# Craton acceptable use

The rules of use for Craton: what the platform is for, what it must not be
used for, and what happens when a rule is broken. It is the companion to the
[terms of service](/terms), which refer to this page rather than restating it.

---

## Status of this page

**Approved by the operator on 2026-08-18** (`BLOCKED_OPERATOR.md` item 8,
`docs/GTM.md` GTM-14 and GTM-15), together with the
[terms of service](/terms) it companions.

Written by the build fleet, and the one decision it reserved to a human — the
address for abuse and security reports — was made by the operator on that date
and recorded in item 8. Everything else on this page is a rule this build
already enforces on itself.

## Who this applies to

Everybody who calls the API, holds a key, uses the free sandbox, publishes to
the model registry, or consumes the published schema.

## What Craton is, so the rules read straight

Craton outputs technical prices, never quotes; it drafts terms, never offers; it cannot bind, issue, endorse, claim or settle.

It is software: analysis and drafts, self-service, with fees for usage of the
software as its only money flow. Most of the rules below are that sentence,
applied.

## Use it for

* Integrating the API and the SDK into your own systems.
* Turning schedules, bordereaux and event data into canonical risk objects.
* Analysis, structuring work, technical pricing and historical testing that
  you or your organisation carry out for yourselves or your clients.
* Composing, testing and publishing models in the registry.
* Research, teaching and evaluation, with the platform's outputs attributed.

## Do not misrepresent what an output is

Craton output is never a quote, never an offer, and never a binding commitment of any kind.

* Do not present one to anybody as if it were. This is the misuse that would
  make the platform dangerous, and it is the one this rule exists for.
* Do not strip the assumptions, the model-and-version label, the technical
  price labelling or the draft marking off an output before showing it to a
  third party. Those labels are what make a number honest.
* Do not present Craton, or yourself acting through Craton, as a carrier, a
  broker, an intermediary or a party to any contract of insurance or
  reinsurance.
* Do not present registry measurements as a ranking, a recommendation or an
  endorsement. The platform never ranks or recommends a model, and neither may
  a page you build on it.

## Do not ask the platform to leave its perimeter

* No request — through the API, through the registry, or to a person — makes
  this platform place cover, touch paper, or move money on anybody's behalf.
  There are no endpoints for it, and none will be added.
* Do not build a workflow that presents the platform as doing any of that,
  even where your own systems do the real thing downstream.
* Fees for software usage are the only money this platform is ever part of,
  and they run through the payment processor named in the terms.

## Data you must not send

* **No individual-level personal records.** Named people, contact details,
  identifiers tied to a person, health, biometric, financial-account or
  criminal-record data. Craton is built for exposure and event data. If a file
  you want to ingest carries a personal column you do not need, remove it
  first.
* **Nothing you do not have the right to send** — data you are contractually
  or legally barred from sharing, and third-party data whose licence does not
  permit it.
* **No credentials, keys or secrets** inside payloads, model definitions or
  model cards.
* **Nothing unlawful, malicious or deliberately hostile to the platform** —
  malware, code shaped to exploit a parser, or content whose purpose is to
  harm somebody.

## Security and fair use

* Do not attempt to reach another account's objects, models, results or usage.
* Do not circumvent rate limits, quotas or metering, and do not spread usage
  across accounts to stay inside the free tier or to avoid fees.
* Do not resell the free sandbox, or the platform's capacity, as your own
  metered service.
* Do not run load, stress or penetration tests against a shared environment
  without the operator's written permission. Test against your own sandbox
  account within the published limits.
* Do not scrape the docs site or the registry at a rate that degrades either
  for other readers. The published schema is free to fetch and cache — that is
  what it is for.
* If you find a security defect, report it before you write about it, and do
  not use it to reach data that is not yours.

## Registry rules

* A model card must be truthful about authorship, inputs, assumptions and
  limitations. A card that misstates what a model does is a breach of this
  page, however good the model is.
* Do not publish a model whose logic attempts a network call, embeds
  non-deterministic behaviour, or is shaped to defeat the determinism and
  backtest checks every published version re-runs on every build.
* Do not publish somebody else's model, data or wording as your own, or
  anything you do not hold the licence to publish.
* Do not publish a model whose purpose is to price people out on a
  characteristic the law where you operate protects.
* A published version is immutable; withdrawal from the public registry is the
  remedy for a card or a model that breaks these rules.

## Unlawful and harmful use

* Do not use Craton where doing so breaks the law that applies to you —
  sanctions and export control, anti-discrimination law, data-protection law,
  or the insurance regulation of your own jurisdiction.
* Do not use its outputs to unlawfully discriminate against people, or to
  target individuals.
* Do not use it to evade a legal or regulatory obligation of your own. A
  technical price computed here is not a regulatory filing, an actuarial
  certification, or a substitute for either.

## If a rule is broken

Proportionate, and in this order wherever the situation allows it:

1. A rate limit, or a temporary block on a key.
2. Suspension of the account, with the reason stated.
3. Withdrawal of a published model version from the public registry.
4. Ending access, and where the law requires it, a report to whoever the law
   says.

Where it is not urgent, you are told what the problem is and given a chance to
put it right first. Where it is urgent — a live security problem, a legal
demand — the block comes first and the explanation follows.

## Reporting

The address for abuse and security reports is support@barite.co. Legal and
privacy notices go to the same address under the
[terms of service](/terms); if you are not sure which a message is, send it
anyway and say what you found.

---

*Drafted 2026-08-13 by the build fleet under `docs/GTM.md` GTM-14; approved
by the operator 2026-08-18 (`BLOCKED_OPERATOR.md` item 8) and the recorded
address transcribed here under GTM-15. Companion page:
[terms of service](/terms).*
