BRidge™ Acceptable Use Policy (AUP)

Effective Date: October 6, 2025 • Version: 1.0
This AUP is part of the Terms of Use and EULA.

Contents

1) Scope & Lawful Use

  1. You may access BRidge solely for legitimate, lawful commercial purposes consistent with applicable laws and your internal policies.
  2. You must comply with anti-corruption, sanctions, antitrust/competition, export controls, and record-keeping obligations.
  3. High-risk exclusions. Do not use BRidge in environments where failure could reasonably lead to death, personal injury, or severe environmental damage (e.g., life-support, emergency services).
  4. Where regional privacy or data obligations provide additional rights or duties, those apply as set out in the Privacy Policy, Data Processing Addendum, and any jurisdictional appendices (e.g., APAC & Canada).

2) Account Security & Access Controls

  1. Protect authentication factors (passwords, API keys, OAuth clients, signing secrets). Do not share beyond least privilege.
  2. Use only assigned roles and entitlements; do not bypass authentication, authorization, rate-limits, idempotency, or kill switches.
  3. You are responsible for the actions of users, service accounts, and automated clients under your tenant.

3) System Integrity & Abuse

  1. Do not introduce malware, exploits, or excessive load intended to degrade BRidge or third-party services.
  2. Do not probe, scan, or test shared production endpoints without a written Safe-Harbor scope grant; no DoS or traffic flooding.
  3. Do not attempt to access data or endpoints you are not authorized to access; do not disable logging, audit chains, or integrity seals.
  4. Monitoring. You consent to operational monitoring, logging, and rate-limiting necessary to secure and operate the service. See Subprocessors for infrastructure vendors and safeguards.

4) Prohibited Content & Conduct

  1. No illegal content; no threats, harassment, hate, or privacy violations (including doxxing).
  2. No infringement or misappropriation of IP; follow the posted notice/takedown process (e.g., DMCA) in the Terms.
  3. No deceptive practices, identity misrepresentation, or falsification of business records (including BOLs, signatures, customs/tax forms).

5) Market Integrity & Data Usage

  1. No manipulation. Prohibit spoof-like behavior, wash-like trading, artificial volume, or other schemes designed to move prices or indices.
  2. Reference & Derived Data. Unless explicitly licensed for redistribution, BRidge reference prices, indices, and derived outputs are for internal operational use only.
  3. Surveillance & audit. Do not tamper with surveillance signals, audit logs, or settlement/mark processes.
  4. Metering & fees. Do not circumvent metering, billing, or usage-based fees (e.g., rotating identities or masking origins to evade limits).

6) APIs, Automation & Fair Use

  1. Identify automated clients via a standard User-Agent and, where feasible, include contact info for operations.
  2. Honor published rate-limits, idempotency keys, pagination, and backoff policies; BRidge may throttle or block abusive patterns.
  3. No automated account creation or credential stuffing; no scraping/bulk extraction beyond documented exports/APIs.

7) Data Protection, Privacy & Transfers

  1. Handle personal data and Customer Content in accordance with your contracts (Terms, DPA) and the Privacy Policy, including cross-border transfer safeguards and regional appendices.
  2. You are responsible for subprocessors and integrations you enable in your environment (e.g., webhooks, exports) and must ensure those third parties meet your compliance obligations. Atlas’ authorized infrastructure subprocessors are listed on the Subprocessors page.
  3. Do not upload sensitive data categories unless contractually permitted and protected by suitable controls.

8) Sanctions, KYC/AML & Export

  1. Do not use BRidge for or on behalf of sanctioned parties or embargoed jurisdictions; do not attempt to evade KYC/AML obligations.
  2. Follow export control laws for software/data transfers, including re-exports and deemed exports; implement regional restrictions as required.

9) Security Research (Limited Safe Harbor)

  1. Good-faith testing within your tenant that does not harm other tenants is permitted. Do not test shared production endpoints, perform DoS, or access data you do not own.
  2. Report vulnerabilities to info@atlasipholdingsllc.com; Atlas will not pursue legal action for good-faith reports that follow this AUP and coordinated-disclosure practices.
  3. Atlas may revoke Safe Harbor if activity degrades service or risks data.

10) Incident Reporting & Cooperation

  1. If you suspect account compromise, data leakage, or integrity issues (e.g., settlement marks, audit chain), notify Atlas without undue delay at info@atlasipholdingsllc.com.
  2. You will cooperate in reasonable investigations, including providing relevant request IDs, headers, client versions, or automation fingerprints.

11) Enforcement Ladder

  1. Atlas may apply a progressive ladder proportionate to risk and harm: warning → temporary throttling → suspension → termination.
  2. Severe abuses (e.g., exploitation, data exfiltration, sanctions evasion, destructive automation) may result in immediate suspension and referral to authorities.
  3. Reinstatement may require remediation steps (key rotation, re-KYC, risk plans, or attestations).

12) Changes to this AUP

  1. Atlas may update this AUP to reflect new features, risk controls, regulatory changes, or infrastructure changes.
  2. Updates will be posted on the legal site; where required, Atlas will provide advance notice consistent with the change-management approach in your legal pages.

13) Definitions (Summary)

Customer Content
Data you upload or generate in BRidge (e.g., contracts, BOLs, inventory, indices inputs).
Derived Data
Outputs generated by BRidge (e.g., indices snapshots, reference-price transforms, forecasts).
Reference Prices
Third-party or internal basis prices surfaced for operational use.
Tenant
Your BRidge organizational account and all associated users, roles, and integrations.