Keel Insights LLC
Acceptable Use Policy
Requirements for safe, lawful, and authorized use of Keel MSP
This Acceptable Use Policy (“AUP”) forms part of the Keel MSP Terms of Service and any customer agreement that incorporates it. It protects Customers, managed clients, users, third-party providers, and the Keel platform from unlawful, unauthorized, abusive, or unsafe activity.
Capitalized terms not defined here have the meanings given in the Terms of Service or the applicable customer agreement.
2 Illegal or Harmful Activity
You may not use the Services to:
- violate applicable law, regulation, court order, contract, or another person’s legal rights;
- commit or facilitate fraud, deception, impersonation, harassment, threats, discrimination, or unlawful surveillance;
- create, distribute, or support malware, ransomware, destructive code, phishing, credential theft, or other harmful activity;
- infringe intellectual property, privacy, publicity, confidentiality, or data-protection rights; or
- store, distribute, or transmit content that is unlawful or that creates a credible risk of harm to a person, system, or organization.
3 Security Abuse
You may not attempt to gain unauthorized access to the Services, another Customer, a managed client, a third-party system, or supporting infrastructure. Prohibited activity includes unauthorized vulnerability scanning, exploitation, credential testing, privilege escalation, interception, disruption, tenant-boundary bypass, and circumvention of authentication, authorization, approval, logging, rate-limit, or security controls.
Security testing of Keel systems requires Keel’s prior written authorization. Authorized MSP security work involving a managed-client environment must remain within the Customer’s documented authority and the applicable provider’s terms.
4 Data, Privacy, and Third-Party Rights
You may not submit, retrieve, disclose, or process data through the Services unless the Customer has a lawful basis and appropriate authority to do so. You may not connect a Google, Microsoft, PSA, RMM, security, backup, documentation, or other third-party account without permission from the organization that controls it.
You must comply with applicable privacy notices, retention duties, data-subject rights, third-party API terms, and provider policies. You may not use data obtained through an integration for a materially different purpose from the purpose for which access was authorized.
5 Platform and Service Abuse
You may not:
- overload, flood, disrupt, degrade, or interfere with the Services or another user’s access;
- circumvent quotas, usage limits, billing controls, safety controls, or rate limits;
- scrape, harvest, or extract data except through authorized features and APIs;
- resell, sublicense, or provide unauthorized access to the Services;
- reverse engineer non-public portions of the Services except where applicable law prohibits that restriction;
- remove proprietary notices or misrepresent the source of reports, evidence, or Service output; or
- use the Services to build, train, benchmark, or operate a competing product without Keel’s written permission.
6 AI and Automation
You may not use AI-assisted or automated features to fabricate evidence, impersonate a person, misrepresent source data, evade review requirements, or initiate an action that you are not authorized to perform. You must maintain appropriate human review for client-facing conclusions, technical-alignment decisions, recommendations, device actions, security actions, and other consequential output.
You may not use the Services as the sole basis for legal, medical, financial, employment, credit, insurance, or other decisions that produce significant effects on a person.
7 Sensitive and Regulated Data
Unless expressly authorized in a written agreement with Keel, you may not intentionally submit protected health information, full payment-card data, government-issued identification numbers, biometric templates, data about children, classified information, export-controlled technical data, or other data that would subject Keel to specialized legal or security obligations beyond the contracted Services.
Do not place passwords, private keys, recovery codes, or other reusable secrets in free-form notes, prompts, reports, tickets, or uploaded documents. Integration credentials must be provided only through designated secure credential fields.
8 Enforcement
Keel may investigate suspected violations and may restrict an account, integration, action, feature, API, collector, or workspace when reasonably necessary to protect the Services or others. Depending on severity, Keel may remove prohibited material, preserve relevant records, require remediation, suspend access, notify the Customer, notify an affected provider, or terminate access as allowed by the Terms and applicable law.
When practicable and consistent with security and legal obligations, Keel will provide notice and an opportunity to cure. Severe, deliberate, repeated, or unlawful conduct may result in immediate action.
9 Reporting Concerns
Report suspected abuse, unauthorized access, or a violation of this AUP to hello@keelinsights.ai. Include enough information for Keel to identify the affected Customer, workspace, integration, or activity, but do not send passwords, private keys, or other reusable secrets by email.
10 Changes
Keel may update this AUP to address changes in the Services, threats, law, or provider requirements. Keel will update the “Last updated” date and provide reasonable notice of material changes when practicable. Please also review the Terms of Service and Privacy Policy.