Responsible Use Policy
Last updated: 2026-10-09
PurifySec is a defensive security product. This policy explains what it may and may not be used for. It applies to everyone who uses PurifySec, including early-access pilot partners. It is in addition to the usage policies of our model provider, Anthropic, which also apply.
1. Defensive use only
PurifySec may be used to help protect systems, for example to triage alerts, summarize incidents, analyze logs, map behavior to MITRE ATT&CK, review code for security weaknesses and draft remediation guidance and reports.
2. Authorized systems and data only
You may only submit alerts, logs, code and other data from systems that you own or are explicitly authorized to manage. You are responsible for having the rights and permissions needed to share that data with us.
3. Prohibited uses
- Penetration testing, scanning or attacking any system through PurifySec.
- Writing, improving or validating exploits or proof-of-concept attack code.
- Analyzing, creating or modifying malware, ransomware or other malicious code.
- Gaining or attempting unauthorized access to systems, accounts or data.
- Evading security controls, detection or monitoring.
- Surveillance of individuals or any use that violates privacy or applicable law.
- Using outputs to train AI models that compete with our model provider.
4. Human in the loop
PurifySec produces suggestions and drafts. It does not take actions on your systems by itself. A qualified person must review outputs before they are used for decisions, and remains responsible for those decisions. AI outputs can be wrong or incomplete.
5. Data handling
- Minimize. Share only the data needed for the task, and redact personal data and secrets where possible.
- Processing. Customer data is processed through Anthropic's Claude API to produce outputs. Under Anthropic's commercial terms, Anthropic does not use API customer content to train its models.
- Retention. Pilot data is kept only for the duration of the pilot and deleted within 30 days after it ends, unless we agree otherwise in writing.
- Access. Access to pilot data is limited to the people who need it to run the pilot.
6. Enforcement
We may suspend or end access for any use that breaks this policy, and we may report illegal activity to the relevant authorities.
7. Reporting concerns
If you believe PurifySec is being misused, or you have found a security issue in our service, contact hello@purifysec.com.