LEGAL / RESPONSIBLE USE

Acceptable Use Policy

Clear authorization boundaries for Blackfrost services and model releases.Effective and last updated September 3, 2026

1. Scope and responsibility

This Policy applies to the Blackfrost website, licensed models, documentation, repository access, custom model and hosting services, The Void method used within custom model work, and systems delivered under an agreement. You are responsible for your users, contractors, deployments, prompts, tools, data, outputs, and downstream applications.

De-risked describes reduced or removed refusal behavior; it does not mean risk-free, safe by default, compliant, or unrestricted. Reduced refusal is a research characteristic, not permission. A model’s technical capability does not determine whether an activity is lawful, authorized, safe, or appropriate.

2. Prohibited use

You may not use Blackfrost services or models to:

  • Violate applicable law, regulation, court order, sanctions, export controls, or third-party rights.
  • Access, disrupt, damage, surveil, or manipulate systems, accounts, networks, devices, or data without explicit authorization.
  • Develop, deploy, or facilitate malware, credential theft, destructive payloads, indiscriminate exploitation, or unauthorized persistence.
  • Commit fraud, impersonation, extortion, harassment, stalking, doxxing, trafficking, or unlawful discrimination.
  • Generate, obtain, or distribute sexual abuse material, exploit minors, or facilitate physical harm.
  • Make unlawful high-impact decisions about employment, housing, credit, insurance, education, healthcare, legal services, or essential access without required process and oversight.
  • Defeat repository controls, share credentials, redistribute licensed weights, or conceal a material license violation.
  • Misrepresent model provenance, safety, affiliation, authorization, benchmark results, or Blackfrost endorsement.

3. Authorized cybersecurity work

Security testing is permitted only when you own the target or have explicit authorization from an authorized owner or lawful authority. Permission should identify the target, scope, dates, allowed techniques, data-handling rules, contacts, and stop conditions.

Public bug-bounty or vulnerability-disclosure rules control only within their stated scope. Access to public information, exposed infrastructure, or a reduced-refusal model does not itself create authorization.

4. Required deployment controls

Use safeguards proportionate to capability and risk, including scoped credentials, least privilege, isolation, logging, rate limits, human approval, output validation, incident response, and secure deletion. Protect licensed weights against unauthorized copying and limit model or tool access to trained, approved users.

Do not place sensitive, regulated, confidential, or personal information into a model or third-party service unless you have lawful authority and an appropriate data-protection design.

5. Enforcement and reporting

Blackfrost may investigate credible misuse, request reasonable evidence of authorization, suspend delivery or access, refuse service, terminate a license, preserve relevant records, and report activity where required or permitted by law. Enforcement will be proportionate to available facts and contractual rights.

To report suspected misuse or ask whether a planned use is allowed, begin through the contact page without including sensitive details. Security vulnerabilities should follow the responsible disclosure process.