1. Lawful business use
Use MandateShield only for lawful business purposes and within the authority of the identified organization. You must not use it for fraud, theft, deceptive practices, sanctions or export-control evasion, money laundering, unauthorized payments, rights violations or facilitation of another person's unlawful conduct.
2. Prohibited data
Do not submit card numbers, card verification codes, payment cryptograms, bank login details, private keys, passwords, authentication tokens, children's data, special-category or highly sensitive personal data, medical records, biometric templates, government identifiers or personal data unnecessary for the documented decision. MandateShield is not a payment-credential vault.
3. Credential and control integrity
Do not expose PROCESSOR or provider credentials to a model, agent, browser or untrusted client. Do not bypass, disable or misrepresent mandate, merchant, amount, currency, budget, replay, challenge, consume, permit-redemption, payee-binding, provider-evidence or settlement-unknown controls. Do not retry an unknown payment outcome without reconciliation.
4. Platform abuse
Do not probe another account, attempt unauthorized access, introduce malware, interfere with service, perform denial-of-service or unapproved load testing, evade quotas, scrape against published limits, credential-stuff, mass-create accounts or use automated scanners without validating impact under the Responsible Disclosure Policy.
5. Deception, affiliation and public proofs
Do not fabricate receipts, adoption, savings, prevented losses, conformance or third-party endorsements; use an integration badge to imply certification or comprehensive protection; publish a proof for a subject you do not control; or claim a partnership with MandateShield, Stripe, Visa, Google, OpenAI, a protocol project or another party without written evidence.
A Proof Network publisher grants the limited right to host and display its submitted report and binding evidence, confirms it has the necessary rights, and accepts correction, expiry, revocation, appeal and lawful takedown procedures. A self-report is not a certification or customer reference.
6. Prohibited decision contexts
Do not use an output as the sole or determinative control for healthcare, employment, housing, education admission, credit, insurance, law enforcement, immigration, essential services, safety-critical systems or another decision producing legal or similarly significant effects for a person. Do not use MandateShield as a replacement for obligations concerning AML, KYC, sanctions, fraud, consumer protection, accessibility, tax, chargebacks or payment-network rules.
7. Enforcement and appeal
MandateShield may proportionately rate-limit, quarantine, revoke or suspend affected credentials, content or accounts where reasonably necessary to investigate or stop a violation, preserve evidence, comply with law or protect others. Notice and an opportunity to correct or appeal will be provided where lawful and practicable. Good-faith security research that follows the Responsible Disclosure Policy is treated under that policy.