Acceptable Use Policy
Last updated: August 17, 2026
1. Purpose
This Acceptable Use Policy ("AUP") outlines the permitted and prohibited uses of BlueSentinel products and services. It is designed to protect our customers, their employees, and the integrity of the BlueSentinel platform.
2. Permitted Uses
BlueSentinel may be used for:
- Preventing unauthorized data exfiltration from organization-owned or managed devices
- Enforcing data protection policies on corporate endpoints
- Monitoring compliance with organizational security policies
- Managing disk encryption and recovery keys across your fleet
- Generating security audit reports for compliance purposes
- Protecting sensitive business data including customer records, financial data, PII, intellectual property, and trade secrets
3. Prohibited Uses
You shall not use BlueSentinel for:
- Personal Surveillance: Monitoring individuals for personal, non-business purposes or stalking
- Unauthorized Monitoring: Deploying on devices without proper legal authority, employee notification, or required consent
- Discrimination: Using monitoring data to discriminate against employees based on protected characteristics
- Harassment: Using collected data to harass, intimidate, or retaliate against individuals
- Personal Devices: Deploying on employees' personal devices without explicit written consent
- Illegal Activities: Any use that violates applicable local, state, national, or international law
- Competitive Intelligence: Using BlueSentinel to spy on competitors, partners, or third parties
- Circumventing Laws: Using the platform to circumvent data protection, privacy, or labor laws
4. Employee Notification Requirements
You must inform employees before deploying BlueSentinel.
Customers are required to:
- Provide clear written notice to all employees whose devices will be monitored
- Explain what data is collected, how it is used, and how long it is retained
- Include DLP monitoring disclosure in employment agreements or IT acceptable use policies
- Comply with jurisdiction-specific employee monitoring notification laws
5. Data Handling
- Collected data should be used only for its stated security purpose
- Access to monitoring data should be limited to authorized security personnel
- Data retention policies should be implemented and followed
- Monitoring data should not be shared with unauthorized parties
6. Enforcement
Violation of this AUP may result in suspension or termination of your BlueSentinel license. We reserve the right to investigate reported violations and take appropriate action, including reporting illegal activity to law enforcement authorities.
7. Reporting Violations
To report a suspected violation of this policy, contact legal@bluesentinel.io.