Axiom Acceptable Use Policy
Effective: October 1, 2026 · Provided by Iterix Systems, LLC · Version 1.0
1. Introduction and Scope
Iterix Systems, LLC ("Iterix", "we", "us") provides Axiom, the keep-or-drop platform for AI Roles, including the website at myaxiom.world and related software and services (the "Services"). This Acceptable Use Policy ("AUP") governs use of the Services by every Customer and Authorized User ("you"). It is incorporated by reference into the Axiom Terms of Service (the "Terms"). Capitalized terms not defined here have the meanings given in the Terms. The current version is available at the URL for this page and through the "Acceptable Use" link in the Services.
Axiom runs AI Roles that work toward goals you set, inside a budget ceiling you set, and routes consequential actions to you for approval before they proceed. Because Roles act on your behalf, the obligations in this AUP are a material condition of access.
This AUP applies to all Workspaces and every user of a Workspace; all data, documents, keys and settings submitted to the Services; and any AI Model key you connect.
2. Goals, Charters and Approvals
2.1 Permitted Use
You may set goals, charters and budgets and direct Roles for lawful business purposes consistent with your plan and applicable law.
2.2 Prohibited Conduct
You must not:
- Circumvent approvals. Suppress, bypass, disable or route around an approval the Services require, through any means, including API manipulation or misuse of settings.
- Direct unlawful decisions. Set goals, charters or instructions designed to make decisions that violate applicable law, including employment, consumer-protection, anti-discrimination or financial regulation.
- Defeat platform controls. Configure charters, budgets or instructions with the intent of defeating the Services' spending, approval or scope controls.
- Misrepresent Work Product. Present Work Product as a verified or authoritative determination without appropriate human review, particularly in regulated domains.
2.3 Verification Integrity
The Services count work only once a separate checker has passed it. You must not attempt to cause work to be counted as verified without that check, or to interfere with the check, including through account sharing, credential substitution or API misuse. Any such attempt is a material breach of this AUP and the Terms.
3. Workspace Isolation
3.1 Workspace Boundary Respect
Each Workspace operates in an isolated environment. You must not:
- Attempt to access, read, infer, enumerate or exfiltrate data belonging to any other Workspace.
- Submit queries, API requests or other inputs designed to probe, test or defeat row-level security or any other isolation mechanism.
- Share API keys, credentials or session tokens across Workspaces.
- Provision users in a manner designed to blur Workspace boundaries.
3.2 Reporting Obligations
If you discover or suspect a breach of Workspace isolation — whether caused by a defect in the Services or by another party — you must notify Iterix immediately at [email protected] and must not exploit or investigate it beyond what is necessary to identify the issue.
4. AI Usage
4.1 Prompt Injection Prohibition
You must not submit inputs — through the Services' interface, the API, your onboarding brief, knowledge you add, goals or instructions — that are designed to:
- Manipulate the behavior of Roles or of the Services' AI components.
- Extract, replicate or reverse-engineer system prompts or model configurations.
- Override, ignore or subvert instructions embedded in the Services' AI components.
4.2 Downstream Use of Work Product
Work Product may contain errors, omissions or fabrications. You are solely responsible for implementing appropriate human review where Work Product informs a consequential decision; for not presenting AI-generated content as factually verified without independent confirmation; and for complying with any law governing automated decision-making that applies to your business.
4.3 Model Output Restrictions
You must not use Work Product generated through an AI Model provided by Iterix to train, fine-tune, distill or benchmark competing models or AI systems. This restriction reflects Iterix's obligations under its agreements with AI model providers.
4.4 Spend and Routing Integrity
You must not craft inputs designed to evade budget ceilings or spending controls, or to route actions around the approval the Services would otherwise require.
5. Record Integrity
5.1 Non-Tampering Obligation
The Services keep a record of the actions Roles take, the approvals given and the amounts spent in your Workspace. You must not attempt to modify, suppress, delete or obscure entries in that record other than through features the Services provide, submit data or direct Roles with the intent of generating a misleading record, or use the API in ways designed to cause gaps in it.
5.2 Record Acknowledgment
You acknowledge that the record is the Services' account of activity in your Workspace and that it may be disclosed in the context of regulatory investigations, legal proceedings or compliance audits, subject to applicable confidentiality obligations.
5.3 Legal Hold Notification
If you become subject to a legal hold, regulatory investigation or litigation that implicates data in your Workspace, you must notify Iterix promptly and must not take any action that would compromise the integrity or availability of the relevant record.
6. AI Model Keys
6.1 Key Submission
If you connect your own AI Model key, you are solely responsible for it. You must submit only a key you are authorized to use for this purpose, must rotate it promptly if you suspect compromise, and must notify Iterix if you do. You must not submit a key belonging to a third party without authorization.
6.2 Third-Party Terms Compliance
You are responsible for ensuring your use of your own AI Model key complies with that provider's terms of service. Iterix does not accept liability for your violation of a third party's terms.
7. Knowledge and Documents
7.1 Document Rights
The Services use the onboarding brief, knowledge and documents you submit as context for Roles. By submitting them, you warrant that you hold all rights necessary to submit them for AI-assisted processing; that they do not contain third-party confidential information submitted without authorization; and that submission does not breach any non-disclosure agreement, intellectual property right or contractual obligation.
7.2 Prohibition on Adversarial Content
You must not submit documents or knowledge containing content designed to manipulate AI behavior (document-embedded prompt injection), or to produce actions that would defeat the Services' approval, spending or isolation controls.
7.3 Accuracy Obligation
You must not knowingly submit false or materially misleading goals, charters or instructions with the intent of obscuring or evading the controls they are meant to set.
8. Data Submission
8.1 Responsibility for Data
You are responsible for accurately representing the nature and sensitivity of the data you introduce into the Services, including through documents, knowledge and instructions.
8.2 Restricted Data Categories
You must not submit data categories not covered by your plan or the Data Processing Addendum, including:
- Protected health information under HIPAA.
- Payment card data subject to PCI-DSS.
- Sensitive personal information under applicable US state privacy law, except as your plan and the Data Processing Addendum expressly permit.
9. Regulatory Responsibility
9.1 Customer Regulatory Responsibility
Iterix provides the technical infrastructure for the Services. Iterix does not warrant that any goal, charter, approval or use of the Services satisfies any regulatory requirement applicable to your business. You are solely responsible for ensuring your use complies with the law and regulation of your jurisdiction and industry; for obtaining any required approvals, licenses or legal opinions before directing Roles to carry out regulated activity; and for maintaining records required by law independently of the Services.
9.2 Privacy Rights Requests
Where you act as the controller of personal data processed through the Services, you are responsible for responding to requests from individuals exercising their privacy rights with respect to that data, with Iterix's assistance as set out in the Data Processing Addendum.
9.3 Regulated Domain Use
If you use the Services in a regulated domain (for example financial services, healthcare or legal), you are responsible for conducting your own compliance assessment and must not rely on Iterix's security documentation as evidence of your own compliance.
10. Prohibited Use — General
In addition to the prohibitions above, you must not use the Services to:
- Attack the Services or their infrastructure, including denial of service, fuzzing, vulnerability scanning or any security testing without Iterix's prior written authorization.
- Reverse engineer the Services, including decompiling, scraping or otherwise extracting proprietary logic, prompt configurations or architectural details.
- Resell or sublicense access, or provide API access to third parties not provisioned through an agreement with Iterix.
- Operate the Services on behalf of entities that do not hold their own account.
- Facilitate illegal conduct, including fraud, money laundering or sanctions evasion.
- Introduce malicious content, including malware, exploits or content designed to compromise the Services or other customers.
- Obscure identity or origin, including misrepresenting your identity, spoofing credentials or obscuring the origin of requests.
11. Enforcement
11.1 Breach
Violation of this AUP is a material breach of the Terms. Iterix may suspend or terminate access immediately where a violation poses a security risk to the Services or other customers, is unlawful, or is otherwise egregious; for other violations, Iterix will give notice and a reasonable opportunity to cure under the Terms. Iterix may preserve and disclose records and associated data to law enforcement or regulators as required by law, and may pursue all available legal remedies.
11.2 Investigation Cooperation
You must cooperate reasonably with Iterix's investigation of a suspected AUP violation, including providing requested information and preserving relevant records.
11.3 Reporting
Please report suspected violations of this AUP by other customers or third parties to [email protected].
12. Miscellaneous
12.1 Amendments
Iterix may amend this AUP. You will be notified of material changes in accordance with the notice provisions of the Terms, and continued use of the Services after a change takes effect constitutes acceptance.
12.2 Relationship to the Terms
This AUP, and any dispute arising out of or in connection with it, is subject to and governed by the Terms, including their provisions on confidentiality, intellectual property, governing law, arbitration and venue, notices, assignment, entire agreement and amendment.
