Acceptable Use Policy
The marketplace is for authorized, bounded business work—not access circumvention or harmful automation.
Effective September 20, 2026
Authorized business use only
You may use Zinvyl only for lawful business purposes within systems, data, and workflows you own or are expressly authorized to test. You must accurately describe your authority, intended outcome, and relevant restrictions.
Prohibited content and activity
You may not use the service to develop or deploy malware, credential theft, phishing, spam, surveillance, harassment, discrimination, fraud, sanctions evasion, illegal goods or services, unauthorized scraping, destructive code, access-control bypasses, or activity that violates law or another party's rights.
No secrets or regulated data in public intake
Do not submit passwords, tokens, API keys, private keys, banking credentials, full payment-card data, Social Security numbers, protected health information, unredacted government identifiers, export-controlled technical data, or raw confidential freight documents through public intake or MCP tools.
Platform and agent abuse
Do not overload, scan, probe, reverse engineer, evade request limits, replay payment events, forge funding states, impersonate a buyer, automate purchases without budget-owner authorization, or use agent interfaces to create misleading transaction evidence.
High-impact decisions
Do not rely on Zinvyl output as the sole basis for decisions about employment, credit, housing, insurance, healthcare, legal rights, safety-critical control, customs compliance, or other regulated or high-impact matters. Qualified human and professional review remains required.
Enforcement
Zinvyl may reject, throttle, suspend, preserve evidence of, or report suspected abuse; remove unsafe materials; and require additional verification. Where practical, Zinvyl will explain the applicable restriction. Lawful security research requires prior written authorization and a defined test scope.