This Acceptable Use Policy forms part of the
Terms of Service.
Stinger is for authorized security testing only. This Acceptable Use Policy defines what you may not do with the Service. Violations may result in immediate suspension or termination, and you remain responsible for the acts of your users, agents, and contractors.
1. Authorization and scope
- Do not target any AI system, model, endpoint, agent, or application that you do not own or operate, unless you hold current written authorization to test it.
- Do not exceed the scope, duration, or methods of the authorization you hold.
- Do not use the Service to test or attack AIM Intelligence’s own infrastructure, or the platform itself, outside of a coordinated disclosure arrangement.
2. Prohibited conduct
- Any unlawful activity, or use for any purpose prohibited by applicable law.
- Operationalizing findings, generated content, or attack chains against real users, production systems, or third parties to cause harm.
- Denial-of-service, resource-exhaustion, or volumetric attacks intended to degrade availability rather than evaluate guardrails.
- Social-engineering, phishing, or physical-intrusion testing of real people unless explicitly authorized in writing.
- Using the Service to facilitate the development of weapons (including nuclear, chemical, biological, or missile systems), mass surveillance, or harvesting of personal data.
- Impersonation, fraud, extortion, or threats of disclosure against any party.
3. Handling of sensitive data encountered during testing
- Minimize the collection of any real personal data, credentials, or regulated data a Target may emit, and stop and report rather than further exploit such data.
- Do not feed confidential or regulated data into unauthorized third-party AI tools, and apply human review to any AI-generated output before relying on it.
4. Outputs and resale
- Do not misuse the jailbreaks, exploit chains, or other dual-use output the Service produces for any unlawful or harmful purpose.
- Do not resell Stinger output as third-party red-team services, or provide the Service to others as a service bureau, without a written OEM or reseller agreement.
- Do not reverse-engineer the Service or use it to build a competing product.
5. Responsible disclosure
Where the Service is used in shared, benchmark, or arena settings involving third-party models, observe any applicable disclosure embargo and do not attempt to de-anonymize other participants. Report security issues with the platform itself to success@aim-intelligence.com.
Questions about this policy: success@aim-intelligence.com.