Acceptable Use Policy
Threat intelligence is dual-use by nature. This policy draws the line between defending your organisation and doing harm with what we show you.
Effective 26 August 2026
1.The principle
Everything SINON surfaces exists because someone was harmed or is about to be. You may use it to defend your own organisation and the people who depend on it. You may not use it to cause harm, to investigate individuals, or to profit from the exposure of others.
This policy forms part of the Terms of Service.
2.Permitted use
- Detecting and responding to threats against your own organisation, brands, domains and personnel.
- Assessing risk in your supply chain and among vendors you have a legitimate relationship with.
- Informing your own incident response, security awareness and executive reporting.
- Sharing individual findings with your professional advisers, insurers, regulators, law enforcement and incident responders where reasonably necessary to act on them.
- Notifying another organisation that it appears to be affected, in good faith.
3.Prohibited use
Against people
- Looking up, monitoring, profiling or investigating a specific individual — including employees, candidates, former staff, journalists, activists, family members or any private person.
- Using findings for employment, tenancy, credit, insurance or immigration decisions about an individual.
- Stalking, harassment, doxxing, intimidation, or building a dossier on anyone.
- Any use amounting to surveillance of a population, a community, or people defined by ethnicity, religion, politics, sexuality, health status or union membership.
Against systems
- Using exposed credentials, tokens, cookies or access details to log into any system — including your own organisation’s, where you are not authorised, and including to “verify” a finding.
- Attacking, probing or testing any third party’s systems on the basis of what we surface.
- Contacting, negotiating with, paying or transacting with threat actors using our intelligence.
- Re-uploading, mirroring or redistributing leaked data we reference.
Against the service
- Reselling, sublicensing or providing the service or its output to third parties.
- Bulk-extracting platform content except through features we provide for that purpose.
- Using platform output to train machine-learning models without our prior written consent.
- Circumventing access controls, rate limits, allowlists or usage restrictions.
- Sharing credentials, or giving access to anyone outside your organisation.
- Misrepresenting your identity, organisation or purpose in order to obtain access.
Generally
- Any use that is unlawful in your jurisdiction or ours, or that would put us in breach of sanctions or export controls.
4.If you find someone else's exposure
You will sometimes see material concerning organisations that are not you. Notifying them in good faith is permitted and encouraged. Using it for competitive advantage, publishing it, or approaching them commercially on the strength of it is not.
5.Handling what you receive
- Treat findings as confidential and share them on a need-to-know basis.
- Do not publish findings, screenshots or exports publicly without our written consent.
- Remember that our sources are adversarial: a claim may be false, exaggerated or planted. Verify before you act on it, and never act against a third party on an unverified claim.
6.Enforcement
We may investigate suspected breaches and may suspend or terminate access immediately, without refund, where we reasonably believe this policy has been breached. Serious breaches — particularly those involving harm to individuals or unauthorised system access — may be reported to law enforcement.
To report misuse of SINON, contact [email protected].