Acceptable use.
Aorka gives you powerful capabilities over real infrastructure. Use them responsibly.
You may not.
- —Use Aorka to attack, compromise, or gain unauthorized access to systems you do not own or have authorization to manage.
- —Attempt to circumvent, disable, or bypass the safety pipeline, script scoring system, or human approval gates.
- —Share account credentials, MFA secrets, MCP tokens, or API keys with unauthorized parties.
- —Use the platform to store, transmit, or process content that violates applicable law.
- —Reverse-engineer, decompile, disassemble, or otherwise attempt to derive the source code or underlying structure of the platform, or create derivative works from it. The agent source code is plaintext and readable by design — reading it, running it, and modifying your own copy are not breaches of this. The restriction is on the server-side platform. Where applicable law gives you a right to reverse-engineer for interoperability that cannot be waived by contract, this does not purport to take it away; ask us first and we will usually just tell you.
- —Use the Service to build, train, or market a product or service that emulates or copies any core functionality of Aorka. Core functionality includes the AI composition of remediation, the safety pipeline and the scoring behind it, the shared script library, the agent execution model, the knowledge base, and the platform’s workflows and user interface. Evaluating Aorka to decide whether to buy it is expected. Evaluating it to rebuild it is not.
- —Extract, copy, or retain the script library in bulk — by scraping, automated collection, or systematic manual copying — for any purpose other than operating your own infrastructure through the Service.
- —Publish benchmarks, performance measurements, or comparative evaluations of the Service without our prior written consent. We will not withhold it unreasonably, and we will not make approval conditional on the result being favorable.
- —Resell, sublicense, or provide access to the Service to third parties without written authorization.
- —Intentionally inject prompts designed to manipulate the AI into generating harmful, deceptive, or unauthorized scripts.
- —Place secrets, credentials, or confidential information in the body of a script. Scripts are held in a shared library that other customers of the Service can retrieve — use the credential vault and script parameters instead.
Authorization to manage connected systems.
The Service allows you to connect and manage endpoints, Microsoft 365 and other cloud tenants, network devices, and other systems (collectively, “Connected Systems”), and to execute actions that may read, modify, restart, or otherwise change them. Some Connected Systems may belong to your clients, customers, or other third parties. You represent and warrant that you have obtained all authorizations, consents, and legal rights necessary to connect those systems to the Service and to permit actions to be taken on them. The Service acts as a tool operating under your direction and approval; it does not independently decide what changes to make to your or your clients' systems.
Your responsibility.
You are responsible for all activity under your account. You are responsible for reviewing and approving scripts before execution. The human approval gate is a safety mechanism, not a rubber stamp. You are responsible for the commands you approve.