Skip to content

Responsible AI · Security

Acceptable Use Policy

Last updated: 2026-08-31. These rules form part of the Terms and protect users, affected persons and Kasp's integrity.

01 Purpose

Principle

Kasp is intended for research, structuring, task-based analysis, learning and transformation planning. Users remain responsible for their inputs, specific use, human oversight and compliance with all applicable laws.

Kasp supports decisions with traceable evidence, uncertainty and open questions; it does not make decisions about individuals. Organisational analyses, including Orbit, remain focused on roles, tasks, programmes, systems or aggregates.

02 Rules

What is not permitted

  1. 01Lawful useKasp must not be used for illegal content or actions, fraud, deception, identity misuse, harassment, discrimination, infringement of copyright, trademark, personality or data protection rights, or to circumvent legal obligations.
  2. 02No prohibited AI practicesIn particular, manipulative or exploitative practices, social scoring, impermissible biometric categorisation, emotion recognition in workplaces or educational institutions, unlawful facial image databases and other uses prohibited by the EU AI Act are prohibited.
  3. 03No employment decisions about individualsKasp is not approved for assessing, ranking, selecting, monitoring, promoting or dismissing applicants or employees, or for automatically assigning tasks based on personal characteristics. Only role-, task- or organisation-based analyses without decisions about identified individuals are permitted.
  4. 04No individual decisions in sensitive areasKasp must not be used, either on its own or as a recommendation system, to assess, rank, admit, reject or otherwise make decisions about individuals concerning admission to or assessment in education, creditworthiness, insurance risk or pricing, public benefits, migration, law enforcement, justice, biometrics or emotions. Human review does not remove this product limit. General, aggregated and non-personal analyses remain permitted.
  5. 05Data minimisation and authorisationUsers may submit only data and files for which they have a sound legal basis for processing and the necessary rights. Special categories of personal data, criminal offence data, professional secrets, trade secrets and identifiable employee data should not be entered without documented approval.
  6. 06Security and system integrityMalware, phishing, exploitation of vulnerabilities, circumvention of access controls, load or attack testing without approval, prompt injection against others' data, automated scraping, reverse engineering beyond statutory permissions, and sharing access credentials are prohibited.
  7. 07Transparent sharingAI-generated content must not be presented as guaranteed human-made or authentic. Visible AI notices, sources, uncertainties and provenance features must not be misleadingly removed. Deepfakes and published AI-generated text on matters of public interest must be labelled in accordance with applicable rules.
  8. 08No circumvention of plans or safeguardsAllowances, roles, security filters, rate limits, file checks, billing restrictions and access restrictions must not be circumvented, manipulated or abusively multiplied through multiple accounts.

03 Measures

Review, suspension and reporting

Kasp may technically restrict content, decline an operation or temporarily suspend an account following appropriate review if there is a concrete suspicion of a significant breach. Where reasonable, the user is informed and given an opportunity to respond or remedy the issue. Immediate action may be necessary in the event of acute security risks, unlawful use or mandatory official orders.

Suspicious or harmful use, security issues and incorrect AI outputs can be reported to kontakt@kasp.ai . Specific allegedly illegal content can be reported through the DSA reporting channel.

Also applicable are the Terms, the Privacy Policy and the information under AI transparency.