acceptable_use · 2026-08

Effective date:
2026-08-01
Language:
en
Published:
2026-08-23T22:58:16.598878+00:00
Status:
current
Digest:
50459a186dac8dab45b17a51e0c8624b8e58cfc6d3eea3a1f4b546f0d9251645
Computed as:
sha256 over pegtrace.legal-doc-text.v1
Acceptable Use Policy PEGTrace LLC | Last Updated: August 2026 This Acceptable Use Policy (this “Policy”) establishes mandatory operational and conduct requirements for authorized use of the PEGTrace Platform by institutional and professional users. This Policy supplements the Terms of Service and may also be incorporated into an applicable order form or other negotiated agreement, subject to the applicable order-of-precedence provisions. This Policy does not independently govern an individual consumer purchase or a visitor’s use of PEGTrace’s public informational, fraud-report intake, wallet-exposure-check, or verification functions unless separately presented and accepted for that function or transaction. By affirmatively accepting this Policy or using authenticated Platform services under terms that incorporate it, you agree to comply with this Policy. If you do not agree, you may not use the affected authenticated services. Capitalized terms not defined in this Policy have the meanings assigned in the Terms of Service; if another written agreement expressly incorporates this Policy and defines a term differently, its applicable order-of-precedence provisions control. 1. Definitions and Scope 1.1 “AI Coach” means an artificial-intelligence-assisted feature intended to explain application functionality, interface navigation, and workflow mechanics. 1.2 “Case Data” means identifiers, transaction hashes, notes, documents, analytical observations, metadata, and other case-related information submitted to or generated through the Platform by or for you. 1.3 “Evidence Ledger” means the append-only, hash-linked chronological record of designated Platform events that is designed to make subsequent alteration detectable. 1.4 “Platform” means the PEGTrace web application, public verification portal, cryptographic hashing engine, evidence-packaging workflows, and application programming interfaces operated by PEGTrace LLC. 2. Credential Governance and Account Security 2.1 Individual Account Assignment. Each user account is assigned to one individual and may be used only by that individual. You may not transfer or disclose passwords, session credentials, authorized access links, or authentication tokens, except that an invitation or access link generated through an authorized Platform workflow may be provided to its intended recipient. 2.2 Prohibition on Credential Sharing and Access Circumvention. You may not share account credentials; permit multiple individuals to use a single account; bypass restrictions on user seats, roles, tenants, or case access; or provide Platform access to an unauthorized person. A violation may result in suspension or termination under Section 6 of this Policy. 2.3 Authentication and Compromise Reporting. You must use a strong, unique password; safeguard devices and browsers through which you access the Platform; comply with authentication controls made available and required by PEGTrace; and promptly notify PEGTrace through its designated security contact if you suspect unauthorized access, disclosure of credentials, or compromise of your account. If PEGTrace makes an additional authentication control available and requires its use for your account, you must enable and maintain that control. 3. Sensitive Data, AI Use, and Prohibited Credentials 3.1 Permitted Data Submission and Prohibited Credentials. You must never input, paste, upload, or transmit raw private wallet keys, cryptocurrency seed phrases, full bank-account numbers, active online-banking passwords, or unencrypted personal data concerning a fraud victim into open interface fields, public verification routes, or general investigative notes. 3.2 Restricted Sensitive Data. You must not enter full bank-account information, Social Security numbers, government-identification numbers, victim-identifying information, or other unnecessary sensitive personal data into the AI Coach, public verification routes, filenames, general investigative notes, or other free-text fields. If a designated Platform field expressly requests particular personal or financial information for an authorized workflow, you may submit only the information reasonably necessary for that workflow and must use the designated field rather than a general narrative field. 3.3 AI Coach Input and Use Restrictions. Text entered into the AI Coach is transmitted as entered to third-party artificial-intelligence services. You must not enter information prohibited by Sections 3.1 or 3.2 of this Policy, privileged communications, or sensitive Case Data into the AI Coach. You must not use the AI Coach to obtain legal or other professional advice; identify or attribute a wallet, account, transaction, or alleged conduct to a natural person; determine guilt or legal liability; or generate a purported professional conclusion. PEGTrace’s automated controls do not detect or prevent every prohibited or unnecessary submission. 3.4 Review of AI Responses and External Outputs. You must independently review AI Coach responses, Case Data, narrative fields, filenames, attachments, generated reports, and evidence packages before relying on them or disclosing them outside the Platform. You must not represent an AI-generated response as professional advice, verified evidence, a factual finding, an identity attribution, a legal conclusion, or a determination made by PEGTrace. Before external disclosure, you must remove or appropriately segregate personal data that is unnecessary for the intended purpose and confirm that the disclosure is authorized and complies with applicable law and your organization’s requirements. Platform controls may not prevent every inclusion or disclosure of personal data. 4. Prohibited Conduct, Misrepresentation, and Recovery Exploitation 4.1 Prohibition on Harassment and Unlawful Targeting. You must not use the Platform, Case Data, transaction information, third-party intelligence, verification records, or generated outputs to dox, harass, stalk, threaten, intimidate, blackmail, extort, discriminate against, or otherwise unlawfully target any person or organization. You must not publicly disclose personal data obtained or generated through the Platform unless the disclosure is lawfully authorized and reasonably necessary for a permitted purpose. 4.2 Prohibition on Misrepresentation and Unsupported Attribution. You must not represent Platform outputs, cryptographic hashes, timestamps, verification results, third-party labels, risk scores, or analytical signals as a judicial or governmental determination, a finding made by PEGTrace, or definitive proof of fraud, criminal guilt, ownership, identity, intent, legal liability, asset recoverability, authenticity, or admissibility. You must not identify or attribute a wallet, account, transaction, or alleged conduct to a natural person without an independent and lawful evidentiary basis. You must not remove or obscure source information, qualifications, limitations, or disclaimers in a manner that materially misrepresents an output. 4.3 Prohibition on Unlawful or Deceptive Recovery Services. You must not use the Platform to operate, promote, or assist a fraudulent, deceptive, unlicensed, or otherwise unlawful asset-recovery or investigative service. You must not guarantee or falsely represent that assets will be identified, frozen, returned, or recovered; falsely claim affiliation with PEGTrace, a financial institution, cryptocurrency custodian, law-enforcement agency, court, regulator, or licensed professional; solicit or collect a fee prohibited by applicable law; use Platform information to coerce payment or disclosure of credentials; or communicate with another person as though PEGTrace had authorized you to act on its behalf. Nothing in this Section prohibits an authorized attorney, investigator, accountant, financial institution, government agency, or other professional from using the Platform to provide lawful services within the scope of its authority, licensure, and professional obligations. 5. Infrastructure Protection and Automated-Use Restrictions 5.1 Prohibition on Unauthorized Automated Access. Except through an application programming interface, integration, or other automated method expressly authorized by PEGTrace, you must not use a bot, script, spider, crawler, scraper, or other automated means to access, query, monitor, index, harvest, or systematically extract data, verification records, Evidence Ledger information, Platform outputs, or nonpublic Platform content. Any authorized automated access must comply with the applicable documentation, access limitations, rate limits, and written agreement. You must not bypass a CAPTCHA, rate limit, access control, technical restriction, or other measure intended to regulate automated access. 5.2 Prohibition on Reverse Engineering and Security Circumvention. Except to the extent a restriction is prohibited by applicable law, you must not reverse engineer, decompile, disassemble, translate, or attempt to derive the Platform’s nonpublic source code, proprietary workflow logic, database structures, security controls, authentication methods, or package-generation architecture. You must not circumvent or attempt to circumvent authentication, authorization, role, tenant, case-access, storage, or other security restrictions. 5.3 Prohibition on Unauthorized Model Training and Benchmarking. Except as expressly authorized in writing by PEGTrace, you must not use the Platform, its nonpublic architecture, verification routing, or AI Coach responses to train, fine-tune, validate, or benchmark a machine-learning model, large language model, automated fraud-detection system, or similar computational system. This restriction does not transfer ownership of your Case Data to PEGTrace or prohibit your use of Case Data and exported materials as otherwise permitted under the terms governing your use of the Platform. 5.4 Prohibition on Malicious Code and Service Interference. You must not introduce malware, malicious code, corrupted content, or another harmful component into the Platform; attempt to gain unauthorized access to an account, case, system, network, or data repository; interfere with or disrupt Platform operation; impose an unreasonable or disproportionately large load on Platform infrastructure; use the Platform to attack or compromise another system; or scan, probe, or test a Platform vulnerability without PEGTrace’s prior written authorization. 6. Enforcement, Suspension, and Termination 6.1 Investigation, Suspension, and Termination. PEGTrace may investigate a suspected violation of this Policy and may restrict, suspend, or terminate access for a material violation; fraudulent or unlawful conduct; conduct that threatens Platform security or infrastructure; or conduct presenting a material risk to another person or the Platform. PEGTrace may act immediately when reasonably necessary to address security, legal, or safety concerns and otherwise will provide notice and an opportunity to cure when commercially reasonable, subject to any contractual notice and cure rights. PEGTrace may preserve relevant records or disclose information concerning suspected unlawful conduct when required or permitted by applicable law, subject to the Privacy Policy. 7. Relationship to Other Agreements and Policy Updates 7.1 Supplemental Policy and Order of Precedence. This Policy supplements the Terms of Service and may be incorporated into an applicable order form or other negotiated agreement. If this Policy conflicts with those terms, the applicable order-of-precedence provisions control. The Privacy Policy and Data Handling and Subprocessor Disclosure are notices concerning PEGTrace’s data practices and do not independently create contractual warranties or a separate liability, arbitration, or entire-agreement regime. 7.2 Governing Law and Dispute Resolution. This Policy does not create a separate governing-law or dispute-resolution regime; those matters are governed by the terms applicable to the relevant relationship. This Policy does not subject an individual consumer purchase or a visitor’s use of a public informational, fraud-report intake, wallet-exposure-check, or verification function to institutional dispute-resolution provisions unless the applicable terms are separately presented and accepted for that transaction or function. 7.3 Policy Updates. PEGTrace may update this Policy to reflect legal, security, technical, or operational changes. An updated version will state its revised effective or “Last Updated” date. For existing authenticated users, PEGTrace will present a material revision through the Platform’s acceptance mechanism or another reasonable electronic method before treating the revision as accepted.

PEGTrace LLC·Jersey City, NJ

Company·Legal·support@pegtrace.com