Acceptable Use Policy
3.1Introduction
This Acceptable Use Policy (“AUP”) governs the use of the Raasel software (“Software” or “Raasel”) provided by Raseen Labs. It is incorporated by reference into our Terms of Service.
By using the Software, Customer and its End Users agree to comply with this AUP. Customer is responsible for ensuring that all End Users of its Raasel deployment comply with this AUP.
Violations of this AUP may result in suspension or termination of Customer's license to use the Software, as set out in §1.11 of the Terms of Service.
3.2Scope
This AUP applies to:
- the Customer (the organization or individual that has obtained a license to use the Software);
- End Users (individuals authorized by Customer to use Customer's Raasel deployment);
- any third party accessing the Software through Customer's deployment.
Because Raasel is self-hosted, Customer is primarily responsible for enforcing this AUP within its own deployment. Customer must implement reasonable policies and technical measures to monitor for, prevent, and respond to violations by End Users.
3.3Acceptable Use
You may use the Software:
- for lawful business or personal communications;
- in accordance with the Terms of Service, this AUP, and all applicable laws;
- in a manner consistent with the security and integrity of the Software and Customer Infrastructure.
3.4Prohibited Activities
You may not use the Software, or permit any End User to use the Software, to:
3.4.1Engage in unlawful activity
- transmit, store, distribute, or facilitate any content or communication that is illegal under applicable law, including child sexual abuse material, terrorism content, or content inciting violence;
- engage in fraud, identity theft, money laundering, or other financial crimes;
- infringe any third party's intellectual property rights (copyright, trademark, patent, trade secret) without authorization;
- defame, harass, threaten, or stalk individuals or organizations;
- violate any privacy or data-protection laws applicable to the communications transmitted;
- violate any applicable sanctions or export-control laws.
3.4.2Misuse security and encryption features
- attempt to circumvent or disable the Software's encryption or other security mechanisms (except for authorized security research conducted in accordance with §3.5);
- use the Software to facilitate or conceal any criminal activity, including the planning or coordination of unlawful acts;
- claim or imply that Raseen Labs can decrypt End User communications (it cannot, by design, in a properly configured Raasel deployment);
- use the Software to provide false assurances to End Users about the security or privacy of their communications.
3.4.3Violate the security and integrity of systems
- attempt unauthorized access to Customer Infrastructure, Raseen Labs systems, or any third-party system in connection with use of the Software;
- transmit malware, viruses, ransomware, worms, trojans, or any other malicious code through the Software;
- conduct denial-of-service attacks, port scans, or other intrusive network activity through or against systems running the Software;
- exploit, attempt to exploit, or disclose security vulnerabilities in the Software except through the responsible-disclosure process described in §3.7.
3.4.4Impersonate or mislead
- impersonate any person or entity, including Raseen Labs personnel;
- misrepresent affiliation with any person or entity;
- forge headers, falsify identifiers, or otherwise disguise the origin of any communication transmitted through the Software;
- claim or imply endorsement, sponsorship, or affiliation with Raseen Labs without permission.
3.4.5Send spam or engage in abusive automation
- send bulk unsolicited messages (spam);
- engage in phishing, social engineering, or similar deceptive practices;
- use automated tools to register accounts or send messages at a scale that disrupts other users or the Software's normal operation;
- use the Software to host or distribute commercial spam infrastructure.
3.4.6Misuse third-party components
- violate the licenses of any open-source or third-party components incorporated into the Software;
- remove, alter, or obscure any attribution, license notice, or copyright notice required by third-party components.
3.5Encryption Policy
The Software uses end-to-end encryption (E2EE) to protect End User communications, using the Matrix Olm and Megolm protocols inherited from Element X. As a result, Raseen Labs cannot read End User messages or files transmitted through a properly configured Raasel deployment.
Customer acknowledges that:
- Customer is responsible for configuring the Software in accordance with the Documentation. Misconfiguration may compromise E2EE.
- Customer is responsible for compliance with any applicable laws of the jurisdictions in which it operates regarding lawful interception, key escrow, or content monitoring. Some jurisdictions impose obligations on operators of communication services that may affect Customer's deployment.
- Raseen Labs does not operate a backdoor or key-escrow capability, and does not hold any master key or shared secret that would allow Raseen Labs to decrypt End User communications.
- Customer-controlled key backup. Customer may optionally enable Customer-controlled key backup in its Raasel deployment (Matrix Server-Side Key Backup or equivalent). In such configurations, key material is held under Customer's control on Customer Infrastructure, encrypted by a recovery key that Raseen Labs does not possess. Raseen Labs has no access to keys held by Customer, in backup or otherwise.
- Customer responsibility. Where Customer enables key backup or other key-recovery mechanisms, Customer is responsible for the security and lawful operation of those mechanisms.
3.6Content Moderation
Because Raasel is self-hosted, Customer is responsible for content moderation within its own deployment. Customer should:
- establish and publish to End Users a clear acceptable-use policy consistent with this AUP;
- provide End Users with mechanisms to report abuse, harassment, or other violations within Customer's deployment;
- respond to credible reports of violations in a timely manner;
- implement administrative controls (e.g., room moderation, user removal) appropriate to the deployment.
Raseen Labs does not moderate End User content. Raseen Labs has no visibility into End User communications under the self-hosted model.
3.7Reporting Violations
3.7.1Violations within Customer's deployment
End Users should report violations of this AUP that occur within Customer's deployment to Customer's designated point of contact, in accordance with Customer's internal policies.
3.7.2Security vulnerabilities in the Software
If you discover a security vulnerability in the Software itself (as distinct from a Customer's deployment), please report it confidentially to:
security@raseenlabs.com
We follow a responsible-disclosure process. We aim to:
- acknowledge receipt within seventy-two (72) business hours;
- provide a preliminary assessment within seven (7) business days;
- coordinate disclosure timing with the reporter where appropriate;
- credit the reporter in security advisories (unless requested otherwise).
We do not currently offer a paid bug bounty program. Reporters may be acknowledged in security advisories (“hall of fame”) subject to their preference.
3.7.3Violations involving Raseen Labs (the company)
If you believe Raseen Labs is itself violating this AUP, the Terms of Service, or applicable law, contact us at legal@raseenlabs.com.
3.8Enforcement and Consequences
Raseen Labs may, in its sole discretion and without prior notice, take any of the following actions in response to a violation of this AUP by Customer or in connection with Customer's deployment:
- request that Customer investigate and remedy the violation;
- suspend Customer's license to use the Software pending remediation;
- terminate Customer's license to use the Software in accordance with §1.11 of the Terms of Service;
- report the violation to law enforcement or other authorities where required by law or appropriate given the nature of the violation;
- pursue any other legal or equitable remedies available.
In severe cases involving imminent threats to safety, security, or the lawful interests of third parties, Raseen Labs may act immediately and without prior notice.
Suspension or termination under this AUP does not relieve Customer of any obligations under the Terms of Service, including payment obligations.
3.9Changes to This Policy
Raseen Labs may update this AUP from time to time. We will notify Customer of material changes in accordance with §0.7 of the website integration spec. Continued use of the Software after the effective date of the updated AUP constitutes acceptance.
3.10Contact
Questions about this AUP can be directed to:
Raseen Technology Labs Ltd
aup@raseenlabs.com