Acceptable Use Policy
This Acceptable Use Policy (“AUP”) describes what you may and may not do with benchwright.ai and the related services operated by Benchwright LLC (“Benchwright,” “we,” “us,” or “our”). It is part of our Terms of Service. Capitalized terms used here have the meanings given in the Terms.
1. General rules
You agree not to use the Service, and not to help or enable anyone else to use the Service, in any way that:
- Violates any applicable law, regulation, or sanctions regime (including U.S. export controls and OFAC lists);
- Infringes, misappropriates, or violates the intellectual property, privacy, publicity, contractual, or other rights of any person;
- Is deceptive, fraudulent, or designed to mislead;
- Harasses, threatens, or promotes violence against any individual or group;
- Generates or distributes content that sexually exploits or endangers minors (CSAM), non-consensual intimate imagery, or material that violates applicable obscenity law;
- Circumvents, interferes with, or disables any security, access control, or rate limit of the Service or of any third-party service the Service connects to;
- Violates the terms of service of any third-party model provider, data source, or API you interact with through the Service.
2. System abuse & security
You agree not to:
- Probe, scan, or test the vulnerability of the Service or any system or network, except against systems you own or are expressly authorized to test, and then only in a manner consistent with accepted responsible-disclosure norms;
- Use the Service or our sandboxes to send denial-of-service traffic, port-scan third parties, brute-force credentials, relay malware, send spam, phish users, or generate or distribute viruses, worms, or other malicious code;
- Use our sandboxes for cryptocurrency mining, proof-of-work or proof-of-stake validation, arbitrary network-relay services (open proxies, Tor exit relays, VPN termination), or any workload that is not tied to a benchmarking use case;
- Upload or run code that is designed to exfiltrate data from our infrastructure, other customers, or third parties;
- Attempt to reverse-engineer the Service, extract source code, bypass billing, abuse free trials, or evade suspensions;
- Submit automated traffic or content that interferes with the Service’s ability to serve other customers.
To report a security vulnerability, email legal@benchwright.ai with the subject line “Security.” We appreciate good-faith disclosure and will not take action against researchers who follow this policy.
3. Data & credentials
- Do not upload personal information about other people unless you have a lawful basis to process it and their rights are respected.
- Do not upload content you are contractually or legally barred from sharing, including protected health information (PHI) subject to HIPAA or cardholder data subject to PCI DSS — the Service is not configured for these categories and is not a HIPAA Business Associate.
- Only supply API keys and other credentials that you are authorized to use. Credentials you store with us are used only as you direct and are subject to our Privacy Policy.
4. Benchmarking, red-teaming & adversarial testing
Benchwright exists to help you evaluate AI systems, including their safety properties. Adversarial benchmarking — jailbreak probes, prompt-injection tests, refusal evaluations, misuse elicitation, capability benchmarks that require eliciting potentially unsafe outputs — is a legitimate use of the Service when conducted for good-faith research, safety evaluation, or model development, and when your use otherwise complies with this AUP and with the terms of the model providers you interact with.
When you run adversarial benchmarks you are responsible for:
- Containing any harmful outputs to the benchmark run itself — do not publish, forward, or use those outputs for any harmful purpose;
- Complying with any use-case or misuse restrictions imposed by the model provider you are testing;
- Reporting material safety findings responsibly to the provider, to us (where Benchwright is implicated), and to affected parties.
We may decline to host benchmarks, or terminate runs in progress, if we determine in good faith that the benchmark is designed primarily to produce operational uplift for real-world harm (for example, detailed weapons synthesis, CBRN instructions, targeted cyber-operations against systems you don’t own). This is not a decision about the research; it is a decision about the content being generated inside our infrastructure.
5. Resale & automated access
You may build products on top of the Service. You may not repackage the Service as a competing benchmarking platform without a separate written agreement. Automated access (scripts, SDKs, API clients) must use your own account credentials and respect rate limits. Do not scrape content from other customers or from the Service itself beyond the data your account is entitled to access.
6. Enforcement
If we believe your use of the Service violates this AUP, we may (at our discretion and in addition to our rights under the Terms of Service):
- Contact you to ask for clarification or changes;
- Halt a specific run and withhold its charges only if the run itself was caused by the violation;
- Suspend your account or specific features;
- Terminate your account;
- Retain relevant logs to the extent reasonably necessary to investigate, cooperate with law enforcement, or defend ourselves in a legal matter;
- Report illegal activity to appropriate authorities.
Where we can, we will give you notice and an opportunity to cure before terminating for a violation. Where the violation is severe or presents imminent risk to others, we may act without prior notice.
7. Report abuse
To report abuse of the Service — content or runs that appear to violate this AUP — email legal@benchwright.ai with as much detail as you can share (URLs, run IDs, timestamps). We investigate every report.