Acceptable Use Policy Cyber Readiness Platform

Group-IB Cyber Readiness Platform

This Acceptable Use Policy (“AUP”) sets out the conduct rules applicable to Customer’s use of the Platform. It forms Schedule 3 to, and is incorporated into, the Agreement. Capitalized terms not defined in this AUP have the meanings given in the Agreement.

Customer is responsible for compliance with this AUP by itself, its Authorized Users (including Facilitators), and its Participants. Breach of this AUP may result in suspension or termination of access, in addition to any other remedies available under the Agreement or applicable law.

1. General Principles

The Platform must be used lawfully, in good faith, and consistently with its intended purpose: the design, delivery and assessment of cyber crisis-management exercises, attack simulations and training activities.

2. Prohibited Activities

Customer must not, and must ensure that its Authorized Users and Participants do not:

(a) use the Platform in violation of any applicable law, regulation, court order or third-party right;

(b) use the Platform to engage in fraudulent, deceptive or harmful conduct;

(c) use the Platform to test, attack, disrupt or simulate attacks against systems, networks, devices or assets that Customer does not own or is not authorized to test, beyond the scope of an Exercise scenario contained within the Platform;

(d) use the Platform to plan, facilitate or carry out actual offensive cyber operations against any third party;

(e) reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, models, algorithms or training data of the Platform, except to the extent expressly permitted by law;

(f) circumvent or attempt to circumvent any access, authentication, security or usage limit of the Platform;

(g) introduce malicious code, viruses or other harmful components into the Platform;

(h) probe, scan or test the vulnerability of the Platform, or breach Group-IB’s security or authentication measures, except under a written authorized-testing agreement with Group-IB;

(i) use the Platform to develop, train or improve a product, service, dataset or model that competes with the Platform or any Group-IB service; or

(j) resell, sublicense, lease, or otherwise commercialize access to the Platform, except as expressly permitted under Section 2.4 of the Agreement (including where Customer’s business involves providing Exercise facilitation, advisory, or similar services to its own clients).

3. Prohibited Content

Customer must not upload to, generate on, or input into the Platform any content that:

(a) infringes any intellectual-property right, image right or right of publicity of any person;

(b) constitutes confidential information or trade secrets of any third party, where Customer does not have the necessary authorization to share such information with Group-IB;

(c) contains personal data of children;

(d) contains any personal data, unless strictly necessary for the Exercise and where Customer has a valid legal basis;

(e) is unlawful, defamatory, harassing, threatening, obscene, hateful or discriminatory;

(f) contains operational details of real, ongoing security incidents that are subject to confidentiality, regulatory or law-enforcement constraints; or

(g) contains classified information or information subject to export-control or sanctions restrictions, where its transmission to Group-IB or its sub-processors would breach applicable law.

Documents uploaded for assessment and/or scenario generation (such as incident-response plans, internal policies and procedures) should be reviewed by Customer prior to upload to ensure consistency with this Section 3. Customer should avoid including unnecessary personal details, signatures, and contact information that are not relevant to the assessment.

4. Use of AI Features

The Platform incorporates artificial intelligence components. As used in this Section 4, “AI Outputs” has the meaning given in Annex A of the Agreement. In addition to the rules above, Customer must not, and must ensure that its Authorized Users and Participants do not:

(a) attempt to extract, replicate, reverse-engineer or distill the underlying AI models, prompts, weights or training data;

(b) use AI Outputs to train, fine-tune or evaluate any model that competes with the Platform or with the underlying AI services;

(c) input prompts or content designed to bypass safety or content filters, generate unlawful content, or cause the AI components to behave in a manner inconsistent with their intended purpose;

(d) misrepresent AI Outputs as having been validated or endorsed by Group-IB beyond the disclosures provided in the Outputs themselves; or

(e) rely on AI Outputs as final decisions without the Facilitator review required under Section 4.3 of the Agreement.

5. Accounts and Credentials

5.1. Authorized Users must keep their credentials confidential and must not share them with any other person. Each Authorized User must use individual credentials.

5.2. Participant access links and codes are intended only for the Participants identified by the Facilitator and must not be shared beyond the intended Exercise group.

5.3. Customer must promptly disable access for any Authorized User who no longer requires it, and notify Group-IB without undue delay of any actual or suspected unauthorized access or compromise.

6. Security Testing

Customer must report any vulnerability, bug or security concern identified in the Platform to Group-IB at https://www.group-ib.com/services/cert/ and must not publicly disclose it without Group-IB’s prior written consent.

7. Reporting Misuse

Customer must report to Group-IB any breach of this AUP of which it becomes aware, whether by an Authorized User, a Participant or a third party, and cooperate with Group-IB in addressing the breach.

8. Enforcement

8.1. Group-IB may investigate suspected breaches of this AUP and may, in its reasonable discretion:

(a) request information and cooperation from Customer;

(b) suspend access of specific Authorized Users, sessions, scenarios or the Platform as a whole;

(c) remove or quarantine offending content; and

(d) terminate the Agreement in case of material or repeated breach, in accordance with Section 12.

8.2. Group-IB will provide notice of enforcement actions where reasonably possible. Where prior notice is not practicable for security or legal reasons, notice will be provided as soon as possible thereafter.

9. Updates to this AUP

Group-IB may update this AUP from time to time, on prior notice, to reflect changes in the Platform, the threat landscape, applicable law or industry practice. Continued use of the Platform after the effective date of an update constitutes acceptance of the updated AUP.