Vestibo
All legal documents

Legal

Acceptable use

Acceptable Use Policy (AUP)

Version: v1.0 — 2026-07-23 Effective date: 2026-07-23

This Acceptable Use Policy ("AUP") governs your use of the Vestibo platform (the "Service") and is incorporated into the Terms of Service. Violating this AUP is a material breach of the Terms and may result in suspension or termination of your account without refund, and in serious cases reporting to law enforcement.

This AUP applies to:

  • you (the customer) as the configurator of an AI agent;
  • the AI agent you build using the Service; and
  • the end-users your agent interacts with on your behalf.

You are responsible for the conduct of your end-users where their conduct is enabled by your configuration of the Service.

1. Prohibited content and behaviour

You may not use the Service, and you may not configure an agent on the Service, to:

1.1 Illegal activity

  • Promote, facilitate, or engage in any conduct that violates any applicable law or regulation, including without limitation the TCPA, CAN-SPAM, CASL, GDPR, UK GDPR, HIPAA, PCI DSS, the Computer Fraud and Abuse Act, the UK Computer Misuse Act, EU Digital Services Act, US OFAC sanctions, or any export-control regime.

1.2 Harm to people

  • Threaten, harass, or facilitate violence against any person or group.
  • Sexually exploit, sexualise, or facilitate the abuse of any minor. Generation of CSAM is strictly prohibited and will be reported to NCMEC (in the US) or the equivalent authority.
  • Facilitate or coordinate human trafficking, terrorism, organised violence, or the planning of any of the foregoing.
  • Provide instructions or material assistance for the creation, acquisition, or use of biological, chemical, nuclear, or radiological weapons, or for attacks on critical infrastructure.
  • Encourage or facilitate suicide, self-harm, or eating disorders.

1.3 Deception

  • Impersonate another person, business, or government agency without authorisation.
  • Deceive callers about the AI nature of the agent in any jurisdiction that requires AI disclosure (including California SB 1001, the EU AI Act Art. 50, and several emerging US state laws). The Service exposes a configurable AI disclosure on every voice call; you must keep it enabled.
  • Generate content for the purpose of fraud, phishing, spear- phishing, business email compromise, romance scams, or any form of social engineering targeting another person's funds, credentials, or sensitive information.
  • Synthesise the voice, likeness, or signature of any real person (alive or recently deceased) without that person's written, documented consent. Where voice synthesis relies on a third-party provider, you must also comply with that provider's consent requirements.

1.4 Unsolicited communications

  • Send marketing or commercial SMS, calls, or emails to recipients who have not given the lawful consent required in their jurisdiction (TCPA prior express written consent, CASL express consent, GDPR/ePrivacy consent, etc.).
  • Pretend to be calling from a number you do not control or are not authorised to use. Spoofing Caller ID with intent to defraud or cause harm violates the US TRACED Act and several other laws and is forbidden.
  • Send communications that violate the recipient's documented do-not-call, do-not-text, or unsubscribe preference.

1.5 Sensitive verticals and regulated activity

  • Provide medical diagnoses, prescribe medication, or provide individualised treatment advice. The agent may take messages and schedule appointments on behalf of a healthcare provider; it may not act as the provider.
  • Provide individualised legal advice or take any action that constitutes the unauthorised practice of law.
  • Provide individualised financial advice that requires a licensed representative (broker-dealer, RIA, mortgage originator, etc.).
  • Operate as the sole channel for any emergency service (911, 999, 112). Your agent's configuration must direct callers to dial the relevant emergency number in a life-threatening situation.
  • Process Protected Health Information (PHI) without an executed BAA and without being on the HIPAA-eligible tier.
  • Process cardholder data (PCI) through the Service. The Service is not PCI-certified; route payments via Stripe or another PCI-DSS-certified processor and exchange only opaque tokens with the agent.

1.6 Infrastructure abuse

  • Attempt to gain unauthorised access to any system, account, network, or data not your own.
  • Probe, scan, or test the vulnerability of any system without prior written authorisation from its owner (see our Vulnerability Disclosure programme for authorised research).
  • Send a volume of traffic, calls, SMS, or API requests intended to overwhelm or impair the Service (denial of service) or any third-party service.
  • Reverse-engineer, decompile, or attempt to extract the source code of the Service except to the extent permitted by mandatory applicable law.
  • Use the Service to mine cryptocurrency, host content delivery for unrelated workloads, or perform other compute-abusive activities the Service is not designed for.

1.7 Model and content safety

  • Attempt to "jailbreak", manipulate, or trick the agent's guardrails, content filters, or refusal behaviour. Use the Suggested Improvements queue if you need behaviour changed.
  • Configure an agent whose system prompt or constraints knowingly cause it to violate this AUP. You are responsible for the behaviour you configure.
  • Generate non-consensual sexual content, hateful content, content that incites violence against a protected group, or content designed to harass a specific person.

1.8 Browser Agent abuse

The Browser Agent is an experimental capability, off by default and not available on every plan; the following apply where it is enabled for your account.

  • Use the Browser Agent to circumvent a website's terms of service, paywall, CAPTCHA, rate-limit, or robots.txt directive.
  • Use the Browser Agent to scrape personal data from any site that prohibits scraping in its terms of service.
  • Direct the Browser Agent at any host that is not on your configured allowlist. The Service is designed to block this where the Browser Agent is enabled; do not work around the control.

1.9 Marketplace abuse

  • Publish a marketplace template that contains malware, credentials, tenant identifiers, or PHI. Our sanitiser strips credentials, tenant identifiers, and PHI on publish, but intentionally trying to slip prohibited content through — or publishing malware — is a violation and may be rejected in review.
  • Publish a template you do not have the right to distribute.

2. Notification and enforcement

If we receive a credible report or detect activity that we reasonably believe violates this AUP, we may:

  • contact you to investigate;
  • require you to modify or remove the offending configuration;
  • suspend the affected channel, agent, or account immediately if the activity poses an imminent risk;
  • terminate your account under the Terms;
  • report the activity to law enforcement or the relevant authority (mandatory for CSAM and certain other categories);
  • preserve relevant logs for evidentiary purposes.

For urgent abuse reports, contact abuse@vestibo.com.

3. Cooperation

You agree to cooperate with our investigation of any suspected violation, including by promptly providing reasonable information about your configuration, your end-users' conduct, and the context of the suspected activity.

4. Changes

We may update this AUP from time to time to address new patterns of abuse, new laws, or new product capabilities. Material changes will be announced with at least thirty (30) days' notice through the dashboard or by email.


Changelog

  • v1.0 (2026-07-23) — first published version; rebranded to Vestibo and reconciled to the current product.
  • v0.1 (2026-05-16) — initial internal draft.

Questions? Email legal@vestibo.com.