Acceptable use policy

Rules for the apps, machines and network Pilae operates for you: what is not allowed, security testing, reporting abuse and how the policy is enforced.

Last updated

This acceptable use policy (“AUP”) sets the rules for using the services of Pilae SA, Rue de Bourg 27, 1003 Lausanne, Switzerland (“Pilae”). It applies as set out in the customer’s contract. Where the contract says something different, the contract prevails.

1. Who this policy applies to

1.1 This AUP applies to every customer of Pilae and to everyone the customer lets use the services: employees, contractors, partners and end users.

1.2 The customer is responsible for use of the services by the people it gives access to, and for making them aware of these rules.

2. What the services cover

2.1 “Services” means the apps Pilae operates, the machines in Pilae Cloud, the Pilae control plane and console, the Pilae Agent, the private network and the monitoring, whether they run in Pilae Cloud, on the customer’s premises or in a hybrid or air-gapped setup.

2.2 On the customer’s premises, the customer’s own policies also apply to its machines. This AUP covers what the customer does with the services Pilae provides there.

3. Unlawful use

The customer must not use the services to:

3.1 Break Swiss law, or the law that applies to the customer or to the place where the service runs.

3.2 Store, process or share child sexual abuse material. Pilae reports such material to the competent authorities.

3.3 Infringe the intellectual property, privacy or personality rights of others.

3.4 Process personal data without a lawful basis under the Swiss Federal Act on Data Protection, the GDPR or other data protection law that applies.

3.5 Defraud, deceive or impersonate others, including through phishing pages.

3.6 Breach sanctions or export control rules, or provide the services to a person those rules prohibit.

4. Security and network abuse

The customer must not use the services to:

4.1 Gain or attempt unauthorised access to any system, account or data, including Pilae’s systems and those of other customers.

4.2 Distribute malware, or operate botnets or command-and-control servers.

4.3 Run denial-of-service attacks, or traffic floods against any target.

4.4 Scan, probe or test systems the customer does not own or is not authorised to test.

4.5 Operate open relays, open proxies or open resolvers.

4.6 Bypass, disable or interfere with the private network, the gate, the monitoring, the backups or the audit log that Pilae operates.

5. Email and messaging

5.1 The customer must not send unsolicited bulk messages, or messages that breach the Swiss Federal Act against Unfair Competition or similar law elsewhere.

5.2 The customer must not forge message headers or send from domains it has no right to use.

5.3 Apps that send email must do so with a valid sender domain and a working unsubscribe mechanism where the law requires one.

6. Resource use in Pilae Cloud

6.1 The customer must not use Pilae Cloud machines for cryptocurrency mining unless the contract allows it.

6.2 The customer must not run load or stress tests against Pilae’s shared components, such as the gate or the control plane, without agreeing a test window with Pilae first.

6.3 Use must stay within the resources in the contract. Pilae contacts the customer before any change is needed and does not throttle without notice, except in an emergency under section 10.

7. AI services

7.1 Where the customer runs AI models or assistants with Pilae, it remains responsible for the prompts, the documents it connects and the use of the answers.

7.2 The customer must not use AI services to create content that is unlawful under section 3, or to make decisions about people that the law prohibits or restricts, without the safeguards the law requires.

7.3 Where the customer enables an external model provider, it must also respect that provider’s usage terms.

8. App licences

8.1 The apps Pilae operates are open source or source-available. Each is used under its own licence.

8.2 The customer must respect the terms of those licences. Some carry conditions, for example on branding above a number of users or on offering the app as a service to third parties. Each app’s page names its licence and the conditions Pilae knows of. See the app catalogue.

9. Security testing and vulnerability reports

9.1 The customer may test the security of its own apps. It tells Pilae in advance at security@pilae.com, with the scope, the dates and the source addresses, so the tests are not treated as an attack.

9.2 Tests must not target Pilae’s shared components or other customers.

9.3 Anyone who finds a vulnerability in a Pilae service can report it to security@pilae.com. See responsible disclosure.

10. Enforcement

10.1 Pilae does not read customer content as a matter of routine. It acts on a report, an alert from its monitoring, or a request from an authority.

10.2 When Pilae believes this AUP has been breached, it tells the customer, explains what it found and gives a reasonable time to fix it.

10.3 Pilae may suspend the affected app or machine without prior notice only where this is needed to prevent serious harm to Pilae, its other customers or third parties, or where the law requires it. Pilae limits the suspension to what is needed, tells the customer at once and restores the service when the cause is removed.

10.4 Repeated or serious breaches may lead to termination of the contract under its terms.

10.5 Suspension under this AUP is excluded from the availability commitment in the service level agreement.

11. Reporting abuse

11.1 To report abuse of a Pilae service, write to security@pilae.com with the addresses, times and evidence you have.

11.2 For questions about this policy, write to hello@pilae.com.

12. Changes to this policy

Pilae may update this AUP to reflect changes in law or in the services. It announces material changes to customers in advance.

13. Governing law and jurisdiction

This AUP is governed by Swiss law. The place of jurisdiction is Lausanne, Switzerland, subject to any mandatory place of jurisdiction.

Tell us what you need to run.

Thirty minutes with an engineer, a written plan and a fixed price for the first workload.