Skip to content
Legal

Acceptable use policy

Short, specific, and enforced. On Door 1 we are the party your provider sees, so what one customer sends can cost every other customer their access. That is the reason this page is stricter than a policy written by a company that only ever holds metadata.

Last updated 2026-08-01

1. Scope

This policy is part of the terms of service and applies to everyone using Finest: your organisation, your personnel and contractors, your end users, and any automated agent acting for you. You are responsible for their conduct as if it were your own.

It applies to both doors, but it bites hardest on Door 1, where your requests pass through our infrastructure and reach a provider on our credentials.

2. Your provider’s rules are also our rules

Every provider publishes its own usage policies, and those policies continue to apply to traffic routed through us. You must comply with the policies of each provider your routes reach, as they exist from time to time, and where a provider’s policy is stricter than this page, the provider’s policy governs.

If a provider tells us that traffic from your workspace breaches its policies, we will act on that: expect suspension of the affected routes first and questions second. We would rather explain a suspension to you than explain your traffic to a provider that has already cut off every Finest customer.

3. Content you must not send

  • Child sexual abuse material, or any sexual content involving a minor, in any form and for any stated purpose. We report this to the authorities and to the relevant provider, and terminate immediately without notice.
  • Content that sexualises a real person without their consent, including synthetic intimate imagery.
  • Material that incites or facilitates violence, terrorism, or serious harm to a person or group, or that supports a designated terrorist organisation.
  • Malware, ransomware, exploit code intended for use against systems you are not authorised to test, phishing kits, or instructions whose purpose is to compromise a system or a person.
  • Content designed to deceive about its origin: impersonating a real person or organisation, fabricated records or credentials, false attribution of authorship, or synthetic media of an identifiable person presented as genuine.
  • Content that infringes a third party’s copyright, trademark, trade secret, patent, or privacy and publicity rights, including material you do not have the rights to send to a model.
  • Unlawful discrimination, harassment, defamation, or content that violates the law applicable to you or to us.

4. Things you must not do

  • Reselling, sublicensing, brokering or sharing gateway access, or using a Finest key on behalf of a third party as a service.
  • Using the gateway as a general-purpose proxy for traffic unrelated to your own application, or to obtain provider capacity, rate limits, pricing or terms you would not be granted directly.
  • Circumventing or probing a rate limit, quota, credit balance, spend ceiling, clearance flag or safety control, whether ours or a provider’s.
  • Automating account or workspace creation, or creating workspaces to collect promotional credit more than once.
  • Attacking, overloading, degrading or attempting to gain unauthorised access to Finest, a provider, another customer’s workspace, or any system reachable through us.
  • Interfering with the integrity of evidence: falsifying a corpus, laundering already-consumed evidence into a fresh run, or misrepresenting what a receipt or verification record says.
  • Extracting, scraping or reverse engineering the hosted service, or using it to develop a competing product.
  • Bypassing a provider’s safety systems, including by splitting prohibited content across requests, or using the service to generate content a provider has refused to produce.

5. Data the gateway is not built to carry

The gateway keeps no prompt or completion content at rest, and that is a real property of the schema rather than a setting. It is still not the same thing as being an appropriate place to send regulated data, because the obligations that attach to these categories are about contracts, controls and audits we have not put in place yet. So unless we have agreed otherwise in a signed writing that names the category, do not send:

  • Protected health information, or any data subject to HIPAA or an equivalent health-privacy regime.
  • Payment card numbers and cardholder data subject to PCI DSS.
  • Government identity numbers, passport and driving licence data, and financial account credentials.
  • Biometric identifiers, genetic data and precise geolocation.
  • Special-category personal data as defined by UK or EU data protection law, including data revealing racial or ethnic origin, political opinions, religious belief, trade union membership, health, sex life or sexual orientation.
  • Personal data of children, or data collected from a service directed at children.
  • Classified, export-controlled or otherwise government-restricted technical data.

We are not a HIPAA business associate, we are not in PCI DSS scope, and we will not sign a business associate agreement in this release. When that changes we will say so here with the date, not imply it with a badge.

6. High-risk and regulated uses

Do not use the service where a failure could reasonably lead to death, personal injury, or severe environmental or property damage, and do not build it into a medical device, a safety system, a weapons system, or critical infrastructure control.

For decisions that materially affect a person’s rights or livelihood, including employment, credit, housing, insurance, education, immigration and criminal justice, and for legal, medical or financial advice, a qualified human has to make the decision and be accountable for it. A model output is an input to that decision, and the service is not designed to be the decision itself.

7. Security research

We want to hear about vulnerabilities, and the security page sets out the disclosure process and the safe harbour that comes with following it. Testing outside that scope is not research: do not use another customer’s data, do not run load or denial-of-service tests, do not attempt to reach provider credentials, and do not test a provider’s systems through us. Report to [email protected] and give us a chance to fix it before you publish.

8. What happens when a line is crossed

Depending on what happened, we may warn you, throttle or suspend a route, key or workspace, remove access to a provider, refuse to serve particular traffic, or terminate the agreement. For anything involving child safety, an active attack, or a provider demand, we act first and explain afterwards. For everything else we will tell you what we saw and give you a chance to fix it where the circumstances allow.

Termination for a breach of this policy does not entitle you to a refund of Credits already consumed, and it does not relieve you of amounts already owed. Where a breach costs us a provider relationship, a penalty or a third-party claim, section 17 of the terms applies.

9. Reporting abuse

To report abuse of Finest, including content served through it, write to [email protected]. Include enough detail for us to find it: a receipt reference, a timestamp, or a workspace identifier. Reports reach a person, not a queue.

10. Changes

We may update this policy, and a change takes effect when it is posted here and dated. Because the rules a provider imposes on us can change without notice to us, a change that only reflects a provider’s new requirement can take effect immediately; we will record it in the changelog.

This policy is operated by PM Frontier LLC, a Wyoming limited liability company. Legal notices take effect when delivered in writing to:

PM Frontier LLC30 N Gould StSheridan, WY 82801United States

Email to [email protected] reaches us faster and is sufficient for everything except a formal notice under the terms. Other routes are on the contact page.

Acceptable use · Finest