Legal
Acceptable Use Policy
Rules for using DueFiles.
Last updated 13 September 2026
This Acceptable Use Policy is part of the Terms of Service. It applies to every user of a workspace, every portal visitor, and every system that calls a DueFiles API. Customer is responsible for the conduct of its users and for portal tokens it issues.
The Service is a business tool for collecting and reviewing insurance and related vendor documents. Use it for that purpose. If a use is not listed as prohibited, that does not mean it is permitted when it would reasonably harm other customers, vendors, or the integrity of the Service.
Permitted use
You may create workspaces for your organization, invite colleagues, send portal links to your vendors and brokers, store certificates and endorsements you have a right to hold, configure requirement templates, export your own data, and connect webhooks to systems you control.
You may not
Without limiting the Terms, you may not:
- Probe, scan, or load-test the Service, another customer's workspace, or a portal token you were not issued, except with our prior written permission.
- Bypass authentication, tenant isolation, rate limits, or payment controls, or attempt to access data that is not yours.
- Upload malware, or files you do not have the right to share.
- Use inbound addresses, reminder mail, or SMS to send unsolicited bulk messages to people who are not your vendors, brokers, or employees.
- Resell, timeshare, or operate DueFiles as a managed certificate bureau without a written reseller or MSP agreement.
- Misrepresent a DueFiles extraction, status badge, or report as a legal opinion, insurance policy, binder, or proof that a carrier will defend or indemnify anyone.
- Interfere with reminders, audit logs, or another user's access, or alter logs to hide a decision.
- Use the Service to violate export, sanctions, privacy, anti-spam, or insurance-licensing law.
- Scrape the Service to build a competing product, or to compile a marketing list of vendors or brokers.
- Submit content that is unlawful, harassing, or that depicts a minor in any sexual context.
- Use automated agents to create accounts or consume extraction at a volume intended to degrade the Service.
Security research
Good-faith security research is welcome at security@duefiles.com. Stay within the reported scope. Do not access other customers' data, destroy data, or publicly disclose an issue before we have had a reasonable chance to remediate it. We will not pursue legal action against researchers who follow those rules.
Enforcement
We may disable a token, inbound address, or workspace that violates this policy, and we may report unlawful activity to authorities. Repeated or severe violations may result in termination under the Terms, without refund except where required by law.
Last updated 13 September 2026.