- Effective date
- Last updated
This Acceptable Use Policy (AUP) protects Riskscape, our customers, data subjects, data partners, and the reliability of the Services. It applies to every user, API request, integration, upload, download, query, and use of Riskscape data or output. It forms part of the Terms of Service.
1. Lawful and authorised use
You may use the Services only for lawful, authorised purposes within your plan, order, documentation, and data licence. You must obtain all notices, consents, licences, permissions, and lawful grounds required for Customer Data and your use of output.
You may not use the Services to violate POPIA, consumer-protection, credit, insurance, intellectual-property, privacy, anti-discrimination, cybersecurity, sanctions, export-control, or other applicable laws or third-party rights.
2. Restricted data
Do not submit or expose through the Services:
- full payment-card details, CVVs, bank credentials, EFT PINs, one-time passwords, or private cryptographic keys;
- passwords or live authentication credentials for another service;
- health, biometric, precise active-tracking, children's, or other special or highly sensitive personal information;
- government identifiers combined with information that creates a material identity-theft or privacy risk; or
- unlawfully obtained, confidential, or proprietary data.
This restriction does not apply where a particular Service and written agreement expressly authorise the data type and appropriate security, lawful-processing, and data-handling requirements are in place. If restricted data is submitted accidentally, stop processing, secure the exposure, and notify info@riskscape.pro immediately.
3. Prohibited conduct
You must not:
- introduce malware, ransomware, malicious code, destructive content, or hidden access mechanisms;
- probe, scan, test, exploit, or bypass security or authentication without our prior written authorisation;
- access another customer's account, data, keys, or systems;
- intercept traffic, forge requests, impersonate another person, or misrepresent authority;
- share credentials outside authorised users or publish API keys in client-side code or public repositories;
- evade quotas, rate limits, usage meters, billing, access controls, or plan restrictions;
- overload, disrupt, degrade, or interfere with the Services or another user's use;
- scrape or extract data outside documented APIs and download functions;
- reverse engineer, decompile, discover, copy, or reconstruct non-public source code, models, scoring logic, datasets, or security mechanisms, except to the limited extent law does not permit restriction;
- re-identify, or attempt to re-identify, a person from aggregated, anonymised, pseudonymised, or de-identified information;
- combine output with other data in a way that creates an unlawful or disproportionate surveillance or profiling capability;
- resell, sublicense, redistribute, publish, or build a competing database, API, model, or service from Riskscape data unless a written licence permits it;
- use the Services to send spam, phishing, deceptive communications, or unsolicited direct marketing;
- use the Services to facilitate fraud, identity theft, stalking, harassment, discrimination, property crime, environmental harm, or physical harm; or
- conceal a breach or give false information during a security, billing, or compliance investigation.
4. High-impact decisions
Riskscape output may assist decisions concerning property, lending, insurance, infrastructure, environment, and other significant matters. You must not use output as the sole basis for a decision that has legal or similarly significant effects on a person where law or fairness requires additional safeguards.
You are responsible for:
- assessing whether the data is relevant, current, sufficiently accurate, and suitable for the use;
- testing for inappropriate bias, proxy discrimination, and disparate impact;
- using qualified human review and additional evidence where appropriate;
- giving notices, reasons, access, correction, objection, or appeal rights where required; and
- avoiding use for a prohibited or unfair discriminatory purpose.
5. API and platform integrity
Use documented authentication and supported integration methods. Respect rate limits, concurrency controls, pagination, caching rules, retry guidance, and reasonable-use limits.
Your integration should use secure secret storage, least-privilege access, encrypted transport, safe logging, input validation, timeouts, bounded retries, and monitoring. Do not log or expose API keys, restricted Customer Data, or complete sensitive responses unnecessarily.
If your use creates unusual load or risk, we may require a technical remediation plan, reduce limits temporarily, or move you to an appropriate capacity plan.
6. Data ownership and permitted sharing
Do not remove copyright, licence, source, confidence, date, or attribution notices. Preserve material limitations when sharing permitted conclusions or derived output.
You may share output only as allowed by your plan or order. Internal use does not authorise making raw data, bulk extracts, credentials, or a substitute data service available to affiliates, clients, contractors, or the public.
7. Security incidents and vulnerability reporting
Promptly report suspected credential exposure, unauthorised access, data leakage, or a vulnerability affecting Riskscape to info@riskscape.pro. Provide enough detail to investigate and avoid public disclosure until we have had a reasonable opportunity to address the issue.
Good-faith security research requires prior written authorisation defining scope, methods, timing, data handling, and disclosure. This AUP does not itself grant testing permission.
8. Enforcement
We may investigate suspected violations and preserve relevant evidence. We may rate-limit, block a request, remove content, rotate credentials, restrict a feature, suspend access, or terminate the affected Service where reasonably necessary.
Where practicable, we will notify you and allow a reasonable opportunity to remedy the violation. We may act immediately where delay could cause harm, compromise security, violate law or third-party rights, or threaten the Services. We may report unlawful conduct to affected parties or authorities where required or permitted by law.
You remain responsible for charges incurred before enforcement and for reasonable costs or losses recoverable under the Terms and applicable law.
9. Contact
Questions, permission requests, and incident reports: info@riskscape.pro
Riskscape (Pty) Ltd
Unit A-1002A, First Floor, Corobay, corner Aramist and Corobay Avenue, Menlyn, Pretoria, Gauteng, 0181, South Africa