Skip to content
ProductSourcesCapabilitiesDevelopersPricingTrust
Sign InSee how it works

Legal / aup-2026-08-12

FINA1 Acceptable Use Policy

Platform-wide rules for authorized, lawful, secure, and non-harmful use.

Terms of Service↗Privacy Policy
Terms of ServicePrivacy PolicyAcceptable Use PolicyCustomer-Directed Source Access TermsSource Access AttestationData Processing AddendumCopyright and Source Rights PolicySubprocessor List

Effective Date: August 12, 2026 Version: aup-2026-08-12

This Acceptable Use Policy (“AUP”) applies to all access to and use of FINA1 websites, applications, APIs, Model Context Protocol interfaces, and ZENITH by FINA1 (collectively, the “Service”). This AUP forms part of the FINA1 Terms of Service and any applicable Order Form.

Customer is responsible for the conduct of its users, applications, API clients, MCP clients, credentials, agents, and integrations.

1. General standard

You may use the Service only for lawful, authorized, non-harmful business and professional purposes consistent with the Agreement, applicable law, third-party rights, Source terms, licenses, and technical restrictions.

Technical availability does not create legal authority. A Source operation appearing in a catalog does not mean that every customer is authorized to access or use that Source or its content.

2. Unauthorized access and circumvention

You may not use the Service to:

  • access or attempt to access an account, Source, system, network, database, document, credential, or information without authorization;
  • use credentials, API keys, tokens, cookies, licenses, subscriptions, or accounts that you are not authorized to use;
  • bypass or attempt to bypass CAPTCHA, paywalls, login gates, access controls, anti-bot systems, rate restrictions, geographic restrictions, robots protections, license controls, or other technical protection measures;
  • conceal or falsify the identity, authority, origin, or purpose of a request to defeat a Source restriction;
  • perform credential stuffing, password spraying, brute-force access, session hijacking, or account takeover; or
  • direct Zenith to perform an operation after you know or reasonably should know that your authorization has expired or been revoked.

3. Security abuse

You may not:

  • introduce malware, ransomware, spyware, malicious code, destructive payloads, or unauthorized persistence;
  • exploit or attempt to exploit a vulnerability without FINA1’s prior written authorization;
  • scan, probe, fuzz, benchmark for attack purposes, or conduct penetration testing against FINA1, Zenith, a Source, or another customer without express authorization;
  • interfere with, degrade, disrupt, or overload the Service or a Source;
  • attempt to defeat tenant isolation, role controls, rate limits, quotas, metering, billing controls, audit logging, safety checks, or authorization decisions;
  • exfiltrate secrets, credentials, tokens, private keys, cookies, session material, or other protected information; or
  • use the Service to develop, distribute, or operate tooling primarily intended for unauthorized intrusion, evasion, credential theft, destructive action, or abuse.

Good-faith security research requires prior written authorization and must remain within the approved scope.

4. Harmful, fraudulent, or unlawful conduct

You may not use the Service for:

  • fraud, deception, identity theft, impersonation, phishing, or social engineering;
  • stalking, harassment, threats, extortion, doxxing, or unlawful surveillance;
  • discrimination prohibited by law;
  • trafficking, exploitation, or other criminal activity;
  • infringement or misappropriation of intellectual property, privacy, publicity, confidentiality, database, trade-secret, or contractual rights;
  • unlawful collection, use, disclosure, sale, or sharing of personal data;
  • evasion of court orders, regulatory restrictions, sanctions, export controls, or lawful access restrictions; or
  • any activity that creates a material risk of harm to a person, Source, customer, infrastructure provider, or the Service.

5. Consequential and high-impact actions

Unless a separate written agreement and an operation-specific policy expressly authorize the activity, you may not use the Service to execute or automatically cause:

  • securities, futures, options, digital-asset, foreign-exchange, or other financial trades;
  • wagers, bets, gaming transactions, or sportsbook actions;
  • transfers of money, funds, assets, or property;
  • medical diagnosis, treatment, or emergency action;
  • legal filings, legal representation, or binding legal decisions;
  • employment, housing, credit, insurance, education-admission, benefits, or other high-impact eligibility decisions;
  • physical control of vehicles, industrial systems, weapons, security systems, or other safety-critical equipment; or
  • destructive, write-capable, account-changing, purchasing, publishing, or external-communication actions.

The Service may provide informational or analytical outputs relating to regulated or consequential domains. You remain responsible for independent review and lawful human decision-making.

6. Third-party Sources and credentials

When you direct Source access, you must comply with the Customer-Directed Source Access Terms and Source Access Attestation.

You may not:

  • misrepresent FINA1 or Zenith as endorsed by, affiliated with, or acting for a Source;
  • use Source content beyond rights you possess;
  • remove Source attribution or provenance where required;
  • store, cache, publish, sell, sublicense, or redistribute Source content in violation of law, Source terms, license restrictions, or the applicable operation policy;
  • use one customer’s Source credential for another customer or person; or
  • request background harvesting or continuous collection outside an expressly approved product or written agreement.

7. Scraping, automation, and collection

Automation is permitted only where the underlying operation is authorized, technically supported, and consistent with the Agreement.

You may not use the Service to conduct indiscriminate harvesting, unauthorized bulk collection, credential-gated scraping without authority, access-control circumvention, or automated collection that materially burdens a Source or violates applicable restrictions.

FINA1 may impose rate limits, concurrency limits, call weights, pagination limits, quotas, caching restrictions, or other controls to protect the Service and Sources.

8. Personal data and regulated information

You may not intentionally submit or process through the Service:

  • children’s personal data;
  • protected health information subject to HIPAA;
  • full payment-card data intended to place FINA1 inside cardholder-data scope;
  • biometric identifiers used for identification;
  • government-issued identification numbers;
  • precise financial-account credentials; or
  • special-category or similarly sensitive personal data,

unless the applicable Order Form or product specification expressly permits the category and required legal and technical safeguards are in place.

If an authorized Source response incidentally contains sensitive information, you must handle it lawfully and in accordance with any applicable Source restrictions.

9. Intellectual property and reverse engineering

Except to the extent applicable law provides a non-waivable right, you may not:

  • reverse engineer, decompile, disassemble, reconstruct, or derive source code from the Service;
  • copy or reproduce proprietary FINA1 interfaces, documentation, schemas, or implementation details to build a competing substitute service;
  • remove proprietary notices;
  • misuse FINA1 or Zenith trademarks; or
  • use Service access to train or benchmark a competing product in a manner that violates the Agreement or misappropriates FINA1 Confidential Information.

This Section does not restrict lawful analysis of customer-owned outputs or third-party materials where Customer otherwise has the necessary rights.

10. Rate, metering, and commercial abuse

You may not:

  • evade or manipulate usage metering;
  • rotate accounts, organizations, keys, or identities to defeat rate limits or plan limits;
  • resell account access or seats except under an agreement permitting resale;
  • use automation to obtain unpaid Service capacity;
  • interfere with billing or entitlement records; or
  • exploit an obvious pricing, metering, or entitlement defect after becoming aware of it.

If you believe a metering or billing error exists, use the dispute process in the Agreement rather than attempting to bypass controls.

11. Sanctions and export controls

You may not use or provide the Service in a manner prohibited by U.S. economic sanctions, export controls, or applicable trade restrictions. You may not provide the Service to a person or entity when doing so would violate restrictions administered by the U.S. Department of the Treasury’s Office of Foreign Assets Control or the U.S. Department of Commerce’s Bureau of Industry and Security.

FINA1 may request information reasonably necessary to evaluate sanctions or export-control risk and may restrict access where required by law.

12. Misrepresentation and source integrity

You may not:

  • falsify provenance, freshness, record counts, request identifiers, normalization versions, or Source identity;
  • present normalized or derived data as an official Source record when it is not;
  • remove warnings or limitations in a manner that materially misleads downstream users; or
  • imply that FINA1 has licensed, endorsed, certified, or guaranteed third-party materials where no such representation is expressly made.

13. Enforcement

FINA1 may investigate suspected violations and may throttle, reject, suspend, quarantine, revoke credentials, disable an integration, preserve relevant evidence, or terminate access where reasonably necessary.

Where practicable, FINA1 will provide notice and an opportunity to cure a remediable non-emergency violation. Immediate action may be taken for security threats, unlawful activity, unauthorized credentials, Source complaints, sanctions risk, destructive conduct, fraud, or other material risk.

FINA1 may report unlawful conduct or respond to lawful requests where required or permitted by law.

14. No waiver of Source or legal restrictions

A FINA1 authorization decision, successful request, paid subscription, catalog entry, or technical capability does not waive or override a Source’s rights, applicable law, contractual obligations, or restrictions binding on Customer.

15. Reporting concerns

Security, abuse, intellectual-property, Source-rights, and other policy concerns may be submitted through the applicable reporting or legal/contact mechanism identified in the Service or the legal/contact section of fina1.com.

FINA1 is the public-facing technology company. ZENITH by FINA1 is its flagship secure API and MCP platform.

Production. Production customer identity and control-plane infrastructure are available. Billing and Source execution remain independently policy- and configuration-gated.

Explore

ProductSourcesCapabilitiesPricing

Build

DevelopersMCPIdeas & RequestsRequest an API

Assurance

SecurityTrustStatusResponsible Disclosure

FINA1

AboutContactPrivacyTermsAcceptable UseSource Access Terms
© 2026 FINA1. Controlling legal documents effective August 12, 2026.Every Source. One Zenith.