Acceptable Use Policy
HukProof is a powerful security-testing tool. This Acceptable Use Policy (“AUP”) sets the non-negotiable rules for using it lawfully and ethically. It is part of, and incorporated into, our Terms of Service. Violating it can lead to immediate suspension or termination and, for serious abuse, preservation of evidence and referral to law enforcement.
The one rule that matters most: you may only send simulated phishing to people who are members of your own organization and whom you are authorized to test. Sending simulations to anyone else — customers, the public, friends, or personal email accounts — is strictly prohibited and may violate computer-misuse and anti-fraud laws (such as India’s Information Technology Act, the U.S. Computer Fraud and Abuse Act, and equivalents elsewhere).
1. Scope
This AUP applies to everyone who uses HukProof and to all activity conducted through the Service. Capitalized terms have the meaning given in our Terms of Service.
2. Authorized use only
You may use HukProof solely to assess and improve the security awareness of your own workforce. Before launching any campaign you must:
- have internal authorization to conduct security testing (for example, from your leadership, security, HR, or legal function, per your organization’s process);
- ensure every recipient is an employee, contractor, or comparable member of the organization that owns the account; and
- comply with all applicable employment, privacy, telecommunications, and data-protection laws, including any obligation to disclose that a simulation program exists (you need not disclose the timing of individual tests).
QR-code and poster simulations. A shared QR code — including one printed on a physical poster — is not tied to a single email address, so our automatic domain safeguard cannot restrict who scans it. You are solely responsible for ensuring any such code is displayed or distributed only within your own organization, on your own premises or channels, and only to your own authorized workforce. You must not place a shared code where members of the public or people outside your organization could scan it. By launching a QR or poster simulation you confirm you meet these conditions.
3. Prohibited targets
You must never use HukProof to send messages to:
- anyone outside your organization — including customers, partners, vendors, or the general public;
- personal or consumer email accounts (for example gmail.com, icloud.com, yahoo.com, outlook.com) or any address not on your organization’s registered domain;
- individuals you are not authorized to test, or who are located where such testing is unlawful; or
- minors or any protected group in a manner that is unlawful.
To help you stay within these bounds, HukProof restricts recipients to your organization’s registered email domain and blocks generic providers by default. You must not attempt to bypass, disable, or circumvent these controls, and doing so is a material breach.
4. Prohibited conduct
You must not use HukProof to:
- commit or facilitate actual fraud, identity theft, or financial theft;
- harvest real credentials, payment details, or personal data for any purpose other than an authorized, internal awareness test — and never to access systems or accounts without authorization;
- distribute malware, ransomware, or genuinely harmful payloads;
- harass, threaten, intimidate, discriminate against, or unlawfully retaliate against individuals;
- impersonate a real third party in a way intended to deceive for malicious gain, or infringe others’ intellectual-property, privacy, or publicity rights;
- send unsolicited bulk or commercial messages, or otherwise use the Service in violation of anti-spam laws;
- violate any law, regulation, or third-party right, or breach any contract you have with your recipients or their representatives.
5. Platform integrity
You must not:
- probe, scan, or test the vulnerability of the HukProof platform, or breach or circumvent its security or authentication, except through our responsible-disclosure process (see our Security page);
- access the Service or data you are not authorized to access, or interfere with any other customer’s use;
- place an unreasonable load on, disrupt, or overload the Service (including via automated scraping, denial-of-service, or excessive request volume);
- reverse-engineer, resell, or provide the Service to third parties except as expressly permitted.
Fair-use sending limits. To protect inbox deliverability for every customer on our shared, reputation-managed sending service, each organization has a monthly send allowance based on its active headcount. Real simulation sends count toward it; test emails and security-training emails do not. When the allowance is reached, new launches pause until it resets at the start of the next month; anything already scheduled is unaffected. You must not attempt to evade this limit — for example, by splitting one campaign across multiple accounts. The current allowance bands are set out in our fair-use sending policy.
6. Content standards
Simulation content must be limited to what is reasonably necessary for a legitimate awareness exercise. It must not contain unlawful, defamatory, hateful, or sexually explicit material, and it must not misuse third-party trademarks or brands beyond fair, non-deceptive simulation of a realistic lure for your own employees.
7. Your responsibilities for results data
Simulation results describe your employees’ behavior and may be sensitive. Use them to educate and improve — not to punish, single out, or discipline individuals in a way that is unlawful or contrary to your obligations. Handle, store, and delete results in line with the laws that apply to you and with our Privacy Policy.
8. Enforcement
We may investigate suspected violations and may suspend or terminate access, remove content, or block activity — with or without notice — to protect people and the platform. For serious abuse (for example, targeting people outside your organization or attempting real fraud), we may preserve evidence and cooperate with, or report to, the relevant authorities. Enforcement of this AUP is at our reasonable discretion, and not enforcing it in one case does not waive our right to do so in another.
9. Reporting abuse
If you believe HukProof is being misused, or you received a message you believe was sent in violation of this policy, contact us immediately at privacy@hukproof.com.