Skip to content

Acceptable Use Policy

Last updated: 2026-08-05

This policy sets out how the Taiga platform may and may not be used. It forms part of our platform terms and applies to everyone who accesses the platform. Where the signed services agreement contains acceptable-use provisions, those take precedence.

Who this applies to

Every person a customer organization gives access to, and anything acting on their behalf, including scripts, integrations, and agents driven through the API. The customer organization is responsible for use under its own tenant.

What is not allowed

Do not use the platform to:

  • Build, host, or operate anything unlawful, or anything intended to harm people or systems.
  • Process content you have no right to process, or that infringes someone else's rights.
  • Reach, or attempt to reach, another tenant's data, or to circumvent tenant or role boundaries.
  • Circumvent usage limits, quotas, authentication, or any technical control.
  • Reverse engineer the platform, or use it to build a competing service, except where law makes that right non-excludable.
  • Resell or provide the platform to a third party outside the terms of the signed agreement.
  • Place a load on the platform that degrades service for others, or otherwise disrupt its operation.

Using the agents

The platform's agents act on instructions and hold real credentials. Do not use them to reach systems or data you are not authorised to reach, and do not craft input intended to make an agent ignore its instructions, exfiltrate configuration or secrets, or act outside the permissions its tenant holds. Treat agent output as work to be reviewed, not as work already approved.

Security testing

Vulnerability research on the platform is welcome inside a scope agreed with us in writing. Outside such a scope, do not test. In every case: no denial of service, no access to other people's data, no destructive testing, and no social engineering of our people or our suppliers. Report anything you find to security@tai.ga; the process is in our security.txt.

Accounts and credentials

Accounts are personal to the individual they are issued to. Do not share credentials or API keys. Keep them out of source control and out of anything that logs. Tell us at security@tai.ga if you believe one has been exposed.

Enforcement

Where use breaches this policy we will normally raise it with the customer organization first. Where there is a genuine security risk, unlawful use, or a serious breach, we may suspend access, on the grounds and by the process the signed agreement sets out. We aim to suspend no more than the situation requires and to restore access as soon as it is resolved.

Changes

We may update this policy as the platform changes. The date at the top shows when it last changed. Material changes affecting an existing customer are handled under the change provisions of the signed agreement.

Contact

Questions about this policy go to hello@tai.ga

Back to the platform terms