Acceptable Use Policy
Last updated: 20 July 2026
This policy sets out what you may and may not do with The Risk Register. It forms part of our Terms of Service. The short version: use the service for its intended purpose, managing your organisation's risk records, and do not put other customers, the service, or anyone's data at risk.
Use the service lawfully
- Do not use the service to break the law or to help anyone else break it.
- Do not store content in your records that you have no right to hold, including personal data you have no lawful basis to process.
- Do not upload content that is malicious (such as malware), or that infringes someone else's intellectual property or confidentiality.
Respect security and tenant isolation
- Do not attempt to access another organisation's workspace, records, or data, even if a flaw makes it technically possible. If you find such a flaw, report it to us and stop.
- Do not probe, scan, or test the service for vulnerabilities without our prior written permission.
- Do not attempt to bypass authentication or rate limits.
- Do not share account credentials. Each person using the service needs their own account.
Do not misrepresent the service
- Do not resell access to the service or offer it to third parties as your own product.
Reporting problems
If you find a security vulnerability or see this policy being broken, tell us at hello@alethrikolabs.co.uk. We appreciate responsible disclosure and will not pursue good faith security research conducted within the rules above.
Enforcement
If an account breaches this policy we may, depending on severity: warn the organisation owner, throttle or disable specific features, suspend the account, or terminate it as described in the Terms of Service. For serious risks to the service or to other customers we may suspend first and explain afterwards. Where the law requires it, we may also report unlawful activity to the relevant authorities.
Contact
Questions about this policy: hello@alethrikolabs.co.uk