Usage Policy

A finding is evidence for a person to weigh, never a verdict on anyone.

Version 1.0 · Effective Sep 23, 2026

What may we not do with it?

Do not use a score, a relationship or a verdict as the sole basis for a decision about a person. Do not connect an output to an action no person decides, or work around the controls.

The five rules. Findings are evidence: a person reviews evidence before decisions about people. A person decides: no output drives action without a person. Monitor lawfully: only to secure your own systems. Controls stay intact: respect who may ask or receive. Fallback within rights: send only data you may send.

Scope

This policy applies to Cyberdroid AI Detection and Cyberdroid AI Investigation, the two products of the Cyberdroid SOC Platform, the AI layer of the ARRTECH Security Suite. It applies to every licensed organization and every person who uses the products on its behalf, alongside your agreement with ARRTECH.

Findings are evidence, not verdicts

A score ranks your queue and is never a verdict. A relationship in the graph does not prove intent. A case is written for a person to review.

You may not use a score, a graph relationship or a case verdict as the sole basis for a decision about a person, including discipline, dismissal, legal action, a report to an authority, or removing access other than as a security containment step. A person reviews the evidence first.

A person decides what acts

The Cyberdroid products observe, investigate and communicate. You may not connect their output, directly or through other software, to an action in your estate that runs without a person's decision. DLP policies and SOAR automations that you write are outside this clause.

Monitor lawfully

You are responsible for having the right to collect and analyze the telemetry your SIEM holds, for informing the people concerned where law or agreement requires it, and for consulting employee representatives where law requires it. You may not use the products to monitor people for any purpose other than the security of the systems you are responsible for.

Keep the controls intact

You may not try to get around the controls that decide who may ask and who may receive, impersonate an authorized requester, or configure a roster to grant authority to people not entitled to it. If you find a way around a control, report it under Responsible Disclosure.

External fallback

AI Investigation uses local models by default. Turn on the optional online fallback only for data you are permitted to send to the provider it routes to.

Early access

Use AI Investigation within the terms of your design-partner evaluation.

Reporting and enforcement

Report suspected misuse through our contact page, and a wrong or harmful output under AI Incident Reporting. A breach of this policy is handled under your agreement with ARRTECH. Each version of this policy carries an effective date.

Related

AI Incident Reporting

Responsible Disclosure

Explainability

Human in Command

Data and Model Training

Contact
ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.