Acceptable Use Policy
What the A8 Core™ platform may and may not be used for, the security and data obligations that come with a tenant, and how suspension works.
Last updated 23 July 2026 · Version v.260723
1. Who this applies to
This policy applies to every user of the A8 Core™ platform and APIs: the institution that licenses the platform, its personnel, its service providers acting on its behalf, and any end user acting through it. The licensing institution is responsible for the conduct of everyone acting under its tenant.
2. Prohibited use
You may not use the platform to:
- break any applicable law, regulation or sanctions programme, or help anyone else do so;
- facilitate money laundering, terrorist financing, sanctions evasion, market manipulation, insider dealing or fraud;
- hold or move assets for a person or entity you have not verified to the standard your own programme requires;
- evade a control, threshold, approval requirement or reporting obligation configured in your tenant, including by structuring activity to stay below a threshold;
- act on a record you are not authorised to act on, or use another person’s credentials, Passport or delegated authority;
- present platform output as investment advice, a recommendation, a suitability determination or an endorsement, or as due diligence performed by us;
- infringe intellectual property, or misuse our marks contrary to the trademark policy;
- transmit malware, or attempt to gain unauthorised access to the platform, another tenant, or any underlying system.
3. Data and privacy obligations
You may upload only personal data you are entitled to process, and only for purposes consistent with the notices and consents you have given the individuals concerned. Do not place personal data in fields not intended for it — free-text notes, record identifiers, file names or URL parameters — because data in those places is harder to find, export and delete when someone exercises a right. Do not upload special-category or sensitive data unless your deployment has been configured for it.
4. Security obligations
You are responsible for the security of credentials issued to your tenant. Specifically: enforce multi-factor authentication for privileged users; grant least privilege and review it; never embed a production credential or API key in client-side code, a public repository or a support ticket; rotate credentials on personnel change; and tell us promptly if you believe a credential is compromised.
Do not test the security of the platform without written authorisation. Coordinated testing is welcome — see the security policy for how to arrange it.
5. Platform integrity and fair use
Do not attempt to circumvent rate limits, run load or stress tests against production without authorisation, scrape at a volume that degrades service, or use the platform to build a substantially similar competing service. Published rate limits and quotas are part of the service definition, not a suggestion.
6. Reporting a violation
Report suspected abuse to security@a8core.com. If the report concerns suspected financial crime in your own institution, follow your own escalation procedure first — we are not your compliance function and cannot file on your behalf.
7. Enforcement and suspension
Where use presents an immediate risk to the platform, to another tenant, or of legal or regulatory harm, we may suspend the affected access without prior notice, narrowing suspension to what is necessary. We will tell you what we did and why, and restore access when the risk is resolved. Repeated or deliberate violation may lead to termination under your platform agreement.
Because authorization is evaluated and recorded per data element, a suspension can usually be applied to a specific purpose, delegation or record class rather than by disabling an institution.
This policy supplements and does not replace your platform agreement. Governed by the laws of the State of California; exclusive venue is the state and federal courts located in San Mateo County, California.
Questions about this document? Contact legal@a8core.com or write to Financial Infrastructure, Inc., PO Box 1410, Menlo Park, California 94026-1410.