Scope
This policy applies to everyone using Lyhnis, to every workflow, agent and API key operating in your workspace, and to anyone you grant access. It is incorporated into our Terms of Service.
You are responsible for the behaviour of automations you author, including where an agent chooses the order of the tools you gave it. "The agent did it" is not a defence.
Prohibited content and activity
Do not use the platform to store, process, transmit or generate:
- Content that is unlawful in a relevant jurisdiction, or that infringes intellectual property or privacy rights.
- Child sexual abuse material, or content that sexualises minors, in any form. This results in immediate termination and referral to authorities.
- Malware, ransomware, exploit kits, or infrastructure for phishing and credential harvesting.
- Content designed to harass, threaten or defame a specific person, or to incite violence.
- Material that facilitates fraud, money laundering, sanctions evasion, or the sale of regulated goods without authorisation.
Automation-specific limits
Because workflows run unattended and at machine speed, some conduct that is merely rude by hand becomes abusive at scale:
- No unsolicited bulk messaging. Notification activities - Slack, Teams, email, Telegram - may only be used to reach recipients who expect contact from you. No cold-outreach blasting, no list-scraping campaigns.
- No rate-limit circumvention. Do not rotate credentials, distribute requests across workspaces, or parallelise runs to exceed a third party's published limits or your own plan quotas.
- No unauthorised scraping. Do not use HTTP activities to collect data in violation of a site's terms, robots directives or applicable law.
- No load-shifting abuse. Do not use the platform primarily as a proxy, VPN, crypto miner, media-transcoding farm or general-purpose compute host.
- No infinite loops by design. Workflows that intentionally self-trigger without a terminating condition will be suspended.
Rules for agents
Agent execution deserves its own line, because it acts with judgement inside the vocabulary you give it.
Budgets, tool allow-lists and human approval gates exist so autonomous behaviour stays inside boundaries you chose. Deliberately configuring an agent with no ceiling on turns, tokens, time or cost, and then disclaiming the outcome, is a violation of this policy.
- Do not use agents to probe, enumerate or attack systems you do not own or have written permission to test.
- Do not use agents to impersonate a human where the recipient would reasonably expect a person, or to evade a platform's automation policies.
- Do not remove human approval from decisions that legally require human review - lending, hiring, insurance, medical or legal determinations among them.
- Do not use models on the platform to generate content prohibited by §02, or in breach of the model provider's own policies.
- Do not expose your tenant MCP server to untrusted clients as a way of granting anonymous access to your systems.
Security and platform integrity
- Do not attempt to access another tenant's data, ledger, credentials or files.
- Do not probe, scan or load-test the platform without prior written authorisation from security@lyhnis.com.
- Do not attempt to disable, alter or forge audit ledger entries, or to interfere with signing.
- Do not reverse engineer the engine, or use the service to build a competing execution platform.
- Do not share workspace credentials between people, or embed workspace API keys in client-side code.
Coordinated disclosure is welcome. Report findings to security@lyhnis.com; we will not pursue good-faith researchers who follow that route and avoid privacy violations, data destruction and service degradation.
Enforcement
Where we identify a violation we generally start with the smallest intervention that works: contacting you, throttling an activity, or suspending a single workflow. Where conduct creates immediate risk to the platform, to third parties or to individuals, we suspend first and explain after.
Serious or repeated violations lead to termination under the Terms. We report unlawful content to the relevant authorities where required, and we preserve the audit ledger for the retention period applicable to your plan.
Reporting
To report abuse originating from a Lyhnis workspace, email security@lyhnis.com with any message headers, workflow references, timestamps or run IDs you have. We acknowledge within one business day and will tell you the outcome to the extent we lawfully can.