# Polestar GRC Acceptable Use Policy

Version: 2.2, effective October 9, 2026

Published October 9, 2026. Replaces Version 2.1, effective October 8, 2026. Version 2.2 changes the provider. The provider named in earlier versions assigned the Polestar GRC business to Jonathan Prine, an individual doing business as Polestar GRC, on the date stated in our notice of assignment. Version 2.2 also restates the email rule in Section 4 (do not email PHI or Protected Data to our mailboxes unless we ask) and names our outbound email and SMS providers. For a customer that accepted an earlier version, the change of provider takes effect by assignment on the date stated in our notice of assignment, and the rest of Version 2.1 continues to take effect on November 7, 2026 as our notice of October 8, 2026 stated. The restated email rule in Section 4 is a clarification and applies from the date this version is published (Terms of Service Section 24.2). Every earlier version is archived at polestargrc.com/legal/archive.

This Acceptable Use Policy ("AUP") is part of the Terms of Service between Jonathan Prine, an individual doing business as Polestar GRC ("Polestar GRC", "we", "us"), and each customer. It applies to every organization and every Authorized User who accesses the Service, including auditors who use Audit Room links and partners who use white-label portals. Capitalized terms have the meanings given in the Terms of Service. The customer is responsible for its Authorized Users' compliance.

## 1. Lawful and honest use

Do not use the Service to:

- Violate any law or regulation, including health privacy, consumer protection, anti-discrimination, export control and sanctions laws.
- Store, transmit or generate content that is unlawful, defamatory, harassing, threatening, obscene, or that infringes or misappropriates anyone's intellectual property, privacy or publicity rights.
- Store information you have no right to hold, including PHI uploaded before the applicable Business Associate Agreement is in effect, sensitive client data uploaded before the Data Protection Agreement is in effect, data about individuals collected without a lawful basis, or another organization's confidential information. In HIPAA mode the Service blocks new file uploads and incident narrative text until your administrator accepts the agreement; do not work around that block, for example by putting PHI in titles, names or other fields it does not cover.
- Misrepresent what the Service produces. Assessments, scores, reports, policies and audit packages are documentation of your own program; do not present them as a certification, accreditation, attestation by Polestar GRC, or legal opinion, and do not alter a report to misstate your results.
- Submit false information to us, including a false answer about whether you are a HIPAA covered entity or business associate, a false nonprofit status, or a false ownership verification for a scan target.
- Distribute malware, or upload files intended to disrupt, damage or gain unauthorized access to any system, including ours. (Uploading a configuration file or code repository for analysis is fine; uploading something designed to exploit our scanners or viewers is not.)

## 2. Protecting the Service and other customers

Do not:

- Probe, scan, penetration test, fuzz or otherwise test the security of the Service or its infrastructure, except through the security research process in Section 7 or under a written authorization from us.
- Access, or attempt to access, another organization's workspace, Audit Room, data or credentials, or any account that is not yours.
- Circumvent or disable authentication, authorization, rate limits, multi-factor authentication, trial or plan restrictions, or any other control.
- Interfere with the Service's operation, including by flooding, denial of service, excessive automated requests, or deliberately exhausting AI usage limits, storage or compute.
- Scrape or harvest content, templates, question banks or state-law content from the Service by automated means, or build a dataset or competing product from them.
- Share, lend, sell or time-share accounts. Each Authorized User must have their own credentials and must keep them secret. Do not use someone else's credentials.
- Provide access to the Service to anyone other than your Authorized Users and the auditors you invite, except as a Partner under a written Partner Agreement with us.
- Remove, obscure or alter any proprietary notice, or use our name, logo or branding except as the Terms or a Partner Agreement allow.

## 3. Security scanning and connected systems

The Advanced plan and some integrations let you scan code repositories, container images, infrastructure definitions, cloud accounts and live web applications, and let you connect cloud, log and code platforms. When you use these features:

- Scan only what you own or are authorized in writing to test. You must complete our ownership verification for every web target (DNS record or hosted verification file) before a dynamic scan runs, and you must keep that authorization current. Scanning a third party's systems without authorization may be a crime under the Computer Fraud and Abuse Act and state computer crime laws, and you alone are responsible for it.
- Connect only accounts you administer, with the least privilege our documentation describes (read-only roles, scoped tokens, external IDs). Do not connect a customer's, vendor's or employer's account without their authorization.
- Understand that active scanning can create load, alerts and log noise on your systems. Schedule scans accordingly and tell your own security team.
- Treat scan results as sensitive. Secret-scanning results can reveal live credentials from your own systems; rotate them and limit who can view the results.
- Do not point scanners at the Service itself.

## 4. Content and data minimization

- Upload evidence and documentation at the minimum sensitivity necessary. The Service documents your compliance program; it is not an electronic health record, a designated record set or a system for storing patient charts. Include PHI or Protected Data (as defined in the Data Protection Agreement) only where a feature is designed for it and only to the extent an auditor would reasonably need to see it.
- Put PHI or Protected Data only in features built to hold it (evidence, incident records, vendor records). Do not put PHI or Protected Data in workspace names, policy titles, invitation messages, support tickets, chat messages or free-text fields that are not designed for it.
- Do not put PHI or Protected Data in any field whose contents could be sent by email or SMS, including workspace names, policy and evidence titles, invitation messages and reminder text. Do not email PHI or Protected Data to our mailboxes unless we ask for specific information to resolve an issue, and then prefer the in-app ticket. Our mailboxes are hosted by Google Workspace, and until the Privacy Policy (Section 10) shows our business associate agreement with Google in place, we will ask for that information only in the in-app ticket. Our outbound email and SMS providers (Twilio SendGrid and Twilio) are not covered by a business associate agreement, and our emails and text messages are designed to say only that an item is waiting. Do not use the Service as a client record, scheduling or clinical system.
- Keep AI inputs free of patient-identifying details wherever possible. Automated redaction is a safety net, not a license. Review every AI output with a qualified person before adopting it.
- Use invitation, reminder, training and SMS features only for people who have a legitimate role in your compliance program, and only with addresses and numbers you are entitled to use. Do not use the Service to send unsolicited messages.
- Respect the retention rules your organization and the law require. The Service supports your retention obligations; it does not replace your records management program.

## 5. Audit Rooms, partners and sharing

- Share Audit Room links only with the auditor or reviewer they are intended for, set an expiry that matches the engagement, and revoke links when the engagement ends. You are responsible for what the recipient does with the data.
- Partner features exist only under a Partner Agreement with us. A partner may provision and brand client workspaces only as its Partner Agreement and Section 26 of the Terms of Service allow. When you create a client workspace you must select the compliance mode and HIPAA role that match the client's actual status, and you may not select state mode for an organization that is a HIPAA covered entity or business associate. You may never accept the Terms of Service or a Business Associate Agreement, Subcontractor Business Associate Agreement or Data Protection Agreement for a client, even with the client's written authority; the client's own administrator must accept it in the Service. Partner users may access a client's workspace data only when the client invites them, only to the extent the client has authorized and only to provide services to that client, and you are responsible for having the agreement with the client (including any business associate or processor agreement) that the law requires for that access. You may not represent Polestar GRC outputs as your own certifications.
- An IT provider or consultant that refers an organization to us without a Partner Agreement is not a partner and may not sign up, accept agreements or pay on that organization's behalf.
- Do not export data from the Service to evade its access controls or to disclose another person's information unlawfully.

## 6. Fair use and limits

Plans include generous but finite storage, AI usage, scan frequency and email volume. We may apply rate limits and monthly usage caps to keep the Service reliable for everyone. If your use is far above what is typical for your plan, we will contact you about options before taking action unless the use threatens the Service, in which case we may throttle first and contact you promptly.

## 7. Security research

We welcome good-faith security research on the Service. If you follow these rules we will not pursue legal action against you for your research, and we consider it authorized under the Terms of Service:

- Report findings promptly to security@polestargrc.com and give us a reasonable time (at least 90 days, or longer by agreement) to fix the issue before public disclosure.
- Test only accounts and workspaces you created for the purpose. Do not access, modify or delete other customers' data; if you encounter it, stop and tell us.
- Do not degrade the Service, run denial-of-service tests, use social engineering, phishing or physical attacks, or test third-party services we use.
- Do not exfiltrate data beyond what is needed to demonstrate the issue, and delete it once reported.
- Comply with applicable law.

We do not currently operate a paid bug bounty program.

## 8. Enforcement

We may investigate suspected violations and may remove content, restrict features, suspend accounts or terminate the agreement as the Terms of Service describe. Where practicable we will notify you and give you a chance to cure. We may report unlawful activity to law enforcement or regulators and cooperate with their investigations. We may preserve and disclose information as required by law or to protect the rights, safety and property of our customers, users and us.

## 9. Reporting abuse

Report suspected violations of this AUP, abuse of the Service, or content that should not be on it to abuse@polestargrc.com. Report security vulnerabilities to security@polestargrc.com. Report suspected unauthorized access to your own workspace to security@polestargrc.com immediately.

## 10. Changes

We may update this AUP as the Service and the threat landscape change. Material changes are announced in the way the Terms of Service describe. The version at polestargrc.com/legal/acceptable-use-policy is the current one.

---

Earlier versions of this Acceptable Use Policy: [Version 2.1, effective October 8, 2026](https://polestargrc.com/legal/archive/acceptable-use-policy-v2.1) and [Version 2.0, effective October 1, 2026](https://polestargrc.com/legal/archive/acceptable-use-policy-v2.0). Every version of our legal documents is listed at [polestargrc.com/legal/archive](https://polestargrc.com/legal/archive).
