This Policy states how Nuaj products and services may and may not be used. It applies to every Nuaj product, to nuaj.com and its subdomains, to the download portal, and to every hosted service Nuaj operates.
It is incorporated into the Nuaj Master Terms and into each product's End User License Agreement, and it is linked from the screen on which those are accepted. It is not separately accepted: abuse response cannot wait for a re-acceptance cycle, so this Policy can be updated and take effect immediately. Material changes are notified through the service or by email.
Nuaj Company Inc.
8250 Lawson Rd., Suite 201
Milton, Ontario L9T 5C6
Canada
Abuse reports: abuse@nuaj.com · Security reports: security@nuaj.com · Legal: legal@nuaj.com
Who this applies to
This Policy binds the Customer, every Authorised User, and — through the Customer — every End Customer served with a Nuaj product. Those words have the meaning given in the Master Terms.
The Customer is responsible for compliance by its Authorised Users and its End Customers. Where you provide a service to others using a Nuaj product, you must impose terms on them that are no less protective of Nuaj than this Policy, and you must be able to act on a breach when Nuaj tells you of one.
The core rule
No Nuaj product may be used for any unlawful purpose, and none may be used against a system, network, device, or account that you do not own or have documented written authorization to act on.
Nuaj's products inspect traffic, filter it, block it, and — in the case of a scanner — actively probe systems. Every one of those actions is lawful when performed on infrastructure you control or have been authorised to act on, and can be an offence when it is not. The authorisation is yours to hold. Nuaj does not verify it, cannot obtain it for you, and has no relationship with the party whose infrastructure you touch.
Prohibited uses
You must not use a Nuaj product, or any Nuaj service, to:
- break any applicable law or regulation, or infringe the rights of any person;
- gain unauthorized access to, scan, probe, disrupt, degrade, or attack any system, network, or device you do not own or have documented written authorization to test;
- intercept, monitor, filter, or record traffic on a network where you lack the legal authority to do so, or in breach of any workplace-monitoring, lawful-interception, wiretap, telecommunications, or privacy obligation;
- deny service to others, generate load intended to exhaust another party's capacity, or conduct load or stress testing against infrastructure you have not been authorised to test;
- conceal, facilitate, or carry out any criminal offence, or evade lawful process;
- distribute malware, run command-and-control infrastructure, or stage an intrusion;
- send unsolicited bulk messages, or use Nuaj infrastructure to support a service that does;
- violate the privacy or communications rights of any person, or process personal data in a way your own authority does not permit;
- misrepresent your identity, your authority, or your affiliation with Nuaj.
Authorisation to test and to scan
Where a Nuaj product performs active testing, scanning, probing, or credentialed inspection of an asset:
- you must own the asset, or hold documented written authorization from the party that does, before it is scanned, and you must keep that authorization for as long as you scan;
- that requirement extends to every asset you register on behalf of an End Customer — your authorisation must reach it;
- you must respect the scope and timing conditions of the authorization you hold; and
- you remain responsible for the consequences of a scan you run, including on assets that turn out not to be in scope.
Scanning can break the target. A scan can crash a service, exhaust a device, lock accounts, trip an intrusion detection system, and generate load a third party is billed for. That risk is yours and your End Customer's, not Nuaj's.
Reporting, findings, and other parties' data
Where a product produces findings, reports, or evidence about a third party's infrastructure:
- you are responsible for the lawfulness of what you distribute, and for the confidentiality of findings that describe another party's security weaknesses;
- you must not publish or disclose a finding about a third party's system in a way that exposes it to attack, other than through a coordinated disclosure process; and
- where you submit an abuse report or evidence to a third party through a Nuaj product, the facts in it must be accurate and derived from your own observations.
Shared and community services
Where a product contributes to or draws from a shared Nuaj service — including the Nuaj Threat Exchange and community threat lists:
- you must not submit false, misleading, fabricated, or deliberately poisoned data;
- you must not submit indicators describing a network you have no authority to report on;
- you must not use a shared service to launder attribution, to retaliate, or to cause a third party to be blocked without cause; and
- you must not scrape, resell, or redistribute a Nuaj-operated feed or list except as your licence allows.
Nuaj's own systems
You must not:
- interfere with the integrity, availability, or performance of a Nuaj service, or attempt to;
- circumvent, disable, or interfere with licensing, metering, usage limits, update mechanisms, signature verification, or security measures;
- reverse engineer, decompile, or disassemble any Nuaj product, except as the applicable EULA or an open-source licence permits;
- share, resell, or automate access to the download portal beyond what your access grant allows, or redistribute a Nuaj binary you were granted access to;
- probe or test Nuaj's own infrastructure, other than under the Vulnerability Disclosure Policy at security@nuaj.com; or
- use a Nuaj product to build or improve a competing product or service.
Security research
Good-faith security research on Nuaj's own products is welcome and is governed by the Vulnerability Disclosure Policy. Research conducted within that Policy is not a breach of this one. Research on someone else's systems is not covered by it, and needs their authorization, not Nuaj's.
Enforcement
Breach of this Policy is a material breach of the Master Terms and of the applicable EULA.
Where use is unlawful, or presents a risk to others, Nuaj may suspend or terminate access immediately, without notice and without refund, and may report unlawful activity to the appropriate authorities. Where the breach is capable of cure and presents no immediate risk, Nuaj will normally give notice and a reasonable opportunity to cure first.
Nuaj may also, in proportion to the seriousness of the breach: disable a specific capability rather than the account; remove or refuse to distribute submitted data; require evidence of the authorisation you rely on; or decline to serve a future request.
Nuaj is not obliged to monitor use, and does not. Nothing here makes Nuaj responsible for what a Customer, an Authorised User, or an End Customer does with a product.
Reporting abuse
Report abuse of a Nuaj product or service to abuse@nuaj.com. Report a vulnerability in a Nuaj product to security@nuaj.com under the Vulnerability Disclosure Policy. Include what you observed, when, and how it can be verified; Nuaj acknowledges reports and will act where it can.
Language
This Policy was drafted in the English language, and the English version is the sole authoritative version. A French translation is published for convenience and has no legal effect. In the event of any conflict, the English version prevails.