Acceptable Use Policy
This Policy applies to everyone who uses GitAegis, published by Fahid Digital Ventures LLC. It forms part of the Terms of Service and the End User Licence Agreement. It is short because most of it is obvious. It exists so that when we have to act, you already know why.
- Last updated
- 10 August 2026
1.Scope
1.1 This Policy covers the GitAegis desktop application, the account and cloud service at app.gitaegis.com, the API, and the website at gitaegis.com.
1.2 It applies to you and to anyone using the service through your account, including your employees, contractors, and any automated agent you configure.
1.3 We do not read your code. Cloud capsule objects are encrypted on your device before upload and we do not hold the key material: see Privacy Policy §5. This Policy is enforced on the basis of account behaviour, abuse reports, billing and access records, and lawful requests, not by inspecting repository contents, which we cannot do.
1.4 Nothing here requires us to monitor your use, and we do not.
2.Prohibited uses
2.1 You may not use GitAegis to:
- break the law, or help someone else break it;
- infringe intellectual property, privacy, publicity, or other rights;
- store, transmit, or distribute malware, ransomware, exploits packaged for deployment, or botnet infrastructure (see section 4 for the research exception);
- run attacks against any system, including port scanning, credential stuffing, denial of service, or unauthorised penetration testing;
- gain unauthorised access to any account, workspace, tenant, or system, including ours;
- circumvent seat limits, device binding, licence enforcement, or signature verification;
- abuse the API or the service in a way that degrades it for others;
- resell, sublicense, or provide the service to third parties without a written agreement;
- impersonate another person or organisation, or misrepresent your affiliation;
- harass, threaten, or abuse our staff, our support team, or other users;
- upload material that is unlawful in the jurisdictions where the service operates, including child sexual abuse material, which we report to the competent authorities;
- use the service to develop a competing product, or to benchmark it for publication without giving us the methodology and a right of reply;
- evade a suspension or termination by opening a new account.
2.2 This list is not exhaustive. If something is clearly abusive but not written down here, it is still not allowed.
3.Unlawful and infringing content
3.1 You are responsible for the content you put into the service and for the rights to it.
3.2 We do not host public content and we do not operate a publishing platform. Cloud capsule objects are private, encrypted, and unreadable by us.
3.3 Where we receive a valid legal notice about content in your account, we will forward it to you and give you the chance to respond, unless we are legally prohibited from doing so.
3.4 Repeat infringement, established by valid notices, is grounds for termination.
3.5 Copyright notices go to support@gitaegis.com until a dedicated legal-notice address is published. A notice should identify the work, identify the material, give your contact details, and include the statements required by applicable law. A postal address for Fahid Digital Ventures LLC is not published in this draft.
4.Malware and hostile code
4.1 You may not use GitAegis to distribute malware or to operate hostile infrastructure.
4.2 Security professionals may hold malware samples, exploit code, and offensive tooling in repositories managed with GitAegis as part of legitimate research, detection engineering, red teaming, or incident response. That is normal professional work and it is allowed.
4.3 The line is use, not possession: storing a sample for analysis is fine; using GitAegis as part of a delivery chain to infect someone is not.
4.4 If your work involves samples, we recommend keeping them in dedicated repositories, and we note that a support bundle you send us may reference file paths unless you redact them.
5.Licence, seat and device enforcement
5.1 A seat is for one named individual. You may reassign a seat when someone leaves. You may not rotate a seat between people to serve more users than you have paid for.
5.2 You may not share credentials, use a shared or role account to give multiple people a single seat, or configure a shared host so that several people use one seat.
5.3 You may not modify, patch, or proxy the application to bypass licence checks, device binding, or seat counting, and you may not use a build that has been so modified.
5.4 You may not tamper with a release or install a build that fails signature verification.
5.5 You may not use a trial repeatedly to avoid paying, or create multiple accounts to obtain repeated trials or repeated first-purchase refunds.
5.6 Where we identify a seat shortfall, we will normally contact you and ask you to true up rather than suspend. Deliberate circumvention is treated differently: see section 10.
5.7 The full licence terms are in the EULA §2 and §3.
6.Automated use and the API
6.1 Automated use of the API is expected and supported. Abuse of it is not.
6.2 You may not:
- exceed the published rate limits, or evade them by rotating tokens, accounts, or source addresses;
- run automation that degrades service for other customers;
- scrape the service to build a competing dataset or product;
- use a single seat’s credentials to serve requests for many people, which is a seat circumvention under section 5;
- share, publish, or embed API tokens in a place others can read them.
6.3 Rate limits are documented in the documentation. We return 429 with a Retry-After header. Honour it. Retrying without backoff is itself abuse.
6.4 Agent sessions and branch leases use heartbeats and TTLs. Do not keep a lease alive that your agent is not actually using; other members of your workspace are waiting on it.
6.5 If you need a higher limit for a legitimate workload, ask at support@gitaegis.com before engineering around the limit.
7.Reselling and service provision
7.1 GitAegis is licensed for your own internal use, personal or business.
7.2 You may not resell, rent, lease, sublicense, or provide the service to third parties, or operate it as part of a service you sell, without a written agreement with us.
7.3 Legitimate cases that are allowed: an agency or consultancy buying seats for its own staff, including staff working on client projects; a company buying seats for contractors it engages; managing repositories that belong to your clients using your own seats.
7.4 Not allowed: buying seats and assigning them to a client’s staff as a reseller, or bundling GitAegis into a product you sell, without an agreement.
7.5 If you want to resell or bundle, talk to sales@gitaegis.com. We would rather have the conversation than the enforcement.
8.Security research boundaries
8.1 We want vulnerability reports. The Vulnerability Disclosure Policy sets out what is in scope, how to report, what we commit to in return, and the safe harbour that protects good-faith research.
8.2 Research that stays within that policy is not a breach of this Policy, and section 2.1(4) and 2.1(5) do not apply to it.
8.3 Research that goes outside it is a breach. In particular, do not:
- access, modify, or exfiltrate data belonging to another customer;
- run denial-of-service or volumetric load testing against our production systems;
- use social engineering against our staff, our customers, or our vendors;
- pivot from a finding into further systems once you have proved the issue;
- publish a vulnerability before the coordinated disclosure timeline agreed in that policy.
8.4 Testing against your own account, your own data, and your own local installation is always fine.
8.5 When in doubt, ask at security@gitaegis.com before you test. We answer.
9.Reporting abuse
9.1 Report abuse of GitAegis to support@gitaegis.com with as much detail as you can: what happened, when, and any identifiers. A dedicated abuse address is not published in this draft.
9.2 Report security vulnerabilities to security@gitaegis.com under the Vulnerability Disclosure Policy, not to the abuse address.
9.3 We acknowledge abuse reports and tell you the outcome where we can do so without breaching another person’s privacy. How quickly we acknowledge is a commitment this draft does not state.
9.4 We do not disclose the identity of a reporter to the reported party unless legally required.
10.Enforcement
10.1 Our response is proportionate to what happened. In roughly increasing order:
| Response | When |
|---|---|
| We contact you and ask you to fix it | Most cases: seat shortfall, accidental API abuse, unclear reseller arrangement |
| Rate limiting or feature restriction | Automated abuse that is degrading service, while we talk to you |
| Suspension of the affected part of the account | Continued breach, or a security or legal risk that will not wait |
| Suspension of the whole account | Serious breach, or breach that continues after notice |
| Termination | Material breach not cured within 30 days of notice, or the conduct in 10.2 |
| Report to authorities | Where the law requires it, or where there is a credible risk of serious harm |
10.2 Grounds for immediate termination without a cure period: child sexual abuse material; a credible threat of violence; using the service in an active attack on a third party; deliberate licence circumvention at scale; and repeated evasion of a prior suspension.
10.3 We consider intent, scale, whether it was fixed once raised, and whether it has happened before.
10.4 Enforcement does not entitle you to a refund of fees already paid, except as the Refund Policy provides.
10.5 Termination rights are set out in Terms §14.
11.Suspension
11.1 Where practicable, we give notice before suspending and a reasonable chance to fix the problem.
11.2 Where the risk is immediate (an active attack, a legal requirement, a credible security threat) we may suspend first and tell you straight after, with the reason.
11.3 Suspension does not delete your data. Data retention during suspension follows Privacy Policy §7, and export remains available on reinstatement or, on request, during the suspension.
11.4 During a cloud suspension the desktop application continues to open your repositories, and history, undo, capsule restore and export keep working, unless the suspension is for licence circumvention under section 5.
11.5 We scope suspension as narrowly as we reasonably can: one workspace rather than a whole tenant, one API token rather than an account, where that addresses the problem.
11.6 Fees continue to accrue during a suspension for breach. They do not accrue during a suspension that turns out to have been our error, and we credit any period wrongly suspended.
12.Appeals
12.1 You can appeal any enforcement decision. Write to support@gitaegis.com with your account email and what you think we got wrong. A dedicated appeals address, and the window in which an appeal must be made, are not stated in this draft.
12.2 The appeal is reviewed by someone who was not involved in the original decision.
12.3 We respond in writing, with the outcome and the reason. How quickly is a commitment this draft does not state.
12.4 If we got it wrong, we reinstate the account, restore access, and credit any fees for the period of wrongful suspension.
12.5 If we uphold the decision, we tell you what, if anything, would change it.
12.6 Appealing does not affect any other right you have under the Terms of Service or under applicable law, including the dispute resolution process in Terms §16.
13.Changes and contact
13.1 We may update this Policy. Material changes are notified in advance, as set out in Terms §17. How much notice is not set in this draft.
13.2 Abuse reports and appeals: support@gitaegis.com
13.3 Security: security@gitaegis.com · Support: support@gitaegis.com · Sales: sales@gitaegis.com
13.4 Related: Terms of Service · EULA · Vulnerability Disclosure Policy · Privacy Policy