back to legal hub

custom

LoArt & Dev Acceptable Use Policy

Defines permitted and prohibited use of LoArt & Dev services, including rules for access controls, credentials, APIs, security testing, privacy, and shared infrastructure.

Version v1.0Updated 9/9/2026

1. Purpose

This Acceptable Use Policy describes the rules for accessing and using private services, applications, systems, networks, and other resources operated or made available by LoArt & Dev.

LoArt & Dev is a private group operating through:

https://loart.dev

This policy exists to help protect the security, privacy, availability, and integrity of LoArt & Dev services and the people authorized to use them.

The current version of this policy is publicly available at:

https://loart.dev/legal/acceptable-use-policy

2. Scope

This policy applies to users who have been granted access to LoArt & Dev systems or services.

This includes, where applicable:

  • Helios;
  • applications authenticated through Helios;
  • websites;
  • APIs;
  • servers;
  • storage systems;
  • networking infrastructure;
  • administrative interfaces;
  • development and testing systems; and
  • other private resources operated by or made available through LoArt & Dev.

Individual services may have additional Terms of Service, privacy policies, security policies, or service-specific rules.

3. Authorized Use

LoArt & Dev services are private resources.

Access is permitted only where it has been explicitly or reasonably granted.

Users must use services only for purposes consistent with the access they have been given.

The existence of a technically accessible:

  • URL;
  • endpoint;
  • API;
  • file;
  • server;
  • network service;
  • administrative page;
  • role;
  • permission; or
  • other resource

does not itself constitute authorization to use that resource.

4. Accounts and Credentials

Users must not:

  • share accounts with unauthorized persons;
  • intentionally disclose passwords;
  • share MFA secrets;
  • share recovery codes;
  • transfer accounts without authorization;
  • impersonate another user;
  • use another user's credentials without authorization; or
  • attempt to obtain credentials belonging to another person.

Users should promptly report suspected credential compromise.

5. Access Controls

Users must respect access controls implemented by LoArt & Dev services.

Users must not intentionally:

  • bypass authentication;
  • bypass authorization;
  • escalate their privileges without authorization;
  • modify their own roles or permissions without authorization;
  • exploit incorrectly configured permissions;
  • access another user's private information without authorization;
  • use administrative functionality they have not been granted; or
  • circumvent restrictions imposed by an application or administrator.

If a system accidentally provides access that appears inconsistent with your expected permissions, report the issue rather than intentionally exploiting it.

6. Security Testing

Good-faith security research can be valuable, but testing private systems without appropriate authorization can create security and availability risks.

Unless explicitly authorized, users must not perform:

  • automated vulnerability scanning;
  • credential attacks;
  • password spraying;
  • brute-force authentication attempts;
  • denial-of-service testing;
  • destructive testing;
  • malware deployment;
  • privilege-escalation testing against other users;
  • attempts to extract secrets;
  • social engineering; or
  • testing that intentionally accesses another user's private information.

Suspected vulnerabilities should be reported to:

support@loart.dev

Authorized security testing may be permitted separately.

7. Service Disruption

Users must not intentionally interfere with the normal operation or availability of LoArt & Dev services.

Prohibited activity includes intentionally:

  • overwhelming services with requests;
  • exhausting system resources;
  • disrupting networking infrastructure;
  • corrupting shared data;
  • preventing legitimate users from accessing services;
  • bypassing rate limits;
  • causing avoidable infrastructure instability; or
  • interfering with monitoring, logging, backups, or security controls.

8. Malware and Harmful Content

Users must not knowingly use LoArt & Dev infrastructure to:

  • distribute malware;
  • operate malicious software;
  • compromise other systems;
  • steal credentials;
  • deploy ransomware;
  • conduct phishing;
  • distribute malicious scripts intended to compromise users; or
  • otherwise intentionally harm systems or users.

9. Privacy

Users must respect the privacy of other authorized users.

Users must not intentionally access, collect, copy, disclose, or distribute another person's private information unless they have a legitimate reason and appropriate authorization.

Access granted for administrative or technical purposes should not be used to inspect private information unnecessarily.

10. Administrative Privileges

Users with administrative privileges have additional responsibilities.

Administrative access should be used only for legitimate:

  • administration;
  • maintenance;
  • troubleshooting;
  • security;
  • development;
  • support; or
  • access-management purposes.

Administrative privileges for one LoArt & Dev service do not automatically authorize administrative access to another service.

Users must respect the authorization boundaries defined by each application.

11. APIs and Automation

Where LoArt & Dev services provide APIs, access tokens, API keys, webhooks, or machine credentials, users must protect those credentials appropriately.

Users must not:

  • publish private API keys;
  • expose machine credentials to unauthorized persons;
  • intentionally bypass API authorization;
  • use credentials assigned to another integration without authorization; or
  • deliberately circumvent API rate limits or safeguards.

Compromised machine credentials should be revoked or reported promptly.

12. Logs and Security Controls

Users must not intentionally:

  • delete security records without authorization;
  • falsify audit information;
  • manipulate logs to conceal activity;
  • disable security monitoring without authorization;
  • interfere with incident investigation; or
  • attempt to hide malicious or prohibited activity.

Normal log maintenance performed by authorized administrators is permitted.

13. Lawful Use

LoArt & Dev services must not knowingly be used for activity prohibited by applicable law.

Users remain responsible for ensuring that their use of the services is lawful and consistent with the permissions granted to them.

14. Resource Use

LoArt & Dev services operate on shared private infrastructure.

Users should avoid unreasonable use that materially affects other authorized users or services.

Where unusually resource-intensive activity is required, users should coordinate with an administrator where practical.

15. Reporting Problems

Users are encouraged to report:

  • suspected vulnerabilities;
  • compromised accounts;
  • exposed credentials;
  • unexpected access;
  • suspicious activity;
  • privacy concerns;
  • service abuse; or
  • other security problems.

Reports should be sent to:

support@loart.dev

Reports should contain enough information to investigate the issue while avoiding unnecessary disclosure of passwords, recovery codes, private keys, MFA secrets, or other sensitive credentials.

16. Enforcement

Violations of this policy may result in actions reasonably necessary to protect LoArt & Dev systems and users.

These actions may include:

  • warnings;
  • revocation of sessions;
  • revocation of API keys or machine credentials;
  • removal of roles or permissions;
  • temporary restriction of access;
  • suspension of an account;
  • permanent revocation of access; or
  • other technical or administrative measures appropriate to the situation.

Immediate action may be taken where activity presents a security, privacy, or availability risk.

17. Security Incidents

During an active or suspected security incident, LoArt & Dev administrators may temporarily restrict:

  • accounts;
  • sessions;
  • applications;
  • APIs;
  • integrations;
  • network access; or
  • other functionality

where reasonably necessary to investigate or contain the incident.

18. No Entitlement to Access

Access to LoArt & Dev services is provided privately.

An account, invitation, API key, role, permission, or other access grant does not create a permanent entitlement to continued access.

Access may be changed or revoked when reasonably necessary.

19. Service-Specific Policies

Individual LoArt & Dev services may impose additional requirements.

Where applicable, users should also review the relevant:

  • Terms of Service;
  • Privacy Policy;
  • Security Policy; and
  • other service-specific documentation.

Helios, for example, maintains additional policies concerning its identity and authentication functionality.

20. Changes to This Policy

This Acceptable Use Policy may be updated as LoArt & Dev services, infrastructure, or security requirements change.

The Last Updated date at the beginning of this document identifies the current version.

The canonical current version is available at:

https://loart.dev/legal/acceptable-use-policy

21. Contact

Questions about this policy, requests for clarification, suspected abuse, security concerns, or technical support should be directed to:

support@loart.dev

The primary LoArt & Dev website is:

https://loart.dev

Current public legal documents are available at:

https://loart.dev/legal/