Acceptable Use Policy

Version 1.1.0 (Effective: June 25, 2026)

Acceptable Use Policy

Effective Date: June 25, 2026 Version: 1.1.0

This Acceptable Use Policy ("AUP") is provided by GridBoost, Inc., a Delaware corporation ("Provider," "we," "us," or "our"), and governs your use of the GridWonk cloud platform and related services (collectively, the "Service"). By accessing or using the Service, you ("Customer," "you," or "your") agree to comply with this AUP.


1. Purpose

This AUP establishes the rules and guidelines governing acceptable use of the Service. This AUP is incorporated by reference into the GridWonk Terms of Service (the "Agreement") and forms a binding part of the contractual relationship between Provider and Customer. Capitalized terms not defined herein have the meanings set forth in the Agreement.

Provider reserves the right to enforce this AUP to protect the integrity, security, and availability of the Service for all customers. All users of the Service, including Customer's authorized end users, employees, contractors, and agents, are bound by this AUP. Customer is responsible for ensuring that all individuals who access the Service through Customer's account comply with this AUP.


2. Permitted Use

The Service is designed for grid interconnection document analysis, validation, compliance checking, and related energy sector workflow automation. Permitted uses of the Service include, but are not limited to:

  • Document Analysis and Digitization. Uploading, processing, and analyzing interconnection applications, site control documents, engineering studies, and related energy infrastructure documentation.
  • Deficiency Identification and Remediation. Using AI-assisted tools to identify deficiencies in interconnection filings, generate remediation guidance, and track resolution progress.
  • Compliance Checking. Validating documents and data against applicable interconnection standards, utility requirements, and regulatory frameworks.
  • Workflow Automation. Leveraging the Service's automation capabilities to streamline interconnection queues, manage document workflows, and coordinate between project stakeholders.
  • Reporting and Analytics. Generating reports, dashboards, and analytical outputs related to interconnection project portfolios and operational metrics.
  • API Integration. Accessing the Service via published APIs, SDKs, CLI tools, and MCP server interfaces in accordance with the applicable API documentation and rate limits.

Customer shall use the Service only for lawful business purposes consistent with the intended functionality described above and in the Agreement.


3. Prohibited Activities

Customer shall not, and shall not permit any third party to, engage in any of the following activities in connection with the Service:

3.1 General Prohibitions

  • Illegal Activities. Using the Service to conduct, facilitate, or promote any activity that violates applicable local, state, federal, or international laws or regulations.
  • Harmful or Malicious Content. Uploading, transmitting, or distributing content that is unlawful, defamatory, harassing, threatening, obscene, or otherwise objectionable, or that contains viruses, malware, ransomware, or other harmful code.
  • Unauthorized Access. Attempting to gain unauthorized access to the Service, other customers' accounts or data, Provider's internal systems, or any third-party systems connected to the Service.
  • Service Disruption. Engaging in any activity that disrupts, degrades, impairs, or interferes with the Service's performance, availability, or functionality for other customers.
  • Scraping and Harvesting. Using automated tools, bots, crawlers, or scripts to scrape, harvest, extract, or collect data from the Service except through published APIs used in accordance with their documentation.
  • Circumventing Controls. Bypassing, disabling, or circumventing any security mechanisms, access controls, authentication requirements, rate limits, usage quotas, or other protective measures implemented by Provider.

3.2 Data Integrity Prohibitions

  • Falsifying Interconnection Data. Intentionally submitting false, misleading, or fabricated interconnection application data, engineering specifications, site control information, or environmental compliance data to the Service.
  • Fabricated Document Submission. Submitting forged, counterfeit, or materially altered documents for AI-assisted analysis with the intent to deceive utilities, regulators, or other stakeholders.
  • Misrepresentation of AI Outputs. Representing AI-generated analysis, recommendations, or outputs produced by the Service as official utility decisions, binding regulatory determinations, licensed professional engineering certifications, or stamped engineering documents. AI outputs are decision-support tools and do not constitute professional engineering opinions or official utility actions.

3.3 Regulatory Prohibitions

  • Regulatory Violations. Using the Service in a manner that violates regulations issued by the Federal Energy Regulatory Commission (FERC), the North American Electric Reliability Corporation (NERC), state public utility commissions, or other applicable energy regulatory bodies.
  • CEII Mishandling. Uploading, processing, or transmitting Critical Energy Infrastructure Information (CEII) through the Service in violation of FERC's CEII regulations (18 CFR 388.113) or without proper authorization and safeguards.
  • Export Control Violations. Using the Service in violation of U.S. export control laws, including the Export Administration Regulations (EAR) and sanctions administered by the Office of Foreign Assets Control (OFAC).

3.4 AI Model Prohibitions

  • Reverse Engineering. Reverse engineering, decompiling, disassembling, or otherwise attempting to discover the source code, algorithms, model architectures, or underlying technology of the Service's AI models or systems.
  • Model Extraction. Attempting to extract, replicate, or reconstruct model weights, parameters, training data, or fine-tuning data from the Service through any means, including systematic querying or output analysis.
  • Prompt Injection Attacks. Conducting systematic prompt injection attacks, jailbreak attempts, or adversarial input campaigns designed to manipulate, compromise, or bypass the intended behavior of the Service's AI models.
  • Competitive Model Training. Using the Service's outputs, responses, or data to train, fine-tune, develop, or improve competing AI models or services without Provider's prior written consent.

3.5 Account Prohibitions

  • Credential Sharing. Sharing account credentials, API keys, access tokens, or authentication secrets across organizations or with unauthorized individuals. Each set of credentials is assigned to a specific user or organization and must not be shared.
  • Account Proliferation. Creating multiple accounts, organizations, or identities to circumvent usage limits, access restrictions, billing obligations, or enforcement actions.
  • Impersonation. Impersonating another user, organization, utility, or regulatory body, or falsely claiming affiliation with any entity when using the Service.

3.6 Infrastructure Prohibitions

  • Intentional Overloading. Deliberately sending excessive requests, oversized payloads, or resource-intensive queries designed to overload, stress-test, or degrade the Service's infrastructure without prior written authorization from Provider.
  • Denial-of-Service Attacks. Conducting or facilitating distributed denial-of-service (DDoS) attacks, volumetric attacks, or other network-layer attacks against the Service or its supporting infrastructure.
  • Unauthorized Automated Access. Using automated systems, scripts, or tools to access the Service at rates exceeding published rate limits or in volumes exceeding authorized usage tiers without prior written approval from Provider.

4. Rate Limiting

The Service applies rate limits to API endpoints, server actions, and other interfaces as documented in the applicable API documentation and usage guidelines. Rate limits are designed to ensure fair access, maintain service quality, and protect infrastructure stability for all customers.

  • Standard Limits. All customers are subject to the default rate limits published in the API documentation. These limits apply on a per-user, per-organization, or per-API-key basis as specified.
  • Enterprise Limits. Enterprise customers with requirements exceeding standard rate limits may request higher limits through their designated account team. Elevated limits are subject to Provider's approval and may require additional fees.
  • Limit Enforcement. Requests exceeding applicable rate limits will receive standard HTTP 429 (Too Many Requests) responses. Customers should implement appropriate retry logic with exponential backoff as described in the API documentation.
  • Abuse. Sustained or systematic attempts to circumvent rate limits, including rotating credentials, distributing requests across multiple accounts, or other evasion techniques, constitute a violation of this AUP.

5. Monitoring and Enforcement

Provider monitors use of the Service for compliance with this AUP. Monitoring may include automated analysis of usage patterns, security event logging, anomaly detection, and review of reports submitted pursuant to Section 6.

5.1 Graduated Enforcement

Provider follows a graduated enforcement process for AUP violations, except where emergency action is warranted:

  1. Warning. Upon identifying a potential violation, Provider will notify Customer in writing, describe the nature of the violation, and specify a reasonable timeframe for Customer to cure the violation.
  2. Temporary Suspension. If Customer fails to cure the violation within the specified timeframe, or if a repeated violation occurs, Provider may temporarily suspend Customer's access to the Service or to the specific features involved in the violation. Provider will notify Customer of the suspension and the conditions for reinstatement.
  3. Termination. If the violation is not remediated following temporary suspension, or if the violation is of a nature that makes continued access untenable, Provider may terminate Customer's account and the Agreement in accordance with the termination provisions set forth therein.

5.2 Emergency Suspension

Notwithstanding the graduated enforcement process, Provider may immediately suspend Customer's access to the Service without prior notice if Provider reasonably determines that:

  • Customer's use poses an imminent threat to the security, integrity, or availability of the Service or its infrastructure;
  • Customer's use poses a risk of harm to other customers, their data, or third parties;
  • Customer's use may expose Provider to legal liability; or
  • Immediate action is required by law, regulation, or court order.

Provider will notify Customer as soon as reasonably practicable following any emergency suspension and will work with Customer to resolve the underlying issue.


6. Reporting Violations

If you become aware of any violation of this AUP, or any use of the Service that you believe is unauthorized, harmful, or otherwise inconsistent with this AUP, please report it promptly to:

Email: security@gridwonk.com

Reports should include, to the extent available: a description of the suspected violation, the identity of the individuals or accounts involved, relevant timestamps, and any supporting evidence. Provider will investigate all reports in a timely manner and will treat reporter identity as confidential to the extent permitted by law.


7. Changes to This Policy

Provider reserves the right to modify this AUP at any time. Provider will provide at least thirty (30) days' prior written notice before any material changes to this AUP take effect. Notice will be provided via email to the address associated with Customer's account and/or through a prominent notice within the Service.

Continued use of the Service after the effective date of any changes constitutes acceptance of the modified AUP. If Customer does not agree with a material change, Customer may terminate the Agreement in accordance with its terms before the change takes effect.


Contact

For questions about this Acceptable Use Policy, please contact:

GridBoost, Inc. Email: contact@gridwonk.com