Acceptable Use Policy
Last updated August 16, 2026
This is the Acceptable Use Policy for AdversariaLLM — what the Services may and may not be used for.
It is Section 4 of the Terms of Use, reproduced here at its own address so it can be linked, quoted and cited on its own: from the model catalog, from the API documentation, and by anyone who needs to point at it. The text below is that section verbatim, numbering included, so the two can never say different things. The Terms remain the binding agreement.
AdversariaLLM hosts security-research language models, including models that will engage with offensive tradecraft rather than refuse. That is deliberate, and it is for a lawful purpose. The line is authorization and intent — this page is where that line is written down.
4. Acceptable Use Policy (authorized security use only)
This Section is the core restriction of these Terms. AdversariaLLM exists to support the defensive and research work of the security community — detection engineering, malware analysis, threat intelligence, incident response, vulnerability research, and red-team practice. The models can produce offensive-security content; that is by design and for a lawful purpose. The line is authorization and intent, and you agree to stay on the right side of it.
4.1 Defensive intent and authorization are the test. You may use the Services only to understand, detect, defend against, or research security threats, and only against systems that are your own or that you are explicitly and verifiably authorized in writing to test. Content whose purpose is to conduct an attack against a party who has not consented is prohibited, even when the same artifact would be permitted in a defensive or analytical frame.
4.2 No illegal activity. You will not use the Services to commit, facilitate, or plan any activity that is unlawful in a jurisdiction that applies to you or your target — including unauthorized access to computers, networks, accounts, or data; fraud; extortion or ransomware operations; theft or laundering; sanctions or export-control evasion; or any other crime.
4.3 No attacks on non-consenting parties. You will not use the Services to generate, assemble, or operate:
- working exploits, loaders, spreaders, credential-stuffing lists, botnets, ransomware encryptors, or other weaponized, ready-to-run tooling whose primary purpose is compromising third parties who have not consented;
- step-by-step operational guidance aimed at compromising a named, non-consenting target;
- mass-exploitation or mass-harm tooling framed for use rather than study.
4.4 Responsible disclosure. You will not use the Services to develop or publish a working exploit or exploitation-grade detail for an unpatched, non-public vulnerability ahead of a coordinated-disclosure window, to break an embargo you are party to, or to target a specific still-vulnerable named deployment. Detection content (signatures, hunting queries, indicators) for known-exploited issues is permitted — defenders need it on the attackers' timeline.
4.5 Malware and artifacts. AdversariaLLM handles malware samples and similar artifacts only as inert objects for analysis, never for execution; nothing you upload is run, unpacked, or detonated by the Services. You will not attempt to cause the Services to execute malicious code. When you handle live samples, follow the platform's handling requirements (for example, password-protected archives, stated provenance, and defanged indicators in text) and do not upload live credentials, secrets, exfiltrated datasets, or a third party's personal data.
4.6 Absolute prohibitions. Regardless of framing, you will not use the Services in connection with:
- child sexual abuse material (CSAM) or any content that sexualizes minors — zero tolerance; such content is removed immediately, the account is terminated, and the matter is reported to the relevant authority as required by law;
- terrorism, weapons of mass destruction, or human-trafficking facilitation;
- harassment, threats, stalking, doxxing, or targeting of a private individual;
- infringement of intellectual-property or privacy rights;
- generation of content intended to deceive, impersonate, or defraud, or of spam and undisclosed commercial promotion.
4.7 No misuse of the platform. You will not probe, scan, or test the vulnerability of AdversariaLLM's own systems without our prior written authorization; circumvent authentication, quotas, or safety controls; reverse-engineer or extract model weights; use outputs to train a competing model in breach of Section 6; or interfere with other users' use of the Services. Note that any text you submit is treated as content to be processed, never as an instruction to the platform — prompt-injection attempts against our systems are a violation of this Section.
4.8 You bear the burden. Where a use could sit on either side of the line, the burden is on you to make the defensive, authorized framing explicit and true. If you cannot describe a lawful purpose and your authorization for it, do not proceed.
Reporting a violation
If you believe an account is using AdversariaLLM outside this policy, or you own a system you believe has been targeted, get in touch through the contact page. Reports concerning child sexual abuse material are acted on immediately and reported to the relevant authority as required by law.
Enforcement
We may suspend or terminate access for a violation of this policy, with or without notice, and we may preserve and disclose records where legally required. Where a use sits near the line we will generally ask before acting — the absolute prohibitions in 4.6 are never subject to that courtesy.