Legal
Acceptable Use Policy
Last updated: 25 August 2026
1. Scope
This Acceptable Use Policy ("AUP") applies to every firm, staff member, client, and visitor who accesses Comply.LM, including the workspace, client portal, consultation request flow, the public eligibility-check flow, the blog, the in-app AI helpdesk assistant, staff training, public APIs, and webhook endpoints. By using Comply.LM you agree to this AUP.
Comply.LM is currently in Beta. Features and limits may change. We will update this AUP as the product evolves.
2. Permitted use
- Enrolling your firm with AUSTRAC workflows, onboarding staff and completing staff personal due diligence (PDD) and training, onboarding clients, running KYC/KYB, completing AML/CTF risk assessments, and storing supporting documents for your firm.
- Managing your firm's staff, organisation profile, key representative profile, matters, consultations, AUSTRAC transactional reporting, Annual Compliance Report (ACR) drafting, and record-keeping workflows.
- Using the public eligibility-check flow to determine your own or your business's obligations, and paying the associated fee where applicable.
- Operating your firm's tenant within the role-based access model — Tenant Admin controls are scoped to your tenant only.
3. Account, role, and tenancy rules
- Keep credentials confidential. Do not share staff accounts.
- Use multi-factor authentication if available and rotate credentials when staff leave.
- Tenant Admins manage their own tenant. They must not attempt to access another tenant's data or the Platform Admin scope.
- Platform Admin is reserved for Comply.LM operations and is separated from tenant data by design.
4. Data you upload
- Upload only data you are legally entitled to process — for example, client identity documents you have collected with appropriate consent and legal basis.
- Do not upload payment card numbers, full bank credentials, medical records, or other categories of data not required for compliance workflows.
- Keep client records accurate and up to date. Remove records you no longer need.
5. Prohibited activities
You must not, and must not allow any user to:
- Attempt to bypass authentication, Row Level Security, role checks, or tenancy boundaries.
- Probe, scan, or stress test the service without prior written consent. This includes automated scraping of the helpdesk assistant, the blog, the eligibility-check flow, the consultation flow, or public API endpoints.
- Submit false or misleading information in the eligibility check, KYC/KYB, staff PDD, or consultation flows, including impersonating another person or business.
- Abuse OTP, magic-link, invite, or password-reset flows, including generating them at high volume or targeting addresses you do not control.
- Submit unlawful, harassing, defamatory, fraudulent, or misleading content.
- Upload malware, viruses, or files designed to interfere with the service or other users.
- Reverse engineer, copy, or attempt to extract source data beyond your own tenant.
- Use Comply.LM to send spam, mass marketing, or unsolicited communications, including via connected custom sending domains.
- Forge or replay webhook signatures, or call public API endpoints in ways that violate signature or rate limits.
- Use the in-app AI helpdesk to generate content that violates law, infringes rights, or impersonates a real person, or to attempt to extract data outside its documentation scope.
- Use Comply.LM to facilitate money laundering, terrorism financing, sanctions evasion, or any other illegal purpose.
6. Integrations, payments, and domains
- Stripe and PayPal connections used for consultation payments must be your firm's own accounts. Do not connect accounts you are not authorised to use.
- Eligibility-check fees and platform subscriptions are processed by Comply.LM's merchant accounts. Do not attempt chargeback abuse or fraudulent disputes.
- Custom sending domains and custom app domains must be under your control. Verify DNS records only for domains you own.
- Webhook endpoints under /api/public/* are protected by signature verification. Do not attempt to invoke them without a valid signature.
7. Beta program
- The service is provided as a Beta. Functionality, limits, and pricing may change without notice.
- Maintain your own backups of records you consider business critical.
- Report bugs and risks via the in-app support channel. We triage reports continuously and improve the service based on user feedback.
8. Enforcement
We may suspend or terminate access if we reasonably believe this AUP has been breached. Where possible we will give notice and the opportunity to remediate first. For serious or ongoing breaches, including suspected fraud or unlawful use, we may act immediately.
9. Reporting abuse
If you believe another user, a third party, or content on Comply.LM violates this AUP or applicable law, report it via the in-app support channel. Include enough detail to allow us to investigate.
10. Changes
We may update this AUP from time to time. Material changes will be posted here and noted in-app, with the "Last updated" date above adjusted accordingly.
