Legal
Acceptable Use Policy
Short, because it is a read-only blockchain API on a single host in a free beta. Each rule below exists for a reason and the reason is given, so you can tell which ones are about protecting the service and which are about protecting other people.
Do not attack the service
- Do not try to exceed your limits by creating accounts, projects or keys to get round them. The limits are published on Limits and an operator will raise one if you ask and it is reasonable.
- Do not probe for vulnerabilities without telling us first. If you find one, security.txt is how to report it, and a report is read by somebody who can act on it.
- Do not try to read another customer’s data. If you find a way to, that is a security report and we would rather have it than not.
- Do not automate sign-up. One account per person or organization.
These protect a service everybody else is using. A single host has one pool of capacity and there is no isolation that survives somebody determined to exhaust it.
Do not use it to harm anybody else
- Do not use the API to support activity that is illegal where you are or where we are.
- Do not use it to surveil people who have not agreed to it. Reading a public chain is public; building a profile of an individual from it is a different thing, and this is not the tool for it.
- Do not present StoneReason’s answers as something they are not. Every answer says how strongly it is established; stripping that and selling the number as verified is misrepresenting somebody else’s work.
Do not misuse credentials
- Do not share an API key outside the organization it was issued to. Add a member instead, so what happens is attributable.
- Do not embed a key in a public client — a mobile app, a browser bundle, a public repository. A key in a browser is a key everybody has.
- Do not use an account you were not given.
What is fine
Stated because a policy that only lists prohibitions leaves people guessing:
- Building a commercial product on the Beta. Nothing here is priced and nothing stops you.
- Benchmarking, within your limits. If you want more for a load test, ask; an operator can raise a limit with an expiry.
- Writing about what the API does, including what it does badly.
- Reading every public document, endpoint and generated artefact here.
What happens if a rule is broken
Proportionate, and in this order where there is a choice:
- We tell you. Most breaches are accidents — a key in a repository, a retry loop with no backoff.
- We narrow or suspend a key, a project or an organization. Suspension is reversible and is recorded in the admin audit with the reason.
- We close the account for deliberate attacks or for use that is harming other people.
Where an account is suspended you will be told which rule and why, unless telling you would itself be a problem.
Reporting misuse
If somebody is using StoneReason against you, tell us: security@stonereason.com. Include what you saw and when. We can act on our own service; we cannot act on a blockchain, and we will say so rather than implying otherwise.
This policy is part of the Terms of Service.