Acceptable Use Policy
Version 1.0 · Last updated 23 September 2026
This policy is part of the Terms of Service. It exists to protect the service, the other MSPs who share it, and the people whose systems the service connects to. The short version: monitor only what you are entitled to monitor, do not interfere with the service, and do not use it to break the law.
1. Only monitor what you are entitled to monitor
The service connects to the servers behind every domain you add, and reads public records about them. You may add a domain only if you own it, if the client that owns it has authorised you to manage or monitor it, or if you are otherwise legally entitled to do so. You must remove a domain when that authority ends, for example when a client leaves you.
You must not use the service to survey, probe or gather information about domains, organisations or infrastructure you have no relationship with, whether out of curiosity, for research, for sales prospecting, or for any other purpose.
Why this matters
Connecting to a server without authority may be an offence under the Computer Misuse Act 1990 and similar laws elsewhere. You are responsible for the domains in your workspace, and section 5 of the Terms of Service makes you liable to us for any claim that arises from one that should not have been there.
2. Connected systems
When you connect a PSA or any other system, you must have the right to grant that access, and you must use credentials that belong to your business and that you are permitted to use. You must not connect a system in a way that breaches its own terms of use.
3. Do not interfere with the service
You must not, and must not let anyone else:
- try to access another customer's workspace or data, or test whether you can;
- probe, scan or test the service for vulnerabilities, except as permitted by our vulnerability disclosure policy;
- bypass or interfere with rate limits, authentication, tenant separation or any other security control;
- place unreasonable load on the service, for example by automating requests at a rate no person would, or by adding domains in bulk that you do not intend to monitor;
- introduce malware, or content that is unlawful, defamatory or infringes anyone's rights;
- copy, scrape, reverse engineer or build a competing product from the service, its data or its documentation, except where the law allows this regardless of contract.
4. Accounts
Each user must have their own login. Do not share credentials, and do not let someone who has left your business keep access. Do not create more than one workspace to obtain extra trials, founder pricing or plan limits. Do not impersonate another person or business.
5. Reselling
Your subscription is for your business and its clients. You may use the service's reports and alerts as part of the managed services you sell to your clients. You may not resell, sublicense or provide the service itself to third parties, or run it as a service for other MSPs, without our written agreement.
6. Lawful use
You must comply with all laws that apply to your use of the service, including data protection, computer misuse, export control and sanctions law. You must not use the service in a country or for a person to which UK sanctions prohibit the supply of services.
7. What happens if this policy is broken
If we reasonably believe this policy has been broken, we may remove the offending domains or content, suspend the affected users or the workspace, or end the Agreement, as described in sections 19 and 20 of the Terms of Service. We will tell you what we have done and why, unless the law prevents it or telling you would put the service or others at risk. Where a breach also breaks the law, we may report it to the relevant authority.
8. Reporting misuse
If you believe someone is misusing the service, including monitoring a domain without authority, email abuse@tidehawk.co or support@tidehawk.co. We aim to acknowledge reports within one working day.