Acceptable Use Policy
This Acceptable Use Policy ("AUP") governs your access to and use of the TAMPERLOGS website at tamperlogssecurity.com, the TAMPERLOGS waitlist, and, upon general availability, the TAMPERLOGS chain-of-custody and audit-log platform (collectively, the "Service"), provided by PROVE iT! Forensics, LLC ("TAMPERLOGS," "we," "us," or "our"). This AUP supplements our Terms of Service. By accessing or using the Service, you agree to comply with this AUP. Violation of this AUP may result in suspension or termination of access, in addition to any other remedies available to us.
1. Purpose
TAMPERLOGS exists to create defensible, tamper-evident records of custody, transfer, and handling for physical equipment and digital evidence. Because the Service is designed to produce records that customers and third parties (including courts, auditors, and regulators) may rely on, we hold users to a higher standard of honest, accurate, and non-abusive use than a typical SaaS product.
2. Prohibited uses
You may not use the Service, or allow it to be used, to:
- Falsify, backdate, alter, or fabricate custody records, timestamps, event logs, or any data intended to represent the true history of an item or piece of evidence.
- Circumvent, disable, or attempt to defeat the append-only, tamper-evident, or audit-trail features of the Service, including by uninstalling, disabling, or interfering with the optional TAMPERLOGS endpoint agent on an enrolled device without authorization.
- Use the Service to create records for evidence, equipment, or chains of custody that do not exist, or to misrepresent the provenance of any item.
- Upload, store, or transmit content that is unlawful, infringing, defamatory, or that you do not have the right to submit.
- Access accounts, custody records, or organizations other than your own without authorization.
- Attempt to gain unauthorized access to the Service, its underlying infrastructure, other customers' data, or accounts not belonging to you (including by password guessing, credential stuffing, or exploiting vulnerabilities).
- Probe, scan, or test the vulnerability of the Service without our prior written authorization (see Section 4, Security Research).
- Introduce viruses, malware, or other harmful code, or engage in denial-of-service attacks against the Service.
- Use automated means (scraping, bots, crawlers) to access the Service outside of documented APIs, or in a way that degrades Service performance for other users.
- Reverse engineer, decompile, or attempt to derive source code from the Service, except to the extent applicable law prohibits this restriction.
- Resell, sublicense, or provide the Service to third parties as your own product, except as expressly permitted under a separate written agreement.
- Use the Service in violation of export control, sanctions, or other applicable law.
- Use the Service to build a competing product or for competitive benchmarking without our written consent.
3. Endpoint agent deployment
TAMPERLOGS offers an optional endpoint agent that your organization may install on company-owned Windows devices to report OS-level security events into your custody and audit records (see our Privacy Policy, Section 2, for exactly what it collects). If your organization chooses to deploy the endpoint agent, you agree that:
- You will only enroll devices your organization owns or is otherwise legally authorized to monitor.
- You are solely responsible for providing any notice or obtaining any consent from your own personnel that is required under the law applicable to your organization and its employees before enrolling a device they use. TAMPERLOGS does not determine what notice is legally sufficient in your jurisdiction and does not provide legal advice.
- You will not use the endpoint agent's reporting for a purpose unrelated to chain-of-custody, asset accountability, or security auditing of the enrolled device.
4. Data integrity obligations
Because chain-of-custody data may be relied upon in legal, regulatory, or audit contexts, you additionally agree that:
- You are responsible for the accuracy of data you or your users enter into the Service.
- You will promptly report any suspected tampering, unauthorized access, or integrity issue affecting your custody records to legal@tamperlogssecurity.com.
- You will not represent Service-generated reports as independently certified or notarized unless we have expressly enabled and documented such a feature.
5. Security research
We welcome good-faith security research. Before testing, contact legal@tamperlogssecurity.com to request authorization and scope. Unauthorized testing against production systems or customer data is a violation of this AUP regardless of intent.
6. Enforcement
We may investigate suspected violations and may remove content, suspend accounts, or terminate access, with or without notice, where we reasonably believe this AUP has been violated. Severe or repeated violations, or any violation that compromises the integrity of custody records, may be reported to law enforcement or affected third parties where we determine that is appropriate.
7. Reporting violations
To report a suspected violation of this AUP, contact legal@tamperlogssecurity.com.
8. Changes to this policy
We may update this AUP from time to time. Material changes will be notified as described in our Terms of Service. Continued use of the Service after changes take effect constitutes acceptance.
9. Contact
PROVE iT! Forensics, LLC, [company registered address], legal@tamperlogssecurity.com