Legal
Acceptable Use Policy
Last updated: August 11, 2026
This Acceptable Use Policy (the "Policy") describes prohibited uses of Rye's websites, CLI tools, APIs, dashboards, documentation, and related services. The examples below are not exhaustive. If you violate this Policy or authorize others to do so, Rye may suspend or terminate your access to the Service.
No illegal, harmful, deceptive, or offensive use
You may not use, encourage, promote, facilitate, or instruct others to use the Service for illegal, harmful, fraudulent, infringing, deceptive, abusive, or offensive activity.
- Illegal or fraudulent activity. Identity fraud, stolen credentials, unauthorized system access, sanctions evasion, phishing, money laundering, or other unlawful activity.
- Infringing activity. Content or activity that infringes or misappropriates intellectual property, publicity, privacy, or proprietary rights.
- Deceptive configuration. Misrepresenting workspace identity, device identity, policy scope, audit records, or Rye's role or capabilities to end users, regulators, or other parties.
- Offensive or abusive content. Content that is defamatory, obscene, abusive, exploitative, invasive of privacy, or otherwise objectionable.
- Harmful code or systems activity. Malware, spyware, credential theft, exfiltration, botnet activity, or code that damages, interferes with, intercepts, or expropriates any system, program, or data.
No circumvention of security controls
You may not use the Service to bypass, defeat, or undermine security supervision, policy enforcement, or audit controls — whether Rye's own or those of third-party systems your agents interact with.
- Policy bypass. Configuring agents, prompts, or integrations to route model traffic around the Rye proxy in order to evade policy evaluation or audit recording.
- Audit tampering. Altering, suppressing, or falsifying audit trail records, policy decision logs, or device identity metadata.
- Agent misuse. Deploying AI agents configured to exfiltrate credentials, access unauthorized resources, or manipulate other users or systems without authorization.
- Prompt injection attacks. Crafting inputs intended to hijack supervised agents into ignoring policy controls, leaking secrets, or taking unauthorized actions.
No security violations
You may not use the Service to violate the security or integrity of any network, computer, communication system, software application, API, account, or device.
- Unauthorized access. Accessing or attempting to access systems, accounts, credentials, APIs, or data without permission.
- Security testing without authorization. Probing, scanning, fuzzing, load testing, or vulnerability testing the Service or third-party systems without prior written permission.
- Interception. Monitoring, scraping, or capturing data or traffic without authorization.
- Falsification of origin. Forging headers, request metadata, proxy signatures, device identifiers, or workspace identities.
No network or platform abuse
- Denial-of-service attacks, flooding, or intentional interference with any system.
- Using manual or automated means to bypass rate limits, access controls, policy restrictions, or quota systems.
- Operating open proxies, open relays, credential stuffing tools, or abusive automation through the Service.
- Crawling, scraping, or monitoring systems in a way that violates terms, impairs performance, or disrupts operations.
No email or message abuse
You may not distribute, publish, send, or facilitate unsolicited mass email, messages, promotions, advertising, or solicitations through the Service. You may not alter or obscure message headers, assume another sender's identity, or collect replies from messages that violate this Policy.
Responsible AI agent deployment
- You must clearly disclose to end users when AI coding agents are operating on their behalf and what data those agents may access.
- You must obtain appropriate authorization before deploying agents that access credentials, sensitive source code, production systems, or personal data.
- You must not design agents or prompts intended to trick users into granting excessive permissions or concealing agent actions from oversight.
- You must promptly respond to trust and safety, security, compliance, and support requests from Rye.
Monitoring and enforcement
Rye may investigate suspected violations of this Policy or misuse of the Service. We may remove, disable, throttle, suspend, or modify access to content, integrations, API keys, accounts, or resources that violate this Policy or create risk.
We may report activity that we suspect violates law or regulation to law enforcement, regulators, or other appropriate third parties. Reports may include relevant customer, account, device, or network information.
Reporting violations
If you become aware of a violation of this Policy, notify Rye promptly and provide reasonable assistance to stop or remedy the violation. Reports may be sent to support@rye.com. Security vulnerabilities in the Rye platform should be reported to security@rye.com.