Skip to content
BVECREW
  • Crew
  • Verticals
  • Engagements
  • Trust
  • Pricing
  • About
Request crew

Template -- legal review required

This document is a template. It has not been reviewed by counsel and is not yet in force. Anything in [BRACKETS] is a decision for Black Vault Engineering Group LLC or its lawyer, not a fact. Do not rely on this page until the notice is gone.

LEGAL-AUP

Acceptable Use Policy

Operator
Black Vault Engineering Group LLC, doing business as BVECrew
Version
[VERSION]
Effective
[DATE: pending]
Status
Template, not reviewed by counsel

BVECrew crew members are AI staff, supervised by people. Every one of them says so when asked.

Contents

  1. 1. Scope
  2. 2. The one rule under everything else
  3. 3. Prohibited uses
  4. 4. Approval tiers are not optional
  5. 5. Regulated work and compliance packs
  6. 6. Your systems and your people
  7. 7. Security research
  8. 8. Enforcement
  9. 9. Reporting misuse

Other policies

  • Terms of Service
  • Privacy Policy
  • Acceptable Use Policy
  • AI Disclosure Statement

1. Scope

This Acceptable Use Policy ("AUP") applies to everyone who uses the BVECrew website, the Front Office portal, or an AI Staff Member placed by Black Vault Engineering Group LLC ("BVE"), including your employees, contractors and anyone you allow to give a crew member instructions or approvals. It forms part of the Terms of Service and, where signed, your Master Service Agreement. If those documents and this AUP conflict, the stricter rule applies.

2. The one rule under everything else

An AI Staff Member does only what its Charter allows, narrowed by your Overlay, within its approval tier, and it always says it is AI. Every prohibition below is a specific case of trying to get around that.

3. Prohibited uses

3.1 Hiding that a crew member is AI

  • Instructing, configuring or presenting an AI Staff Member so that people believe it is a human.
  • Removing, obscuring or contradicting its AI-operated disclosure in any channel.
  • Using it to impersonate a specific real person, living or dead.

3.2 Widening a role

  • Attempting through an Overlay, instruction, prompt or connected system to make an AI Staff Member do anything outside its Charter.
  • Prompt injection, jailbreak attempts, or feeding it content designed to override its instructions.
  • Extracting, copying or reverse-engineering a Charter, the platform, or another client’s configuration.

3.3 Payment cards and secrets

  • Giving an AI Staff Member payment card numbers, or directing it to any page or form where cards are entered. The retail compliance pack blocks these on purpose.
  • Using it to store, forward or handle credentials, private keys or secrets outside the scoped access its Anchor connection was granted.

3.4 Harm and unlawful activity

  • Anything unlawful in your jurisdiction or ours.
  • Harassment, threats, discrimination, or content that targets a private individual.
  • Fraud, deceptive marketing, fake reviews, or manipulating anyone into a decision through deception.
  • Unsolicited bulk messaging, or contacting people who have opted out.
  • Collecting data about people without a lawful basis, or scraping systems you do not have the right to read.

3.5 Platform abuse

  • Sharing, reselling or sublicensing a Placement or Front Office access to a third party.
  • Interfering with the audit log, the redaction step, or any control the platform enforces.
  • Connecting Anchor to systems you do not own or have no authority to connect.
  • Load that is clearly outside the scope of the placement you ordered, used to degrade the service for others.

4. Approval tiers are not optional

Actions are classed R0 (Read-only), R1 (Reversible internal writes), R2 (External output, sent after human approval) and R3 (Irreversible / production, always human-approved). You may not:

  • Configure blanket or automatic approvals for R2 or R3 actions, or route approvals to a mailbox nobody reads.
  • Ask an AI Staff Member to break an R3 action into smaller steps to avoid approval.
  • Designate as an approver anyone who does not have the authority in your organisation to authorise the action being approved.
  • Disable or bypass a "checks first" client-approval rule on a role's sheet.

The platform enforces tiers in the runtime. Attempts to defeat that enforcement are a breach of this AUP regardless of whether they succeed.

5. Regulated work and compliance packs

Some roles ship with a vertical compliance pack (tax and accounting, financial services, retail and e-commerce). A pack narrows what a role may do to fit the regulations that apply to that work. You may not use a Placement for regulated work its pack does not cover, and you may not use a general role for work that needs a pack. In particular:

  • Tax roles: no use outside US-only processing; taxpayer consent tracking must stay enabled.
  • Financial-services roles: communications archive export must stay enabled.
  • Retail roles: card-number detection and redaction, card-entry page blocking, refund approval thresholds and AI disclosure on all channels must stay enabled.
  • Any vertical: you remain responsible for your own regulatory obligations. A compliance pack is a control set, not a licence or a certification.

6. Your systems and your people

  • Only connect systems you own or are authorised to connect, and grant the least access the role needs.
  • Tell the people who will interact with an AI Staff Member that it is AI-operated, in addition to the crew member's own disclosure, where your law or your policy requires it.
  • Keep your approver list current. Approvals given by whoever holds the designation are your organisation's approvals.
  • Do not direct an AI Staff Member at people who have asked not to be contacted, or at anyone under [16 / 13] .

7. Security research

Good-faith testing of your own Placement's controls (for example, checking that an R3 action really does wait for approval) is welcome. Testing that touches other clients, the platform's shared services, or BVE's infrastructure is not, unless agreed in writing first. Report anything you find to security@bvecrew.com (placeholder -- HUMAN_ACTIONS: confirm real security contact address). We will not take legal action against good-faith research that stays within these lines.

8. Enforcement

8.1 BVE may pause an AI Staff Member, suspend Front Office access, or refuse a specific instruction immediately and without notice where continuing would breach this AUP, harm a person, or create a legal or security risk. We will tell you what we did and why, as soon as it is safe to.

8.2 For breaches that are not urgent, we will give you notice and [N] days to fix them before suspending.

8.3 Repeated or serious breaches are grounds for ending the relationship under the Terms or your agreement. Fees for the current period remain payable. [COUNSEL TO CONFIRM REFUND POSITION ON AUP TERMINATION]

8.4 Nothing in this AUP limits BVE's duty to keep an AI Staff Member inside its Charter, or shifts that duty to you.

9. Reporting misuse

If you think an AI Staff Member is being misused, or one has contacted you in a way this policy forbids, tell us: legal@bvecrew.com (placeholder -- HUMAN_ACTIONS: confirm real legal/privacy contact address). Include the crew member's id if you have it (it is on every message it sends) and when it happened. A person reads every report.

BVECREW

Add headcount without hiring.

A Black Vault Engineering Group LLC product

Product

  • Anchor connector
  • Strongbox appliance
  • Crew roster
  • Build your crew

Residency

  • L1 Keyed Your storage, your keys.
  • L2 Tenant Runs inside your own cloud account.
  • L3 Vault Nothing leaves your building.

Company

  • About
  • Security
  • Privacy
  • Terms

© 2026 Black Vault Engineering Group LLC. BVECrew is a trademark of Black Vault Engineering Group LLC.