Acceptable Use Policy
Last updated 2026
This policy forms part of the Terms of Service and applies to everyone who uses a kitset.io workspace. It is short on purpose.
1. Do not store secrets in Systems & Access
This is the rule people most often get wrong, so it comes first. The Systems & Access module records which business systems exist, who owns them and who should be able to reach them. It is an ownership register, not a password manager, and it is not built to be one.
Do not store passwords, recovery codes, API keys, private keys, connection strings or session tokens in any kitset.io field, note or attachment. Use a purpose-built secret manager. We may remove such content when we become aware of it.
2. Do not put data in that you have no right to hold
You must have a lawful basis for the personal data you place in a workspace, and you must tell the people it concerns. Do not upload special-category data — health, biometric, racial or ethnic origin, political opinions, religion, trade union membership, sex life or sexual orientation — or payment card numbers, government identity numbers, or data subject to sector-specific regimes such as HIPAA-covered health information, unless we have agreed it in writing beforehand.
3. Do not misuse the platform
- No unlawful, defamatory, harassing or infringing content.
- No malware, and no content designed to compromise a system.
- No attempt to access another workspace's data, to bypass authorization, to probe the infrastructure, or to run denial-of-service traffic. Security research is welcome; do it in your own trial workspace and read the disclosure section first.
- No reselling or providing the service to a third party as though it were your own, unless we have agreed it in writing.
- No scraping or automated bulk extraction beyond the export features the product provides.
4. Do not misuse email
kitset.io sends transactional mail — invitations, reminders, notifications — from shared infrastructure, so one workspace's behaviour affects everyone's deliverability. Do not use it for marketing, bulk mail or anything the recipient has not asked for by being part of your organisation. Do not send to addresses you have no relationship with.
Where an address hard-bounces or files a spam complaint, delivery to it stops across the whole platform. That is not a punishment; it is how sending reputation is protected.
5. Respect the capacity you bought
Do not share one Console account among several people to avoid buying seats, and do not circumvent capacity limits. Automated use of the API is fine and expected; use that is disproportionate enough to affect other customers is not, and we will contact you before taking any action.
6. What happens if this is breached
We will normally contact the workspace Owner and give a reasonable chance to fix it. Where the breach is serious, unlawful, or actively threatens the platform or other customers, we may suspend access immediately and explain afterwards.
7. Reporting abuse
Write to [email protected]. For a security vulnerability, use [email protected] instead.