Acceptable Use Policy
Clear security standards and prohibited activities to protect our multi-tenant community.
1. Purpose & Scope
This Acceptable Use Policy (“AUP”) outlines mandatory behavioral standards for all users of Saathi Bot. Our mission is to provide an ethical, high-performance RAG platform grounded strictly in verifiable facts. This policy protects our customers, their visitors, and our shared cloud infrastructure from abuse.
2. Strictly Prohibited Use Cases
You may not use Saathi Bot, its APIs, or its embeddable widget to engage in, promote, or facilitate any of the following:
A. Malicious Infrastructure Attacks & SSRF
- Server-Side Request Forgery (SSRF): Submitting crawler URLs that resolve to loopback, link-local, private RFC 1918 subnets, or cloud metadata endpoints (e.g.,
127.0.0.1,localhost,0.0.0.0,10.0.0.0/8,172.16.0.0/12,192.168.0.0/16, or169.254.169.254). - Cross-Tenant Exploitation: Attempting to tamper with PostgreSQL Row-Level Security (RLS) keys, forge Supabase service-role headers, or extract vector embeddings belonging to other organizations.
- Denial of Service (DoS): Flooding the streaming chat gateway or embedding pipeline with scripted queries designed to exhaust upstream API quotas or cause latency spikes.
B. Impersonation & Deceptive Practices
- Unauthorized Scraping & Brand Spoofing: Crawling or indexing websites of institutions, banks, or brands you do not own or represent, for the purpose of misleading visitors into believing your bot is an official representative.
- Phishing & Credential Harvesting: Programming bots with system prompts specifically designed to solicit credit card numbers, passwords, OTPs, or government identifiers from end-users.
C. Illegal, Harmful, or Abusive Content
- Content that constitutes, encourages, or provides instructions for criminal offenses or illegal activities under the laws of India or your local jurisdiction.
- Child Sexual Abuse Material (CSAM) or any form of child exploitation (which results in immediate termination and referral to law enforcement).
- Targeted harassment, hate speech, stalking, defamation, extortion, or non-consensual sharing of intimate media.
- Unlicensed medical diagnosis or financial investment advice masquerading as certified professional counsel.
D. Unauthorized Reselling & Commercial Abuse
- Reselling, rent-seeking, or white-labeling raw API access to third parties without prior written partnership agreement.
- Attempting to reverse-engineer our vector chunking algorithms, similarity calculation logic, or proprietary query sanitization pipelines.
3. Proactive Monitoring & Automated Safeguards
To enforce this AUP, Saathi Bot deploys automated guardrails:
- Crawler SSRF Defense: All URLs submitted for ingestion undergo DNS pre-resolution checks. Queries resolving to private IP ranges or cloud metadata endpoints are immediately rejected before any network socket is opened.
- Origin & CORS Validation: Chat widget requests from origins not explicitly whitelisted in the bot settings are rejected with HTTP 403 Forbidden.
- Confidence Gate: Low-similarity queries (< 0.55 similarity) are rejected at zero LLM cost, preventing prompt manipulation and hallucinations.
4. Violations & Enforcement
We investigate all credible reports of AUP violations. In the event of a confirmed violation, we reserve the right to take immediate action, which may include:
- Issuing a formal compliance warning.
- Disabling public access to specific crawled sources or bots.
- Immediate and permanent account suspension without refund.
- Reporting unlawful conduct to appropriate law enforcement authorities.
5. How to Report Abuse
If you believe a Saathi Bot widget on any website is violating this policy or infringing on your rights, please submit an abuse report to abuse@saathibot.com. Please include the URL of the website where the widget is installed, the offending prompt/response, and relevant evidence.