What may we not do with it?
Do not use a score, a relationship or a verdict as the sole basis for a decision about a person. Do not connect an output to an action no person decides, or work around the controls.
Scope
This policy applies to Cyberdroid AI Detection and Cyberdroid AI Investigation, the two products of the Cyberdroid SOC Platform, the AI layer of the ARRTECH Security Suite. It applies to every licensed organization and every person who uses the products on its behalf, alongside your agreement with ARRTECH.
Findings are evidence, not verdicts
A score ranks your queue and is never a verdict. A relationship in the graph does not prove intent. A case is written for a person to review.
You may not use a score, a graph relationship or a case verdict as the sole basis for a decision about a person, including discipline, dismissal, legal action, a report to an authority, or removing access other than as a security containment step. A person reviews the evidence first.
A person decides what acts
The Cyberdroid products observe, investigate and communicate. You may not connect their output, directly or through other software, to an action in your estate that runs without a person's decision. DLP policies and SOAR automations that you write are outside this clause.
Monitor lawfully
You are responsible for having the right to collect and analyze the telemetry your SIEM holds, for informing the people concerned where law or agreement requires it, and for consulting employee representatives where law requires it. You may not use the products to monitor people for any purpose other than the security of the systems you are responsible for.
Keep the controls intact
You may not try to get around the controls that decide who may ask and who may receive, impersonate an authorized requester, or configure a roster to grant authority to people not entitled to it. If you find a way around a control, report it under Responsible Disclosure.
External fallback
AI Investigation uses local models by default. Turn on the optional online fallback only for data you are permitted to send to the provider it routes to.
Early access
Use AI Investigation within the terms of your design-partner evaluation.
Reporting and enforcement
Report suspected misuse through our contact page, and a wrong or harmful output under AI Incident Reporting. A breach of this policy is handled under your agreement with ARRTECH. Each version of this policy carries an effective date.