Legal · Acceptable use
Acceptable Use Policy
This policy governs how kolm's audit tooling, evidence reports, and verification services may be used. Our work tests live systems, so authorization and scope are not optional. They are the foundation of everything we sign.
Allowed and not allowed, at a glance
The full policy is below; this table is a quick orientation, not a substitute for it. Each row uses a mark plus a word so the answer reads without relying on color.
| Activity | Allowed |
|---|---|
| Test a system you own or are authorized to assess | yes |
| Verify a signed report offline at /verify | yes |
| Share an unaltered report with your buyers | yes |
| Test a system you do not own or are not authorized to assess | no |
| Alter a signed report and present it as genuine | no |
| Misrepresent a report's scope, date, or findings | no |
| Build malware, ransomware, or denial-of-service capability | no |
1. Authorization is mandatory
kolm performs security assessments only against systems the customer owns or is expressly authorized to test. Before any audit begins, the customer must confirm in writing that it has the authority to permit testing of the in-scope agent, its tools, and its connected systems. We do not test third-party systems, shared infrastructure, or any asset outside the agreed scope without separate written authorization from the party that controls it.
2. Scope of testing
An audit covers the application's permission posture, audit-trail integrity, data-handling and redaction, egress and supply-chain surface, and adversarial resilience (including prompt-injection probing): the agent and every tool, endpoint, identity and data flow around it, read from the logs the application already produces. Prompt-injection and jailbreak resistance are tested and reported, not warranted: a passing result reflects the tests we ran, not a guarantee that no attack exists. The scope, methods, and limits of each engagement are fixed in the statement of work and reflected in the resulting report.
Scope is contractual. Permission posture, redaction and audit-trail integrity are assessed. Injection is tested and reported, not warranted.
3. Prohibited conduct
You may not use kolm services to:
- test, probe, or attack any system you do not own or are not authorized to assess;
- misrepresent the scope, date, findings, or signature status of a kolm evidence report;
- alter a signed report and present it as genuine (every report is Ed25519-signed and independently verifiable, and tampering is detectable);
- use the tooling to develop, stage, or distribute malware, ransomware, or denial-of-service capability;
- exfiltrate, retain, or resell data belonging to a third party encountered during an engagement;
- circumvent rate limits, access controls, or tenant isolation in kolm's own services.
4. Integrity of evidence
Each report carries a cryptographic signature over its exact contents and a verification path that anyone can run offline with the published public key. Presenting a modified report as kolm-issued, forging a signature, or claiming a scope broader than the one tested is a material breach of this policy and may be unlawful. A buyer who receives a report should verify it at /verify rather than trust a forwarded claim.
5. Responsible disclosure
If you discover a vulnerability in kolm's own services or in a published report's verification path, contact us at dev@kolm.ai before disclosing it publicly. We will acknowledge, investigate, and coordinate a fix and disclosure timeline with you.
6. Suspension
We may suspend or terminate access for any use that violates this policy, threatens the integrity of the evidence we sign, or exposes kolm or a third party to legal risk. Where practical we will give notice and an opportunity to cure; where the conduct is unlawful or endangers others, suspension may be immediate.
7. Changes & contact
We may update this policy as our services evolve; material changes will be reflected in the "last updated" date above. Questions about acceptable use, scope, or authorization go to dev@kolm.ai.
See also: Terms · Privacy · SLA · Threat model
Authorized testing. Signed evidence.
Questions about scope or authorization route to one inbox. Or read the terms that govern an engagement.
Caveats: Scope is contractual. Permission posture, redaction and audit-trail integrity are assessed. Injection is tested and reported, not warranted.