Last updated · 30 August 2026 · draft 0.1
The constraint this policy is written under
This policy prohibits a list of things. A gateway that could never see anything would have no way to act on most of that list, so the honest question is not "what is forbidden" but "what happens when someone does it anyway".
Enforcement runs primarily on four content-blind signals — blind fingerprint matching against known-bad sets, the model vendor's own filter refusals, traffic shape, and payment and identity. Those catch fraud and industrialised abuse well. They catch a low-volume, well-resourced bad actor poorly, which is why a short minimum-retention window sits beneath the zero-retention tiers, and why those tiers are contracted rather than toggled.
At zdr_absolute we hold nothing and therefore cannot investigate at
all. That tier is available precisely because the customer has accepted the
enforcement duty in writing — AUP flow-down to their end users, a named responsible
officer, and indemnity. The duty does not disappear with the ciphertext; it moves.
How the tiers work.
Prohibited uses
You may not use the Service to:
- Do anything unlawful in the jurisdictions where you operate or where the serving endpoint sits.
- Generate or distribute child sexual abuse material. Reports go to the relevant authorities and the account is terminated without notice or refund.
- Produce content intended to harass, threaten or defame a specific person, or to facilitate stalking or doxxing.
- Build systems whose purpose is fraud, phishing, credential theft, malware distribution, or evasion of security controls.
- Generate material designed to deceive about identity or provenance — impersonating a real person or organisation, fabricating records or endorsements, or producing synthetic media of a real person without their consent.
- Operate election disinformation, coordinated inauthentic behaviour, or mass political manipulation.
- Provide medical, legal or financial advice presented as coming from a qualified professional, without human review by one.
- Make consequential decisions about individuals — employment, credit, housing, insurance, benefits, criminal justice — without meaningful human review.
- Develop weapons, or provide operational uplift toward chemical, biological, radiological or nuclear capability.
- Circumvent rate limits, quotas or billing, including by creating multiple accounts to evade a suspension or to claim repeated introductory credit.
- Resell access in a way that conceals from your own customers who is processing their data, where, or under what retention terms. If you resell, tell them — everything you need to do so is on your receipts.
Vendor terms also apply
Each model vendor has its own acceptable use policy, and traffic routed to that vendor's endpoint is subject to it. Where a vendor's terms are stricter than ours, theirs govern for that endpoint.
Two consequences worth stating plainly:
- A vendor's content filter may refuse your request. We surface that refusal as
content_filterand we do not retry it on a different vendor. Routing around a filter would make us a laundering service for the thing the filter exists to prevent. - A vendor may act against traffic it attributes to us. Where that happens we will tell you what we know. Your access does depend on our standing with the vendors — we hold the agreements, and there is no bring-your-own-key arrangement here that would let you route around that. It is a real dependency and we would rather name it than imply an escape hatch we do not offer.
How we enforce
| Signal | What it is | Why it does not require reading content |
|---|---|---|
| Payment | card verification, issuer risk, chargeback history, disposable-email and disposable-phone detection | fraud rings fail here long before their traffic is interesting |
| Velocity | first-week spend caps, key-creation rate, step-ups earned by aged settled payments | caps the damage of an account we have not yet judged |
| Traffic shape | request-size distributions, token ratios, model mix, concurrency curves, time-of-day entropy | industrialised abuse has a distribution; a development team has a different one |
| Identity | business verification above a spend threshold; KYC where required | accountability rather than inspection |
| Blind matching | perceptual hashes of content checked against known-bad fingerprint sets | returns matched: true against a known fingerprint, never the content itself |
| Vendor filters | the serving vendor's own content filter refusals, counted per key | the vendor made the judgement; we only count how often it fires |
| Reports | third-party reports of harm traced to output | a human judgement, not an automated classification |
| Sealed content, on cause | the minimum-retention window, or a 2-of-3 unseal on the escrow tier | requires cause and, above mdr, a second party — and every attempt is written into the customer's own receipt chain |
The first four operate on metadata that already exists for
billing and require no readable copy. The last one is the reason a retention floor
exists at all — and it is bounded by tier, by window, by cause, by dual control above
mdr, and by a record you can audit.
What happens
Proportionate, and with notice except where immediate action prevents serious harm:
- Contact. Most apparent violations are misconfiguration, and a question resolves them.
- Rate or spend restriction. Limits the exposure while we understand the pattern.
- Suspension. Takes effect within seconds, because every request is already gated against a balance at admission.
- Termination, with refund of unused prepaid credit except where the violation was fraud or CSAM.
You may appeal any action to appeals@prismux.com and reach a human.
We will tell you which signal triggered the action, at a level of detail that does
not hand an abuse operation a map of our detection.
Reporting misuse
abuse@prismux.com. Include what you observed and, if you have it, the
receipt id — it identifies the request without revealing its content, which is a
useful property of the format and one of the reasons receipt ids are safe to share
in a report.
The English text is the authoritative version of this document. Translations are provided for convenience and, in the event of any conflict, the English text governs.