Skip to content

Korenact / Legal

Acceptable use policy

Keep Korenact useful, authorized, and accountable to the people your organization serves.

Review draft · October 4, 2026

Policy preview. These documents are being finalized for commercial launch. Operator details and deployment-specific terms require confirmation. Any approved pilot is governed by its signed agreement.

1. Use the service with authority

Only access accounts, contact records, calendars, and other systems you are authorized to use. Obtain appropriate permission before processing someone’s information or making changes on their behalf. Do not impersonate another person or organization or misrepresent the assistant as a qualified human professional.

2. Respect communication choices

Do not use the service for spam, harassment, scams, deceptive solicitations, or communications that violate applicable consent, do-not-call, or messaging requirements. Your organization is responsible for the notices, permissions, sender identity, and opt-out processes required for its channels and audience.

3. Protect access and private information

Do not attempt to bypass verification, approval rules, organization boundaries, rate limits, or other access controls. Do not upload stolen data, secrets, payment-card credentials, or information you lack authority to process. Restrict sensitive data to an explicitly reviewed and approved workflow.

4. Keep consequential decisions supervised

Do not rely on Korenact to provide emergency assistance or independently make clinical, legal, financial, eligibility, tenant-screening, employment, or other consequential decisions about a person. Use appropriately qualified staff and a reviewed process for those decisions. An escalation queue does not replace your emergency response or staffed support process.

5. Do not compromise the service

Do not distribute malware, interfere with other organizations’ service, probe systems without permission, extract other users’ information, evade usage restrictions, or deliberately overload the platform or its connected services. Security testing must be authorized in advance and limited to its agreed scope.

6. Use accurate content and lawful workflows

Maintain current, authorized knowledge and workflow instructions. Respect intellectual-property rights and do not configure unlawful, abusive, discriminatory, or deceptive behavior. Review responses and action records and correct a configuration that repeatedly produces unsafe or inaccurate results.

7. Report and address misuse

If you discover misuse or a security concern, stop the affected workflow where appropriate and request a private follow-up through our contact page with a concise description. Avoid including exploit payloads, secrets, or private customer records in an initial report. Access restrictions, remediation, and contractual consequences are governed by the applicable service agreement and law.