Skip to content

Legal

Acceptable Use Policy

What you may not do with Waltz, so the Service stays secure, lawful and fair to the people it describes.

Draft · Last updated

Draft for counsel's review. Not yet in effect.

1. Scope

This policy applies to everyone who uses the Service under an organization's account: owners, admins, members, viewers, and anyone using a CLI or MCP token. It is part of the Terms of Service. Words defined there have the same meaning here.

2. Connect only what you may connect

  • Connect only systems, repositories and workspaces your organization owns or is authorized to connect to Waltz.
  • Don't connect another company's systems, or a tenant your organization doesn't control.
  • Upload an org chart and recipient lists only for people you have a lawful basis to include.
  • Don't send Waltz special category data (for example health data) or data about children.

3. Use Briefs fairly

Waltz describes how software is built and how it changes. It is designed not to measure individuals.

  • Don't use the Service, or its Output, as the sole basis for decisions about an individual's hiring, pay, promotion, discipline or dismissal. [Counsel to decide whether this belongs here, in the Terms, or both.]
  • Don't use the Service to monitor individuals in ways the law where they work forbids, or without the notice or consultation that law requires.
  • Don't try to work out an individual's identity from hashed identities or team-level Briefs when your org's settings don't name individuals.
  • Don't try to work out another organization's data from pooled benchmarks.

4. Keep the Service secure

  • Don't try to access another org's data, or any account, token or system you aren't authorized to use.
  • Don't probe, scan or test the Service's vulnerabilities except under section 6.
  • Don't try to escape, modify or misuse the analysis runner, or use it to run code or reach systems other than the analysis it performs.
  • Don't place malware, or content designed to manipulate the analysis or a language model (for example prompt injection aimed at another reader), in repositories, tickets or documents you connect.
  • Don't share sign-in links, Brief links, CLI tokens or MCP tokens with people who shouldn't have them. Use guest links where your admin allows sharing outside the org.

5. Don't abuse the Service

  • Don't exceed rate limits, or send traffic meant to degrade the Service.
  • Don't scrape the Service, or access it by automated means other than the documented APIs, the CLI and the MCP server.
  • Don't misrepresent seat counts, for example by marking human contributors as bots, or routing human work through bot accounts to avoid seats.
  • Don't resell, sublicense or offer the Service to third parties, or use it to build a competing product.
  • Don't use the Service for anything unlawful, or to infringe others' rights.
  • Don't use Waltz's email delivery to send mail to people who aren't part of your organization's use of Briefs, or to send unsolicited messages.

6. Security research

We welcome reports of vulnerabilities at [security@waltz.run]. When testing, use only your own org and accounts, don't access or change other customers' data, don't degrade the Service, and give us reasonable time to fix an issue before you disclose it. [Counsel to decide whether to add a safe-harbour statement.]

7. Enforcement

If we believe this policy has been broken, we may remove access for a token or member, disconnect an integration, or suspend the org, as the Terms of Service describe. We'll tell the org's admins where we lawfully and safely can, and restore access when the issue is fixed.

8. Reporting abuse

Report abuse of the Service to [abuse@waltz.run].