Acceptable use policy

What you may and may not do with Grayson.

The Acceptable Use Policy is part of the Master Services Agreement and applies to everyone in your organization who uses Grayson.

Grayson exists to detect and prevent fraud and financial crime, so analyzing data about fraud, scams, money laundering or trafficking in order to catch it is exactly what it's for. The policy prohibits using Grayson to carry out, enable or conceal harm. In particular:

  • Decisions about people: no decisions based on characteristics protected by law, no decisions with legal or similarly significant effects based solely on Grayson's answers, and no surveillance of legally protected activity.
  • Testing controls: no using Grayson to find ways past fraud, anti-money-laundering, sanctions or identity controls, except to strengthen controls you operate.
  • Data you send: no full card numbers, security codes, PINs, passwords, one-time codes, API keys, health information or biometric identifiers; full government ID numbers only when a question requires them and the law allows. Use masked or tokenized values instead.
  • Security: no scraping, sharing accounts, getting around rate limits or access controls, or probing or load-testing the service without written permission. Email support@finic.ai to arrange a test.
  • Children: no exploiting or endangering children. Detecting and reporting the exploitation of children is permitted, but never include abuse material in a request.

Report suspected violations to support@finic.ai.