be executed without a valid release by an authorised user holding release authority for that act.
You must not attempt to alter, suppress, delete, backdate or forge an entry in the STEMPA journal, or to disable journalling.
You must not share a seat, use another person's credentials, or allow a person to act under a seat issued to someone else. A seat is issued to one named natural person.
You must not attempt to grant yourself, or to cause the system to grant you, an authority or a bound that your customer's administrator has not recorded against your seat.
You must not use a service account, a script or an automation to simulate a human release, or to release in the name of a person who has not authorised it.
You must not construct an input, a document or a prompt whose purpose is to cause a model to propose an act outside the bounds recorded against the releasing seat.
Where a customer's own governance requires a second signature or a board resolution before an act, configuring the system so that a single seat can release it does not change the customer's own governance requirement. That remains the customer's responsibility.
4. Security testing
You must not conduct penetration testing, vulnerability scanning, fuzzing, load testing or any other security testing against the KRAGOS surfaces without our prior written authorisation.
To request authorisation, write to ops@kragos.app with the scope, the source addresses, the window and the named person responsible. We will respond, and we will usually agree, in writing, with a defined scope and window.
Unauthorised access to a computer system is an offence under section 86 of the Electronic Communications and Transactions Act 25 of 2002 and under the Cybercrimes Act 19 of 2020. We will report it.
Responsible disclosure. If you find a vulnerability, tell us at ops@kragos.app. Do not exploit it beyond what is needed to demonstrate it, do not access another person's data, and do not publish it until we have had a reasonable opportunity to fix it. We will not pursue a researcher who follows this clause in good faith.
You must not attempt to circumvent authentication, rate limits, tenant isolation, or any other access control.
5. Scraping and automated access
You must not scrape, crawl, spider, harvest, index or otherwise systematically extract content or data from the KRAGOS surfaces, whether manually or by automated means, except:
- through an API we have given you credentials for, within its documented limits;
- using the export functions in the product, for your own data;
- by a search engine crawler obeying our robots directives, for the public site.
You must not use the Services to build a dataset for training an artificial intelligence model, whether your own or a third party's.
You must not remove, obscure or alter a proprietary notice, a watermark, or an attribution in output the Services produce.
You must not use the free compliance calendar to build a competing product or a published dataset.
6. Rate limits and fair use
The Services are subject to rate limits, concurrency limits and volume caps. They protect availability for everyone.
Metered capability usage is capped per subscription under clause 6.2 of the Terms of Service. When a cap is reached the capability stops. It does not bill through the cap.
You must not attempt to evade a limit or a cap, including by creating additional tenants, rotating credentials, or distributing traffic across accounts.
Where usage on a subscription is materially out of proportion to the seats and the scope of work, we will contact you and agree a fair use position before taking any other step.
We may apply a temporary limit without notice where usage threatens availability for other customers, and we will tell you as soon as we have done it.
7. Data you may load
You must not upload personal information that you are not entitled to process. You must have a lawful basis under section 11 of the Protection of Personal Information Act 4 of 2013, and you must have given the notices your own data subjects are entitled to.
You must not upload special personal information under section 26 of that Act, or the personal information of a child under section 34, without first telling us in writing, as clause 18.8 of the Terms of Service requires.
You must not upload information you obtained unlawfully, including a database bought from a broker without a lawful basis, a scraped contact list, or a list taken from a former employer.
You must not use the Services to send direct marketing to a person who has not consented or who has opted out.
You must not upload payment card data, and the Services are not certified to hold it. If you need to, speak to us first.
You must not upload content subject to an export control or a sanctions restriction that would make our processing of it unlawful.
8. Third party systems
Where you connect the Services to a third party system, you warrant that you are entitled to make that connection and to move the data through it.
You must not use the Services to access a system you are not authorised to access, or to act on behalf of a person who has not authorised you.
9. Consequences
If we believe on reasonable grounds that this policy has been breached, we may, proportionately to the breach:
- contact you and ask you to stop;
- restrict or suspend the affected capability, seat or integration;
- suspend the tenant;
- terminate the Order or the Agreement under clause 19.3 of the Terms of Service;
- preserve and disclose evidence to a law enforcement agency or a regulator where the law requires or permits it.
We will normally warn first. We will not warn first where the breach involves material described in clause 2.1 items 4, 5 or 6, where it is an attempt to circumvent the release gate or seat authority under clause 3, where it is unauthorised security testing under clause 4, or where continuing would expose us or another customer to legal or security risk.
Suspension does not suspend the obligation to pay fees, as clause 7.7 of the Terms of Service provides.
Where we suspend, we will tell you why, in writing, and we will tell you what has to change for the suspension to be lifted.
Data export on exit is governed by clause 20 of the Terms of Service and is not withheld as a sanction, except where a court or a regulator directs otherwise.
You may challenge a suspension under clause 28 of the Terms of Service.
10. Reporting abuse
Report abuse, a security issue, or content that breaches this policy to ops@kragos.app. Say what you found and where.
We acknowledge within 5 business days, and sooner where the report concerns an active security incident or unlawful content.
11. Changes
We may update this policy. A material change raises the version number and is notified to customers in writing before it takes effect.
Acceptable Use, version 1.0, last updated 5 September 2026. Published by Ecopackaging (Pty) Ltd (registration number 2014/032538/07, VAT registration number 4530265216) trading as KRAGOS, 750 Nieuwhout Street, Garsfontein, Pretoria, 0081, South Africa. All enquiries and notices to ops@kragos.app. Information Officer: Francois Petrus Heunis. Governed by the law of the Republic of South Africa; the parties consent to the jurisdiction of the Gauteng Division of the High Court of South Africa, Pretoria.