Acceptable Use Policy
Effective August 24, 2026
This policy is part of the Terms of Service. It applies to everyone who uses SOAR, including everyone you invite into your workspace.
The short version: use SOAR to run your business, not to harm anyone else's.
1. Do not break the law with it
Do not use SOAR to do, plan, or conceal anything unlawful. That includes fraud, money laundering, harassment, stalking, and the distribution of material that is illegal to distribute.
2. Do not put data in it that you have no right to process
Only put data into SOAR that you are allowed to hold and to have processed on your behalf. If you are handling personal data belonging to other people — your clients, their customers, your staff — you are responsible for having a lawful basis for it.
Do not put the following into SOAR. The service is not built for them, is not certified for them, and putting them in creates obligations neither of us has agreed to:
- Payment card numbers. SOAR is not in PCI DSS scope and must not be brought into it. If a statement or document you are about to upload contains full card numbers, redact them first.
- Protected health information covered by HIPAA, unless we have signed a Business Associate Agreement with you. We have not.
- Government-classified material, or anything covered by ITAR or export control.
- Biometric identifiers, or the personal data of children under 13.
- Consumer credit reports subject to the Fair Credit Reporting Act.
3. Do not use it to send unsolicited bulk email
SOAR can send mail on your behalf. Send it to people who have a genuine relationship with your business or who have asked to hear from you.
Do not use SOAR for unsolicited bulk email, list rental or purchase, forged headers, or any mail that would breach the CAN-SPAM Act. Honour unsubscribe requests promptly.
We monitor for deliverability problems, and we will suspend sending from an account that is damaging shared sending reputation.
4. Do not attack the service
Do not:
- Attempt to access another customer's workspace or data, or test whether you can.
- Probe, scan or penetration-test the service without our prior written permission. Ask — the answer is often yes, in a scheduled window, and we would rather work with you than find out from a log.
- Circumvent rate limits, authentication, multi-factor enrolment, quotas, or billing.
- Reverse engineer, decompile or disassemble the software, except where the law expressly permits it despite this restriction.
- Introduce malware, or use SOAR to distribute it.
- Use automated means to scrape the service beyond what our documented API allows.
- Resell, sublicense or provide SOAR as a service to third parties without a written agreement with us.
If you find a security vulnerability, tell us at hello@soar-crm.com. We will not pursue you for good-faith research that respects these rules, stops at proof, and does not access, alter or exfiltrate other people's data.
5. Do not misuse the AI
Do not use SOAR's AI features to:
- Generate material that impersonates a real person or organisation in order to deceive.
- Produce content designed to defraud, phish, or manipulate someone into a financial decision.
- Make automated decisions that have a legal or similarly significant effect on a person — credit, employment, housing, insurance, benefits — without a human making the actual decision.
- Deliberately present AI-generated conversation as a human being where the person on the other end would reasonably expect otherwise. SOAR discloses that its assistants are bots; do not undo that.
- Attempt to extract the underlying model's instructions or to circumvent its safety behaviour.
6. Fair use of shared resources
SOAR's AI usage costs real money per request and is subject to spend caps.
Do not deliberately run up consumption in a way that degrades the service for other customers or is plainly outside normal business use. If you need higher volume, ask — we will price it rather than throttle you by surprise.
What happens if you breach this
Most breaches are accidents and start with an email from us.
Where the breach is serious, or where continuing to serve the account would expose us, another customer or a third party to real harm or legal liability, we may suspend the account immediately and without notice. We will tell you why as soon as we reasonably can, and we will restore service once the problem is resolved.
Repeated or deliberate breaches are grounds for termination under §4 of the Terms of Service.
Contact
Report abuse, or ask whether something is allowed, at hello@soar-crm.com.
SOAR CRM LLC 100 Holly Park Court, Holly Springs, GA 30115