Acceptable Use Policy — Security Research
Security Research 層は, 認可された合法的なセキュリティ業務のための無制限モデルを提供します. アクセスは検証済みのセキュリティ専門家に付与され, 本ポリシーに従います. 悪用は即時失効となります.
Assurance Ladder(Assurance Ladder)
各レベルが満たすべきEvidenceと, 解禁される 1 日あたりトークンAllowance. カード登録(レベル1)で無料研究枠が開き, 本人確認・ガバナンス確認(レベル2以降)で上限が上がります.
-
Payment method on file
Evidence: a live credit/debit card (prepaid rejected) verified with a $0 check
Allowance: 102400 tokens/day · 上限 102400
-
Identity verified
Evidence: Stripe Identity document + selfie check bound to the principal
Allowance: 50000 tokens/day · 上限 200000
-
Business verified
Evidence: a company on a public registry, a proven domain claim, clean screening
Allowance: 2000000 tokens/day · 上限 8000000
-
Contracted researcher
Evidence: named researchers, a signed authorized-scope statement, a contract
Allowance: 8000000 tokens/day · 上限 32000000
Allowed uses
- Vulnerability research
- Exploit and proof-of-concept (PoC) development
- Malware analysis and deobfuscation
- Reverse engineering
- Authorized phishing and social-engineering assessments
Strictly prohibited
- Child sexual abuse material (CSAM)
- Chemical, biological, radiological, nuclear weapons or other weapons of mass destruction (CBRN/WMD)
- Large-scale fraud-as-a-service
CSAM and CBRN/WMD content is strictly blocked; confirmed cases are handled through our incident and abuse process.
攻撃的機能(条件付き)
Payload and shellcode development, command-and-control (C2) tooling and weaponized exploits are permitted only inside a live engagement you have attested to — a named client, a named scope and an end date — at the contracted rung, on top of this policy.
Privacy
- Designed for zero data retention
- Request content is screened in memory
- When zero-data-retention is enabled, your content is not used for training
ローカル実行境界
- The service never executes tools, code, commands or network actions server-side; a tool call the model emits is returned to the caller as data (tool_calls) and runs, if at all, on the caller's own machine
- Tool use, command execution and automation stay entirely on the user's local machine, driven by the user's own agent
- Generated exploit or payload text is data returned to the caller — it is never run by kotoba.cloud