Acceptable use & moderation
This policy ("AUP") sets out conduct that is not permitted on the Routero AI service ("Service"). It is incorporated into the Terms of Service and applies to Customer and Customer's end users.
1. Customer responsibility
Routero AI is an inference gateway. Customer (not Provider) selects which upstream LLM provider receives traffic, what prompts are sent, and how responses are used downstream. Customer is responsible for:
- The legality and appropriateness of all prompts and outputs;
- Compliance with the terms of each upstream LLM provider Customer routes traffic to (each provider has its own AUP — OpenAI, Anthropic, Google, AWS Bedrock, etc.);
- The lawfulness of any application or product Customer builds on top of the Service;
- End-user notice, consent, and opt-out where required by law.
Customer is also responsible for ensuring its end users comply with this AUP.
2. Prohibited conduct
Customer must not, and must not permit anyone using Customer's keys or accounts to:
2.1 Unlawful conduct
- Use the Service to commit, facilitate, or encourage any activity that is unlawful including but not limited to the Computer Misuse Act (Singapore), the Spam Control Act (Singapore), the Cybersecurity Act (Singapore), and applicable laws of the user's jurisdiction or the jurisdiction in which the Service is operated.
- Violate export-control, sanctions, or anti-money-laundering laws. Customer must not use the Service, or permit the Service to be used, by or for the benefit of any person, entity, country, region, or end use that is prohibited or restricted under applicable sanctions, export-control, import-control, or trade-compliance laws. Customer must not use the Service for prohibited military, intelligence, surveillance, weapons, or other restricted end uses where prohibited by law or upstream provider terms.
- Infringe intellectual property, trade secrets, or contractual rights of others.
2.2 Harm to people
- Generate, solicit, or distribute content that sexualizes minors in any form. This is an absolute prohibition with no exceptions.
- Generate content that incites violence against any person or group, or that promotes self-harm or suicide.
- Harass, threaten, intimidate, or discriminate against any person or protected group.
- Generate content intended to dehumanize, vilify, or incite hatred toward any class of people.
- Produce non-consensual sexual content of any real person, including deepfakes.
2.3 Privacy violations
- Submit personal data of others without a lawful basis (consent, contract, legitimate interest, etc.).
- Use the Service to dox, surveil, or stalk a private individual.
- Use the Service to perform biometric identification or categorization of individuals in ways that are unlawful in the user's jurisdiction.
- Submit special-category personal data (health, biometric, sexual orientation, religion, political opinion, etc.) without ensuring an appropriate legal basis.
2.4 Deception, fraud, manipulation
- Use the Service to impersonate any person or organization.
- Generate disinformation intended to mislead voters, manipulate elections, or interfere with democratic processes.
- Generate content for the purpose of fraud, scams, phishing, or social engineering.
- Misrepresent AI-generated output as authored by a real human in contexts where that representation is material (e.g., academic submissions, professional advice, certified expert opinions).
2.5 Security and integrity
- Reverse-engineer, decompile, or extract weights/training data of upstream models.
- Probe for vulnerabilities, perform unauthorized penetration tests, or exploit any flaw in the Service.
- Submit malware, viruses, ransomware, or other malicious code, or use the Service to assist in the creation thereof.
- Bypass or attempt to bypass authentication, rate limits, budgets, or content controls.
- Exfiltrate API keys (Customer's or anyone else's), credentials, or sensitive system data.
- Use automation that exceeds reasonable rate limits or that imposes disproportionate load on the Service.
2.6 Content moderation evasion
- Attempt to manipulate the Service or upstream providers into bypassing their safety systems via prompt injection, jailbreaks, role-play scenarios, or otherwise.
- Use the Service to coordinate or distribute jailbreak prompts targeting upstream providers.
2.7 High-risk decisions without human review
Use the Service as the sole decision-maker for any of the following without meaningful human review:
- Credit, insurance, or housing eligibility
- Employment decisions (hiring, firing, promotion, performance evaluation)
- Educational admissions or grading
- Medical diagnosis, treatment, or triage
- Legal advice, legal status determinations, or judicial outcomes
- Law-enforcement decisions, sentencing, parole, or border control
- Safety-critical industrial control or transportation
- Eligibility for public benefits
The Service is a general-purpose inference gateway. It does not validate that outputs are safe to act on automatically.
2.8 Scraping and data abuse
- Use the Service to scrape, harvest, or otherwise collect content from third-party websites, services, or providers in violation of their terms.
- Use the Service to generate or distribute synthetic data that violates privacy, copyright, or contractual restrictions.
2.9 Service abuse
- Resell, sublicense, or share API keys with parties outside Customer's organization without entitlement.
- Use the Service to benchmark Provider's offerings against competing services for the purpose of building a competing product, except as expressly permitted in writing. (Customer may run internal benchmarks for the purpose of evaluating the Service for its own use.)
- Falsely report incidents or abuse cases to manipulate billing or reputation.
3. Content moderation in the Service
Routero AI supports optional content-moderation hooks (prompt-injection detection, Azure Content Safety, Presidio PII redaction) but does not enable them by default. Operators may enable them per their risk profile.
Where Customer enables moderation hooks, those hooks may rewrite or block requests/responses. Customer remains responsible for compliance with this AUP regardless of whether moderation hooks are enabled.
Upstream LLM providers each apply their own safety systems. Customer's traffic is subject to upstream provider moderation in addition to anything Routero AI does.
4. Reporting & enforcement
To report a violation of this AUP, contact trust-and-safety@routero.ai.
We may, in our reasonable discretion:
- Investigate suspected violations;
- Suspend or revoke API keys, users, teams, or organizations;
- Terminate Customer's account for material or repeated violations;
- Cooperate with law-enforcement requests as required by applicable law;
- Refer suspected child-safety material to NCMEC or the equivalent local authority, as required.
We may act with or without prior notice to Customer when we reasonably believe immediate action is necessary to protect the Service, third parties, or compliance with law.
5. Customer remediation
If we notify Customer of a suspected violation, Customer must promptly investigate, remediate (including by suspending or revoking the offending end user's access), and report the outcome.
6. Changes
We may update this AUP. Material changes will be notified at least 10 days in advance, except where the change is required by law or addresses a material safety risk, in which case we may apply it immediately.
7. Contact
Trust & Safety: trust-and-safety@routero.ai
Abuse reports: abuse@routero.ai
Child-safety reports: child-safety@routero.ai (we treat these as the highest priority)