This policy forms part of the Cybee service terms with cybee AG, Selnaustrasse 5, 8001 Zürich, Switzerland. It applies to customers and their authorised users, including use through connected assistants and automation.
1. Use Cybee where you have authority
Cybee is for businesses, including freelancers and sole traders, acting for business or professional purposes. Use it only on devices, accounts and information you own or are authorised to administer. Grant access only to authorised people and tools, and keep credentials confidential.
Where you manage devices or accounts used by other people, you are responsible for having the necessary authority and providing the notices required for your use. Do not use Cybee for unlawful surveillance, harassment, discrimination or another purpose that infringes people's rights.
2. Supported automation is welcome
You may use Cybee's documented CLI, MCP connections, supported assistants and other supported automation for their intended purposes. You remain responsible for the access you grant and the actions you authorise. A connected assistant must not be used to bypass permissions or carry out an action you are not authorised to perform yourself.
3. Protect access and service integrity
You must not:
- Access another customer's data or devices without authority, misuse credentials or impersonate another person.
- Bypass authentication, licence controls or other access restrictions, or exploit a vulnerability to obtain unauthorised access.
- Use Cybee to deploy malicious code, attack another system, steal information or deliberately disrupt a service.
- Overload Cybee, evade documented usage limits or interfere with another customer's use.
- Remove proprietary notices or redistribute the software contrary to its licence. Rights under applicable law and third-party or open-source licences remain unaffected.
4. Share evidence accurately
You may share your organisation's security records through supported functions where you have authority to do so. Preserve their date, scope and limitations. Do not alter or fabricate findings, present outdated records as current, or claim that a record is a certification, an audit opinion or a guarantee of security or insurance cover.
Do not disclose another person's confidential information or personal data without authority. These rules do not transfer ownership of customer information to Cybee.
5. Concerns and misuse
Report suspected misuse or a security concern to [email protected]. Share only the information needed to explain the concern, and do not include passwords, access tokens or unrelated personal data in an ordinary email. Reporting a concern does not authorise access to other people's systems or data.
Cybee may restrict or suspend access where reasonably necessary to address a violation of this policy, protect the service or others, or comply with law. Where practicable and permitted, we will explain the reason and what is needed to resolve it. Urgent security action may be taken first. Termination and its consequences are governed by the service terms.
Nothing in this policy prohibits a good-faith complaint, lawful reporting to an authority or the exercise of mandatory legal rights. It does not create a separate liability exclusion or a promise to compensate every consequence of misuse.