Legal
Acceptable use policy
A short list of things you cannot do with Offsight AI. Most of it is what you would expect. The part that is worth reading twice is what happens when an AI can take actions in your factory on someone’s behalf.
Offsight AI runs real production. A record in it can release a module, close an inspection, or become the evidence a third-party inspector relies on. That is why this policy exists and why it is enforced.
If you are a customer, you are responsible for the use of your tenant by everyone you give access to, including contractors and third-party inspectors — even where you did not authorize the particular use.
1. General restrictions
You may not, and may not permit anyone else to:
- use the Service for any unlawful purpose, or in breach of any applicable law, regulation, export control or third-party right;
- upload or transmit malware, or anything designed to disrupt, disable or impair the Service or any system connected to it;
- probe, scan or test the vulnerability of the Service, or breach or circumvent any security or authentication measure, without Offsight’s prior written permission;
- access another tenant’s data, or attempt to identify another customer from anything the Service returns;
- reverse engineer, decompile or disassemble the Service, or attempt to discover its source code, structure or algorithms, except where applicable law expressly permits it;
- resell, sublicense, rent, lease or otherwise make the Service available to a third party, or use it for the benefit of a third party outside your own operations;
- scrape, crawl or bulk-extract data from the Service other than through the documented APIs and export functions;
- use the Service, or anything it produces, to build, train, evaluate or benchmark a competing product or model; or
- remove or alter any proprietary notice, label or attribution.
2. Accounts and credentials
- Keep credentials confidential. One account, one person.
- Do not share a login to record a sign-off. A quality or inspection record must be attributable to the person who actually performed the work.
- Enable two-factor authentication where your organization requires it.
- Deactivate accounts promptly when someone leaves. Your administrators control per-module and per-user-group permissions; keep them current.
- Tell us immediately at support@offsight.com if you believe an account or an API key has been compromised.
3. What you upload
- Only upload content you have the right to upload — drawings, models, photographs, specifications and documents included.
- Do not submit personal data of third parties that you do not have a lawful basis to submit.
- Do not put sensitive categories of data into the platform unless we have agreed in writing that it is configured to handle them — health records, payment card numbers, government identifiers, and similar.
- Do not put credentials, API keys or passwords into free-text fields, support messages or AI requests. We never need one to help you.
4. Using the AI features
The Offsight AI assistant can read the records in your tenant and, where permitted, take actions in the system. Those actions carry the same weight as work done by hand, which is why the following are prohibited.
Do not falsify a record
Do not use AI features to create, alter, complete or backdate a quality, inspection, compliance, labor or sign-off record so that it misrepresents what was actually built, checked, observed or worked. An AI-assisted record is still a record, and the person on whose behalf it was created is still accountable for it.
Do not escalate permission
Do not attempt to make the assistant act outside the permissions of the requesting user, reach another tenant, or perform an action a user could not perform directly. Prompt-based attempts to do so are treated the same as a direct attempt to breach access controls.
Do not attack the model layer
Do not attempt to extract system prompts, tool definitions, model weights or other underlying implementation of the AI features; to bypass their safety or permission controls; or to inject instructions through uploaded documents, file names or record content intended to make the assistant act against the user’s intent.
Do not treat output as a professional determination
AI output is decision support. It is not an engineering opinion, a code-compliance determination, an inspection result, or a certification. It must be reviewed by a qualified person before it is relied on — and always before a sign-off, a release to ship, a submission to an inspector or building official, a purchase commitment, or any decision affecting the health or safety of a person. The full requirement is in the Terms of Service.
Do not decide about a person by machine
Offsight AI holds labor and productivity data. Do not use AI output as the sole basis for a decision about an individual worker — discipline, pay, scheduling penalties or continued employment. A person must review the underlying data and make the decision.
Do not generate abusive volume
Do not automate AI requests at a volume that degrades the Service for other customers, or route requests through the Service on behalf of parties who are not licensed users. AI credit consumption is metered per account; deliberately exhausting another party’s allowance is a breach of this policy.
5. APIs and automated access
- Use the documented APIs, respect published rate limits, and do not attempt to evade them by rotating identities.
- An API key belongs to the account that issued it. Do not share it across organizations, embed it in a client application, or commit it to a public repository.
- Rotate keys when a person with access leaves, and when a key may have been exposed. Key rotation and live usage metering are built into the platform; use them.
- Do not use automated access to replicate the Service, to bulk-mirror data for a third party, or to sustain load testing without prior written permission.
6. Integrations
When you connect Offsight AI to another system — an accounting or ERP platform, a design-file service, or anything through the API framework — you are responsible for the credentials used, for the scope of access granted, and for compliance with that provider’s terms. Where the AI assistant helps you configure an integration, review the resulting configuration before it moves live data.
7. Reporting a problem
Report abuse, a suspected vulnerability or a compromised account to support@offsight.com. Please include enough detail to reproduce the issue, and do not include credentials. We ask that you do not publicly disclose a vulnerability before we have had a reasonable opportunity to fix it.
8. Enforcement
Where use breaches this policy, Offsight may remove or disable the offending content, suspend an account or an API key, restrict AI features, or suspend or terminate access in accordance with the Terms of Service. We will use reasonable efforts to notify the customer’s account owner and to work the issue with them first, except where immediate action is needed to protect the Service, another customer, or someone’s safety, or where the law requires otherwise.
9. Changes
Offsight may update this policy as the product and the technology change. The current version is always the one published here, with the date at the top of this page. Material changes will be notified to account owners.
10. Contact
Questions about this policy: support@offsight.com. Contract questions: sales@offsight.com.
Offsight Inc.
650 California St
San Francisco, California 94108
Legal center
The rest of the paperwork.
Four short documents that sit alongside this policy.
Terms of Service
The agreement itself — the AI service, credits, human review, and how data is handled.
Learn morePrivacy Policy
What we collect, how AI processing works, how long we keep it, and the rights you have.
Learn moreData Processing Addendum
The processor terms that apply when Offsight handles personal data on your behalf.
Learn moreService Level Agreement
The availability target, the first-response clock by severity, and the exclusions — the policy Terms of Service section 3 refers to.
Learn moreSee what the AI is actually allowed to do.
On the call we will show you the permission model live.