openFactoryAI
How it worksThe catchThe boardFAQToolsBlogSign inGet a seat
How it worksThe catchThe boardFAQToolsBlogSign inGet a seat
Legal

Acceptable Use Policy

Last updated 2026-08-03

Acceptable Use Policy

Effective date: 2026-08-03

This Acceptable Use Policy ("AUP") is part of the Terms of Service and applies to everyone who uses openFactory or any OpenFactoryAI service. It applies to you, to anyone on a seat you pay for, and to any agent you operate through the Service — an agent acting on your instruction is you, for the purposes of this policy.

1. Prohibited content

Do not use the Service to generate, store, or distribute:

  • Child sexual abuse material (CSAM) or any content that sexualises a minor.
  • Content that facilitates human trafficking, exploitation, or non-consensual sexual activity.
  • Malware, ransomware, spyware, rootkits, botnets, or code whose primary purpose is to gain unauthorised access to, damage, or disrupt a system.
  • Content that incites or facilitates violence, terrorism, or genocide, or that provides operational instructions for weapons capable of mass casualties.
  • Targeted harassment, threats, doxxing, or content designed to degrade a person or protected group.
  • Deliberately deceptive impersonation or synthetic media created to defraud.

2. Prohibited use cases

Do not use the Service to:

  • Break into systems you do not own or have written authorisation to test — that includes port scanning, credential stuffing, exploitation, and lateral movement against third-party infrastructure.
  • Exfiltrate, launder, or resell data obtained without authorisation, including scraped personal data and breach dumps.
  • Build tools for mass surveillance, biometric identification of individuals without consent, or social scoring.
  • Operate spam, phishing, or fraud infrastructure of any kind.
  • Circumvent licensing, DRM, or paywalls, or strip attribution from open-source code in violation of its licence.
  • Provide unlicensed regulated advice — medical, legal, or financial — presented as coming from a qualified professional.
  • Violate any applicable law, sanctions regime, or export-control rule.

Security testing against your own systems, and against third-party systems you are contractually authorised to test, is permitted. See §6.

3. Platform abuse

Do not:

  • Share, resell, sublicense, or rotate a seat among multiple people, or use one seat concurrently from multiple people.
  • Create multiple accounts to evade limits, suspensions, pricing, or promotional credit.
  • Circumvent rate limits, quotas, or metering, or misrepresent usage.
  • Resell access to Kalmantic-operated inference as a competing service.
  • Probe, scan, or load-test our hosted infrastructure without written permission.
  • Reverse engineer openFactory except to the extent that right cannot lawfully be restricted — see §2 of the EULA.
  • Use the Service to build a substantially similar competing product.

4. Your obligation to verify output

openFactory produces evidence about generated software. Evidence is not a warranty. You must review, test, and take responsibility for anything you ship. Specifically, you are responsible for:

  • Reviewing generated code for correctness and security before deployment.
  • Checking the licence compatibility of any dependency or code an agent introduces.
  • Ensuring output complies with the regulations of your industry and jurisdiction.
  • Not representing generated output as human-authored where disclosure is legally or contractually required.

Shipping harmful software you generated with openFactory is a breach of this policy, not just a bad outcome.

5. Geographic restrictions

You may not use the Service if you are located in, ordinarily resident in, or acting on behalf of a person in a country or region subject to comprehensive US sanctions, or if you appear on a US restricted-party list (including OFAC's SDN list). You may not export or re-export the Service in violation of US export-control law.

6. Security research

We welcome good-faith security research. If you follow the rules below, we will not pursue legal action and we will work with you:

  • Test only against your own account and your own data.
  • Do not access, modify, or delete another user's data; stop as soon as you have proof of a vulnerability.
  • Do not degrade the Service — no denial of service, no automated high-volume testing, no spam.
  • Report to security@kalmantic.com with reproduction steps and give us 90 days before public disclosure, or less if we agree.
  • Do not extort. A report conditioned on payment is not research.

7. Enforcement

We investigate reports and use the least severe action that resolves the problem. Depending on severity and history that may be: a warning, a rate limit, removal of specific content, suspension of an account or seat, or termination.

For a severe violation — CSAM, credible threats to life, active attacks on infrastructure, or fraud — we act immediately and without prior notice, and we report to law enforcement where the law requires or the harm warrants it.

No refund is due on suspension or termination for a breach of this policy. See the Refund Policy.

Appeals. If you believe an enforcement action was wrong, email legal@kalmantic.com. A person reviews every appeal.

8. Reporting a violation

Report abuse to abuse@kalmantic.com with as much detail as you can safely provide.

Reports of suspected CSAM are reviewed within 4 hours and, where confirmed, are reported to the National Center for Missing & Exploited Children (NCMEC) and preserved as required by law.

9. Changes to this policy

We may update this policy as the threat landscape and the product change. The date at the top of this page changes with any update. Material changes are notified as described in §16 of the Terms of Service.

Kalmantic Inc. operates OpenFactoryAI and openFactory. This policy was last updated on 2026-08-03.

Other legal pages:Terms of ServicePrivacy PolicyCookie PolicyEnd User License AgreementRefund PolicyData Processing Addendum
openFactoryAI
The local-first workspace for agent-built software. One outcome, visible ownership, human authority, and evidence behind the result.
Product
How it worksThe catchPricingFor your roleTokenTopper
Trust
The boardThe ledgerAcademy ↗Blog
Engage
Get a seatSign inTalk to the teamLegalhello@openfactoryai.coGitHub ↗
Terms of ServicePrivacy PolicyCookie PolicyAcceptable UseEULADPARefund Policy
Coding agents, coordinated.© 2026 Kalmantic Inc. All rights reserved.