← Back to home

Acceptable Use Policy

Version 2026-05-16

Draft — pending legal review. This document is an engineering-prepared draft and is not legal advice. It is published in versioned form for transparency while qualified counsel reviews and finalises it. For the current authoritative position contact privacy@opsfi.co.

This policy sets out what you may and may not do with Diligence Forge. It forms part of the Terms of Service; a breach of this policy is a breach of those Terms.

1. Permitted use

You may use the Platform for your organisation's own due diligence, lending, investment, audit or advisory work on the deals you have been given access to, in accordance with your role and the permissions granted to you.

2. Security and access

You must not:

  • attempt to access, view or infer data belonging to another organisation or to a deal you have not been given access to;
  • probe, scan, test or circumvent any security, authentication, rate-limiting, spend-limiting or tenant-isolation control;
  • share credentials, disable multi-factor authentication where it is required, or allow anyone else to use your account;
  • impersonate another user or misrepresent your role or organisation.

3. Content

You must not upload or input:

  • material you do not have the right to process, including personal data for which you lack a lawful basis;
  • unlawful, defamatory or infringing material;
  • malware, malicious code or files designed to disrupt the Platform;
  • content intended to manipulate the behaviour of AI features (for example, instructions hidden in documents intended to alter how the AI classifies, summarises or drafts).

4. AI features

You must not:

  • use AI features to fabricate, backdate or misrepresent financial records, evidence or deliverables;
  • present AI Output as verified human work without the review the Platform records against it;
  • attempt to extract system prompts, model configuration or other organisations' content through the assistant or any AI feature;
  • circumvent AI usage limits or spend controls, or use AI features for purposes unrelated to diligence work on the Platform.

5. Platform integrity

You must not:

  • use automated means to extract data beyond the export features provided;
  • reverse-engineer, decompile or copy the Platform or its models;
  • use the Platform to build or train a competing product or service;
  • interfere with the operation of the Platform or impose an unreasonable load on it.

6. Confidentiality of deal information

Deal information is shared with you for the purposes of the engagement in which you participate. You must handle it in accordance with your organisation's confidentiality obligations, the engagement letter or other agreement governing the deal, and applicable law.

7. Reporting

If you become aware of a security vulnerability, a suspected breach of this policy, or content that should not be on the Platform, report it promptly to privacy@opsfi.co. Do not attempt to exploit or further investigate a vulnerability yourself.

8. Enforcement

OpsFi may investigate suspected breaches, remove content, suspend or restrict features, and suspend or terminate access, in each case in accordance with the Terms of Service. Serious breaches — including attempts to access another organisation's data — are treated as material breaches and may be reported to your organisation and, where required, to the relevant authorities.

9. Changes

Material changes bump POLICY_VERSION and are published in the Documentation Hub.

Questions: privacy@opsfi.co.