Acceptable Use Policy
Current as of July 28, 2026
This Acceptable Use Policy governs use of CORE infrastructure, communications, AI, remote-assistance, and platform services.
1. Overview
This AUP applies to CORE-managed hosting, compute, databases, storage, communications, domains, portals, AI, automation, remote assistance, and applications. It is incorporated into an accepted order or Terms of Service and also states the security and abuse restrictions that apply to visitors and authorized users.
CORE reserves the right to amend this AUP at any time with notice. Serious violations may result in immediate service suspension without notice.
2. Prohibited Content
You may not use CORE services to host, store, transmit, or distribute any content that: (a) is unlawful under applicable federal, state, or local law; (b) infringes any third-party intellectual property rights; (c) constitutes child sexual abuse material (CSAM) or any content that exploits or harms minors; (d) constitutes defamation, fraud, or deceptive trade practices; (e) promotes or facilitates illegal drug sales, weapons trafficking, or human trafficking; (f) violates export control laws or economic sanctions.
CORE has zero tolerance for content that sexually exploits or endangers children. CORE may immediately restrict access, preserve evidence, investigate, and report apparent child sexual abuse material or another reportable offense to NCMEC or law enforcement as required or permitted by law. Response actions are designed to avoid unnecessary viewing, copying, or interference with an investigation.
3. Prohibited Activities
You may not use CORE services to: run or facilitate denial-of-service (DoS/DDoS) attacks against any network or system; attempt unauthorized access to any computer system, network, or data; distribute malware, ransomware, spyware, adware, or other malicious code; conduct phishing, social engineering, or credential-harvesting operations; mine cryptocurrency without CORE's explicit written authorization; operate a proxy, VPN, or relay service for the purpose of obscuring abusive activity; scrape content from third-party websites without authorization; or engage in any activity that violates applicable computer fraud and abuse laws.
You may not use CORE domain registration, transfer, DNS, or broker services for cybersquatting, typosquatting, trademark infringement, impersonation, phishing, malware distribution, unlawful resale schemes, bad-faith acquisition attempts, harassment of domain owners, or activity prohibited by the configured registry, registrar, escrow, marketplace, ICANN, or equivalent governing policy.
4. Infrastructure & Network Abuse
You may not use CORE-hosted resources in ways that abuse or degrade shared infrastructure. Prohibited network behaviors include: generating excessive traffic that consumes disproportionate bandwidth or compute resources; port scanning or network reconnaissance not authorized by the network owner; IP spoofing; intentionally causing packet floods; or any activity that disrupts CORE services for other customers.
CORE may rate-limit, throttle, isolate, or suspend affected resources when usage indicates abuse or threatens shared availability. An overage charge or capacity upgrade applies only when the accepted order or published plan discloses it and the required usage notice, approval, or billing-change process has occurred.
5. Email & Messaging Restrictions
Email services provided by CORE (hosted mailboxes, transactional email, domain-based routing) must not be used to send unsolicited bulk email (spam) as defined by the CAN-SPAM Act or applicable law. All commercial email must include an unsubscribe mechanism, a physical mailing address, and accurate sender identification.
You may not use CORE email infrastructure to send email to harvested or purchased address lists, to conduct phishing campaigns, to impersonate other individuals or businesses, or to send messages that violate any recipient's opt-out request. Excessive bounce rates, spam complaints, or blacklistings caused by your email activity may result in immediate email service suspension.
6. Security Requirements
You are responsible for credentials, users, content, code, integrations, and configuration under your control, including using available multifactor authentication and following supplied security instructions. CORE remains responsible for the safeguards, patches, access boundaries, and managed operations assigned to it by the accepted order; neither party transfers its own legal or contractual security duty through this AUP.
If you discover a security vulnerability in CORE systems or infrastructure, report it responsibly to legal@coretv.co before public disclosure. CORE will acknowledge and triage the report through its security process. Good-faith research that follows a written authorized scope will not be treated as a violation of this AUP.
7. GitHub Usage & Source Control Policy
When source control is included, CORE uses the private or shared repository provider and organization identified for the project. A provider name, CI/CD product, issue tracker, visibility setting, or transfer method is configuration-dependent and is guaranteed only when the accepted order states it. Provider terms and acceptable-use rules also apply to the account that uses that provider.
A person invited to a repository, issue tracker, preview, or deployment system may access only the assigned project and must protect credentials, confidential material, and tenant boundaries. The person must not expand visibility, invite another user, export code, or connect an integration without authority.
Client collaboration may require a provider account. CORE will disclose the required account, license, permissions, and any client-controlled provider terms before access is enabled.
Prohibited repository activities: You may not use a CORE-managed or client-accessible repository to store or distribute malware; evade a license; introduce a deliberate vulnerability; commit exposed credentials, secrets, or keys; or distribute material without authorization. CORE may immediately revoke the affected repository token or access where needed to contain risk; broader account action follows the severity-based process below.
Build and deployment automation is subject to the configured provider's limits and the project's approved workflow. A user may not trigger abusive jobs, bypass required reviews, expose secrets, alter protected branches, or deploy outside the permission granted to that user.
A repository or source handoff is available only when the order, ownership terms, and payment status provide for it. CORE uses reasonable efforts to begin the supported transfer after authority, security, account, licensing, and provider conditions are satisfied. The handoff record identifies exclusions and status; a provider-controlled transfer time is not guaranteed.
8. AI Manipulation, Prompt Injection & Jailbreaking
CORE deploys artificial intelligence systems including AI agents, chatbots, voice agents, and other automated assistants as part of its services. You may not attempt to jailbreak, prompt-inject, or otherwise manipulate any CORE AI system in order to bypass, disable, or circumvent its safety filters, content moderation, usage restrictions, or guardrails, or to cause it to behave in a manner inconsistent with its intended purpose.
You may not attempt to access, reveal, reproduce, or reverse-engineer the underlying system prompts, instructions, configuration, or proprietary logic governing any CORE AI system, nor may you attempt to extract proprietary instructions, training data, model weights, or other confidential materials. Any technique designed to coerce an AI system into disclosing such materials, including adversarial inputs, role-play exploits, encoding tricks, or indirect injection through uploaded content, is prohibited.
You may not use any CORE AI system in an attempt to expose, exfiltrate, or harvest API keys, secrets, tokens, credentials, internal endpoints, customer data, or any other sensitive information belonging to CORE, its clients, or third parties. Probing an AI system for security weaknesses outside of CORE's responsible disclosure process described in this AUP is prohibited.
CORE may log, challenge, rate-limit, isolate, or suspend the affected AI access when manipulation or abuse is detected. Repeated, intentional, illegal, or materially harmful activity may support termination and available remedies after considering severity and evidence. Good-faith authorized security research remains governed by the responsible-disclosure scope.
9. Regulated & Professional Advice
You may not use CORE systems, infrastructure, or AI services to provide, generate, or distribute regulated professional advice — including medical, legal, financial, investment, tax, accounting, insurance, or similar regulated guidance — unless you hold all licenses, registrations, and credentials required under applicable federal, state, and local law to provide such advice in each jurisdiction in which it is offered.
Where you are permitted to offer regulated advice, you must provide all legally required disclaimers, disclosures, consents, and notices, and must clearly identify the limitations of any automated or AI-generated output. CORE AI systems and infrastructure are tools and do not constitute a licensed professional; output must not be presented to end users as a substitute for advice from a qualified, licensed professional.
You are responsible for ensuring a regulated, professional, or licensed use is expressly scoped and complies with applicable law and professional standards. CORE does not represent that a general-purpose service is suitable for a regulated use. Questions regarding a proposed scope may be directed to legal@coretv.co.
10. Consequences of Violation
CORE selects a proportionate response based on severity, immediacy, recurrence, affected people, security risk, provider requirements, and available evidence. Responses may include a warning, remediation deadline, quarantine, rate limit, content restriction, credential or integration revocation, suspension, or termination. An urgent illegal-content, malware, credential-theft, active-attack, child-safety, or provider-suspension risk may require action before notice.
Refunds and credits after a restriction follow the accepted order, Refund Policy, causation, consumed usage, committed vendor costs, and applicable law. CORE may seek documented remediation or provider costs caused by a proven violation only where the agreement and law permit. A good-faith security report within an authorized scope is not treated as abuse.
11. Reporting Violations
If you become aware of a violation of this AUP on CORE infrastructure — including illegal content, abuse, or network attacks originating from CORE-hosted systems — report it to legal@coretv.co with available timestamps, affected routes or accounts, and evidence that can be shared lawfully. CORE triages reports according to severity.
12. Updates to This Policy
This AUP may be updated as CORE's services, threats, and legal requirements evolve. CORE provides the advance notice required by the controlling agreement or applicable law for a material non-urgent change. A narrowly tailored security, abuse-prevention, provider, or legal-compliance restriction may take effect sooner when delay would create unreasonable risk.
13. Communications, consent & identity abuse
You may not use CORE calling, AI voice, SMS, email, campaign, or follow-up tools to contact a person without the permission or other lawful basis required for that message. Prohibited conduct includes spoofing or disguising identity, purchased or harvested lists, ignoring opt-outs or quiet hours, evading A2P or carrier registration, unlawful artificial-voice calls, undisclosed recording, harassment, discriminatory targeting, and sending content that violates a carrier or delivery provider policy.
You must maintain evidence of consent and suppression, use accurate sender and caller identification, provide required automated-system and recording notices, and promptly honor STOP, unsubscribe, do-not-call, or equivalent requests. CORE may pause or block a campaign, number, template, sender, domain, or workflow while consent or registration is reviewed.
14. Remote-assist & co-browsing abuse
You may not start, continue, or simulate a remote-assist session without the visitor's current permission; exceed the approved page, mode, field, or expiration; conceal a command; capture secrets; submit a signature, legal acceptance, approval, or payment for another person; or use remote assistance to bypass access controls. A revoked or expired grant must be honored immediately.
Remote-assist events and commands may be audited. CORE may terminate a session and suspend the responsible account when a command is unsafe, deceptive, outside scope, or inconsistent with the participant's permission.
15. Automation & AI safety
You may not configure an AI agent or automation to make unlawful, deceptive, discriminatory, unsafe, or unauthorized decisions; impersonate a licensed professional or real person; conceal that a legally required automated-system disclosure applies; fabricate evidence; manipulate reviews; or provide emergency services. High-impact or regulated uses require a separately approved scope, lawful basis, qualified human review, and any impact assessment required by law.
Attempts to reveal system instructions, extract another user's data, poison a knowledge base, inject hidden commands, evade an approval gate, bypass model or usage limits, or use generated output to facilitate malware, fraud, credential theft, or exploitation are prohibited.
You may not submit a file, URL, recording, credential, contact list, competitor material, or other source that you lack authority to process; use an intake or retrieval feature to copy protected content unlawfully; or place a password, authentication code, private key, payment-card number, or unnecessary sensitive data in a general AI prompt, intake upload, comment, or knowledge source. Use the designated secret or delegated-access workflow when a scoped service requires credentials.
16. Platform security & rate-limit evasion
You may not probe, scan, scrape, stress, reverse engineer, or test CORE systems outside a written authorization, published API or robots rule, ordinary accessibility-tool use, or other activity that applicable law expressly protects; bypass a permission or tenant boundary; enumerate accounts; upload malicious files; rotate devices, IP addresses, phone numbers, accounts, or domains to evade a limit or block; or interfere with audit, logging, suppression, safety, or monitoring controls.
You may not use a disposable, temporary, deceptive, or repeatedly rotated email address or domain to evade an intake limit, impersonate another person, avoid a suppression record, multiply a promotion or referral, conceal abusive activity, or defeat account or request review. CORE may reject a public submission under an administrator-managed IP, network, or email-domain rule and may preserve protected evidence needed to investigate circumvention. A good-faith user may report an apparent false positive through the published support channel.
CORE may quarantine uploads, rate-limit or block a request or session, revoke tokens, and preserve relevant evidence. Authorized security research must follow the written scope and reporting channel supplied by CORE.
Download this document
Save a PDF copy for your records.