ACCEPTABLE USE POLICY — DRAFT

English working draft. Lawful business/professional use and independent downstream safety controls are fundamental requirements.

1. Authorized use only

The customer may use WAKE402 solely for lawful business or professional purposes and only with callback endpoints it owns or is authorized to use.

2. No harmful or unlawful use

The service must not be used to support fraud, malware, unauthorized access, credential theft, harassment, spam, denial-of-service, circumvention of security controls, or other activities prohibited by law.

3. No endpoint abuse

The customer must not use WAKE402 to test, scan, load-test, harass, or repeatedly contact third-party endpoints without authorization. Attempts to bypass callback validation, SSRF protection, or URL restrictions are prohibited.

4. No secrets in callback URLs

Callback URLs must not contain passwords, API keys, bearer tokens, private keys, session secrets, or other credentials. The customer must minimize personal and confidential information in URLs.

5. High-risk systems

WAKE402 must not be used as the sole safety, emergency, authorization, or timing mechanism for life-critical, medical, emergency, industrial, transport, weapons, critical-infrastructure, or comparable high-risk systems. It must not be the sole trigger for irreversible high-value transactions.

6. Downstream authorization

A WAKE402 callback is not authorization for a downstream action. The customer must implement independent authorization, approvals, spending limits, policy checks, and other safeguards appropriate to its agents’ capabilities.

7. Enforcement

WAKE402 may reject or restrict requests where a violation of this policy is reasonably suspected. The status and recovery of a payment already proven settled and mandatory law remain to be observed.