Skip to content
← DefenseScore
Legal

Acceptable Use Policy

v1.0 — Effective August 8, 2026

This Acceptable Use Policy (“AUP”) governs your access to and use of the DefenseScore platform, web application, and related services (collectively, the “Service”), operated by Ellis Intelligence LLC, a Colorado limited liability company (“we”, “us”, “our”). By accessing or using the Service, you (“Customer”, “you”) agree to this AUP. This AUP is incorporated into and forms part of our Terms of Service and is governed by the Terms of Service it accompanies, including its governing-law and dispute-resolution provisions.

If you violate this AUP, we may suspend or terminate your access without prior notice or refund and may pursue any other remedy available to us.

1. Permitted Use

You may use the Service only:

  • For your own internal business purposes, or, if you operate as a service provider, for purposes of providing services to your direct end customers under your own customer relationships;
  • In compliance with all applicable laws, regulations, and the Terms of Service;
  • Within the usage limits of your subscription tier (rate limits, seats, document counts, storage caps); and
  • Subject to the additional restrictions in the DefenseScore addendum below.

2. Account and Access

2.1 Account Security. You are responsible for maintaining the confidentiality of your account credentials. You must enable multi-factor authentication where the Service offers it. You must notify us immediately at [email protected] of any unauthorized account access.

2.2 No Sharing. Each user account is for a single individual. You may not share login credentials. Each seat used must correspond to a distinct natural person identified by name and email.

2.3 Workspace Isolation. Multi-tenant data isolation is a feature of the Service. You will not attempt to access data belonging to any other tenant, account, or workspace.

3. Prohibited Content

You will not upload, transmit, store, or generate through the Service any content that:

  • Violates any applicable law, including export-control law, anti-bribery law, or law applicable to the handling of regulated data;
  • Infringes any third party’s intellectual property, privacy, publicity, or other rights;
  • Contains malware, ransomware, exploits, worms, viruses, or any other code designed to interfere with software or hardware;
  • Is unlawful, defamatory, harassing, threatening, hateful, obscene, or sexually exploitative;
  • Constitutes “sensitive personal information” in jurisdictions where the Service is not designed to process it, or constitutes regulated data (protected health information, Payment Card Industry cardholder data, classified national-security information, or Controlled Unclassified Information (“CUI”) / Federal Contract Information (“FCI”)) unless your subscription tier and a separate written agreement expressly permit such use;
  • You are not authorized to share, transmit, or process, including content covered by another party’s confidentiality obligations that you cannot lawfully share with us.

4. Prohibited Activities

You will not, and will not permit any third party to:

4.1 Service Integrity. Attempt to gain unauthorized access to any portion of the Service, including any other tenant’s data; probe, scan, or test the vulnerability of the Service except through a coordinated security-research program we publish or pre-authorize in writing; interfere with or disrupt the Service, including by overloading, flooding, or sending malformed input designed to cause failure; reverse-engineer, decompile, or attempt to extract the source code, model weights, training data, or underlying architecture of the Service; circumvent or attempt to circumvent rate limits, usage caps, billing controls, or feature gates; use the Service to build or train a competing product, including by using Service outputs to train a model offered to third parties; or scrape, harvest, or systematically extract data from the Service except through the documented API at the rates we permit.

4.2 Resale and Wrapping. Except where your subscription tier explicitly grants white-label or reseller rights: you will not resell, sublicense, lease, or wrap the Service for delivery to third parties as if it were your own; and you will not use the Service to provide services to end customers without disclosing that the Service is built on third-party infrastructure (you may disclose by reference to our brand or generically — your choice).

4.3 AI and Output Use. You acknowledge the Service uses artificial intelligence systems whose outputs may be inaccurate, incomplete, biased, or contain hallucinations. Outputs may contain errors or omissions, and we make no warranty as to the accuracy, completeness, or reliability of any output. The Service assists your work; it does not make decisions for you. You will independently verify outputs before relying on them, and before submitting them to any third party, for any decision with legal, financial, professional, or safety consequences. You will not represent any output as having been generated by a human, where representation as human is material to the recipient. You will preserve any disclaimers or attribution that the Service applies to outputs unless your subscription tier expressly grants removal rights. You will not use outputs to take any action prohibited by law, including but not limited to unauthorized practice of law, unauthorized practice of medicine, unauthorized financial advice, or unauthorized insurance brokerage.

4.4 Data Hygiene. You will not upload personally identifiable information (“PII”) of any individual without a lawful basis under applicable privacy law; data you obtained through unauthorized access, theft, or breach of any third party’s confidentiality; or children’s data (subjects under 13 in the U.S.) without verifiable parental or guardian consent and proper safeguards. You will not transmit sensitive data — including credentials, PII, or the regulated-data categories in §3 — to or from the Service over unencrypted channels. You will access the Service only through the encrypted (TLS) endpoints we provide and will not disable, downgrade, or bypass transport encryption. Our own commitments regarding encryption of data at rest and in transit are stated in the Data Processing Addendum and are not restated here.

4.5 Customer Responsibility; Indemnification. As between you and us, you are responsible for the lawfulness of the data you submit to the Service and of the instructions, configurations, and directions you give in using it, including every representation of lawful basis, authorization, or consent made in this AUP or in the DefenseScore addendum. Violations of this AUP (including those representations) that give rise to a third-party claim against us are covered by the indemnification provisions of the Terms of Service, subject to the conditions and procedures stated there; where the DPA applies, this allocation does not excuse our own compliance with our obligations under the DPA.

5. Reporting and Cooperation

5.1 Reporting Violations. Report suspected AUP violations to [email protected]. Include the relevant account or tenant identifier, a description of the issue, and any supporting evidence.

5.2 Legal Requests. We will respond to lawful subpoenas, court orders, and government requests in compliance with applicable law. We will notify the affected Customer where lawful to do so.

5.3 Cooperation. You will cooperate reasonably with any investigation of suspected AUP violations involving your account.

6. Enforcement

6.1 Range of Actions. Depending on severity, we may issue a written warning; temporarily throttle, restrict, or suspend specific features of your account; suspend your account in full pending investigation; terminate your account immediately for material breach; refer the matter to law enforcement; and/or pursue civil remedies, including monetary damages and injunctive relief.

6.2 Material Breach — Immediate Action. The following constitute material breach permitting immediate suspension or termination without prior notice or refund: any activity prohibited under §3 involving illegal content, malware, or regulated-data violations; any activity prohibited under §4.1 involving unauthorized access, vulnerability probing without authorization, or denial-of-service activity; use of the Service in violation of export-control law, sanctions law, or anti-bribery law; and repeated lower-severity violations after written warning.

6.3 Refund Policy on Termination for AUP Violation. No refund of pre-paid fees is owed for the billing period in which the violation occurred. Future billing periods are credited or refunded in accordance with the refund provisions of the Terms of Service.

6.4 Survival. Termination, suspension, or expiration of your account or subscription does not relieve you of obligations that by their nature should survive, including obligations of confidentiality; obligations regarding the return or destruction of data (as provided in the Terms of Service and, where applicable, the DPA); the representations in §4.5; and liability for AUP violations accruing before termination.

7. Modifications

We may update this AUP from time to time. Material changes will be communicated by written notice sent by email to the account’s designated contacts (or by in-product notice) and, in addition, posted at defensescore.com/acceptable-use. Written notice is deemed given when sent; failure to read a properly sent notice does not extend any period. Each change takes effect on the effective date stated in the notice, and continued use of the Service after that effective date constitutes acceptance of the updated AUP.

8. Contact

Questions about this AUP: [email protected]
Security and abuse reports: [email protected]

DefenseScore Addendum

DS1. Self-Computed Score — Not an Official DoD/SPRS Score. DefenseScore computes a score from your inputs using the methodology of the U.S. Department of Defense (“DoD”) Supplier Performance Risk System (“SPRS”). It is not the official score in DoD’s SPRS, is not submitted to SPRS by us, and is not a Cybersecurity Maturity Model Certification (“CMMC”) assessment or a certified third-party assessment organization (“C3PAO”) / certified CMMC assessor (“CCA”) service. The score renders as plain text/typography only — no seal, badge, ribbon, watermark, or certificate-style graphic — so it does not visually resemble a third-party validation mark.

DS2. Your Submission and Affirmation. You are responsible for the accuracy of your control inputs and for your own SPRS submission and annual affirmation. DefenseScore tracks clocks and computes; you submit.

DS3. Not Legal or Compliance Advice. The score, Plan of Action and Milestones (“POA&M”) clock, and affirmation reminders are aids, not legal advice and not a guarantee of CMMC or Defense Federal Acquisition Regulation Supplement (“DFARS”) compliance.

DS4. No Government Transmission. We do not transmit your data to SPRS or any government system.

DefenseScore is a product of Ellis Intelligence LLC. This page is posted for transparency and is not legal advice. See also our Terms of Service and Privacy Policy. Questions about this document? Email [email protected].

Self-assessment tool — not a C3PAO. DefenseScore is a self-assessment software tool. It is not a C3PAO, not an assessment, not legal or compliance advice, and does not certify CMMC compliance.

Not affiliated with the U.S. Government. DefenseScore is not affiliated with, endorsed by, sponsored by, or acting on behalf of the U.S. Department of Defense (DoD), the Defense Contract Management Agency (DCMA), the Supplier Performance Risk System (SPRS), NIST, or any other government agency or standards body, and nothing on this site or the Service is, or should be read as, an official communication, determination, or prediction by any of them.

© 2026 Ellis Intelligence LLC  ·  d/b/a DefenseScore  ·  Colorado single-member LLC  ·  Terms  ·  Privacy  ·  Cookies  ·  Acceptable Use  ·  DPA  ·  Subprocessors