IRONKEEP Acceptable Use Policy
Effective Date: July 21, 2026 | Last Updated: July 23, 2026
This Acceptable Use Policy (“AUP”) governs use of the IRONKEEP platform and all of its products and features, including IRONKEEP MAIL, IRONKEEP DRIVE, IRONKEEP CHAT, and IRONKEEP MEETINGS (collectively, the “Services”), operated by DatumWard Technologies, LLC (“IRONKEEP,” “we,” “us,” or “our”). This AUP is incorporated into and forms part of the IRONKEEP Terms of Service. Capitalized terms used but not defined here have the meanings given in the Terms of Service. This AUP supplements the Terms of Service; in the event of a conflict between this AUP and the Terms of Service, the order of precedence set out in the Terms of Service governs.
The Services are designed for organizations, including enterprises and government agencies, and for individuals using the free tier. This AUP applies to the Customer and to every Authorized User the Customer provisions.
1. Purpose & Scope
1.1 Purpose. This AUP describes content and conduct that are prohibited on the Services. Its goals are to protect the integrity, security, availability, and lawful operation of the Services; to protect IRONKEEP, its Customers, Authorized Users, and third parties; to preserve email deliverability and platform reputation; and to support the security and compliance posture for which the Services are architected. The categories below are illustrative and not exhaustive; IRONKEEP may treat other conduct that is unlawful, abusive, or harmful to the Services or third parties as a violation of this AUP.
1.2 Who is bound. This AUP applies to:
- the Customer (the Organization, or the free-tier individual that agrees to the Terms);
- every Authorized User the Customer provisions and permits to use the Services, whether directly or through an identity-management service; and
- any other person who accesses or uses the Services through the Customer’s Organization or credentials, including guests who join IRONKEEP MEETINGS or who interact with shared IRONKEEP DRIVE content.
1.3 Customer responsibility for its users. The Customer is responsible for all activity that occurs under its Organization and through its Authorized Users and credentials, and for ensuring that each Authorized User and any guest it permits to access the Services complies with this AUP. The Customer must communicate the substance of this AUP to its Authorized Users as necessary and is responsible for enforcing acceptable use within its own Organization. A violation by an Authorized User is treated as a violation by the Customer.
1.4 Free-tier individuals. Where the Customer is a free-tier individual provisioned under a shared, platform-operated Organization, that individual is the Customer for purposes of this AUP and is responsible for its own use of the Services. The free tier is provided “as is” and may be changed or discontinued at any time, including in response to actual or suspected AUP violations.
1.5 Relationship to other agreements. Nothing in this AUP limits any obligation under the Terms of Service or the IRONKEEP Data Processing Addendum. The Customer remains independently responsible for compliance with all applicable laws in its use of the Services.
2. Prohibited Content
The categories in this Section are illustrative and not exhaustive. The Customer and its Authorized Users must not use the Services to upload, store, send, receive, host, transmit, edit, share, or otherwise make available any content (including emails, files, documents, chat messages, calendar events, contacts, attachments, and meeting content) that:
2.1 Is illegal. Violates any applicable law, regulation, court order, or the legal rights of any person, including content that is itself unlawful to possess, transmit, or distribute.
2.2 Infringes intellectual property. Infringes, misappropriates, or violates any patent, copyright, trademark, trade secret, moral right, or other intellectual property or proprietary right of any party, including unauthorized copying, distribution, or storage of copyrighted works.
2.3 Contains malware or exploits. Contains, distributes, or facilitates the distribution of viruses, worms, trojans, ransomware, spyware, keyloggers, malicious scripts, or any other malicious or harmful code; or contains exploits, exploit kits, or instructions designed to gain unauthorized access to, disable, or damage any system, network, or data. This includes attempts to deliver such content as email or document attachments, IRONKEEP DRIVE uploads, or IRONKEEP CHAT attachments. The Services apply automated security controls (including malware scanning of inbound and outbound content, link-safety lookups on inbound email, and attachment handling) to the content they process; the Customer must not attempt to defeat, evade, or test these controls except as expressly permitted under Section 7.
2.4 Constitutes child sexual abuse material (CSAM) — zero tolerance. IRONKEEP maintains a strict zero-tolerance policy for any content that sexually exploits or endangers children, including child sexual abuse material. Such content is strictly prohibited. Where IRONKEEP becomes aware of apparent CSAM, it will remove or disable access to the content, preserve it as required by law, terminate the responsible account, and report it to the National Center for Missing & Exploited Children (NCMEC) and/or appropriate authorities as required by applicable law. Mandatory legal reporting obligations will be honored regardless of any other provision of the Terms of Service, this AUP, or the IRONKEEP Privacy Policy.
2.5 Violates the rights of others. Is defamatory, libelous, fraudulent, harassing, abusive, threatening, or that promotes or incites violence, self-harm, terrorism, or unlawful discrimination; or that violates the privacy, publicity, or contractual rights of any person.
2.6 Is deceptive. Is designed to deceive recipients as to its origin, sender, or purpose, including phishing content, forged or spoofed communications, and impersonation of any person or entity.
3. Prohibited Conduct
The categories in this Section are illustrative and not exhaustive. The Customer and its Authorized Users must not, and must not permit any person to:
3.1 Gain unauthorized access. Access or attempt to access any account, Organization, data, system, or network without authorization, including accessing Customer Data belonging to another Customer.
3.2 Circumvent security or data separation. Defeat, bypass, disable, or attempt to circumvent any security, authentication, authorization, encryption, rate-limiting, data-separation, or other access control of the Services. The Customer must not attempt to access, infer, or interfere with data outside its own Organization.
3.3 Probe, scan, or test without authorization. Conduct any penetration test, vulnerability scan, load test, automated probing, or other security or performance testing of the Services or the underlying infrastructure without IRONKEEP’s prior written authorization. Good-faith vulnerability reporting is addressed in Section 7.
3.4 Interfere with the Services or other customers. Take any action that imposes an unreasonable or disproportionate load on the Services, degrades performance, or interferes with or disrupts the integrity or availability of the Services, the underlying infrastructure, or any other Customer’s or Authorized User’s use of the Services.
3.5 Misrepresent identity. Impersonate any person or entity, misrepresent affiliation with any person or entity, forge or manipulate identifiers, headers, or metadata, or otherwise misrepresent the source or authenticity of any communication or activity on the Services. This includes misuse of sending identities, custom domains, or federated or automatically provisioned identities.
3.6 Misuse credentials and administrative roles. Share, sell, or transfer credentials in violation of the Terms of Service; misuse privileged roles; or use legal-hold, audit, data-protection, or access-control capabilities for any purpose other than the lawful administration of the Customer’s own Organization.
3.7 Reverse engineer. Reverse engineer, decompile, or disassemble any part of the Services, or attempt to derive source code, underlying ideas, or non-public algorithms, except to the limited extent applicable law expressly permits despite this restriction.
4. Email & Messaging Use
The Customer’s use of IRONKEEP MAIL, and any other messaging capability of the Services, must comply with all applicable laws and the following requirements.
4.1 No unsolicited bulk or commercial email (spam). The Customer and its Authorized Users must not use the Services to send unsolicited bulk email or unsolicited commercial email, or to participate in any form of spamming. All commercial and bulk email must be sent only to recipients who have provided appropriate consent or with whom the sender has an established relationship permitted by applicable law.
4.2 Compliance with anti-spam laws. The Customer must comply with all applicable anti-spam, electronic-marketing, and consumer-protection laws (such as the U.S. CAN-SPAM Act and any other laws applicable in the jurisdictions of the sender and recipients). This includes providing accurate header and sender information, accurate and non-deceptive subject lines, a clear and functioning opt-out/unsubscribe mechanism where required, and honoring opt-out requests promptly.
4.3 No spoofing or forged headers. The Customer and its Authorized Users must not forge, falsify, or manipulate email headers, envelope information, sender identities, or routing data, and must not send messages that misrepresent their origin.
4.4 List hygiene and consent. The Customer is responsible for maintaining the lawfulness and quality of its recipient lists, including obtaining and documenting any required recipient consent, suppressing addresses that have opted out or generated complaints, and avoiding sending to harvested, purchased, or otherwise improperly obtained address lists.
4.5 No phishing or malicious messaging. The Customer and its Authorized Users must not use the Services to send phishing messages, fraudulent solicitations, business-email-compromise content, or messages designed to deceive recipients into disclosing credentials, payment information, or other sensitive data, or into installing malware.
4.6 Outbound controls, deliverability, and reputation protection. Outbound communications and uploads are subject to IRONKEEP’s automated abuse, data-protection, anti-spam, and reputation-protection controls. To protect platform deliverability and the shared sending reputation of the Services, IRONKEEP may inspect, throttle, queue, quarantine, reject, suspend, or otherwise limit sending or content that it reasonably determines is abusive, non-compliant with this AUP, harmful to deliverability, or in violation of applicable law. These measures may apply to outbound email, file uploads, chat messages, and attachments. The Customer acknowledges that such controls may delay or prevent delivery of non-compliant content.
5. Network & System Abuse
The Customer and its Authorized Users must not:
5.1 Conduct denial-of-service activity. Launch or participate in any denial-of-service (DoS) or distributed denial-of-service (DDoS) attack, or any other activity intended to disrupt, overload, or impair the Services or any system or network.
5.2 Consume resources excessively. Consume computing, storage, bandwidth, mailbox, or other resources in a manner that is excessive relative to the Customer’s plan or that materially and unreasonably burdens the Services or other Customers. Paid plans are subject to usage metering and to the limits set out in the applicable plan or Order Form.
5.3 Mine cryptocurrency. Use the Services to mine cryptocurrency or perform comparable resource-intensive computation unrelated to the intended productivity functions of the Services.
5.4 Engage in automated abuse. Use bots, scrapers, crawlers, or other automated means to abuse, overload, or extract data from the Services in violation of this AUP or the Terms of Service. Legitimate, authorized programmatic use of documented interfaces in accordance with the Terms of Service and applicable rate limits is permitted.
5.5 Resell without authorization. Resell, sublicense, rent, lease, or otherwise make the Services available to third parties except as expressly authorized in writing by IRONKEEP or in an applicable Order Form.
6. Data & Privacy of Others
6.1 Lawful basis. The Customer and its Authorized Users must not use the Services to collect, store, process, or transmit the Personal Data of any individual without a valid lawful basis and in compliance with all applicable data-protection and privacy laws.
6.2 No unlawful harvesting. The Customer and its Authorized Users must not harvest, scrape, or otherwise collect email addresses, contact information, or other Personal Data through unlawful means, and must not use the Services to facilitate such collection.
6.3 Respect for individual rights. The Customer must respect the privacy and data-protection rights of the individuals whose Personal Data it processes through the Services, and must not use the Services to surveil, track, or profile individuals in violation of applicable law.
6.4 Controller responsibility. As between IRONKEEP and the Customer, the Customer is responsible for determining the purposes and means of its processing of Customer Data and for the lawfulness of that processing. IRONKEEP’s processing of Customer Data on the Customer’s behalf is governed by the IRONKEEP Data Processing Addendum and the IRONKEEP Subprocessors list.
7. Security Research & Responsible Disclosure
7.1 Reporting vulnerabilities. IRONKEEP welcomes good-faith reports of security vulnerabilities. If you believe you have discovered a security vulnerability in the Services, please report it promptly to security@ironkeep.us with sufficient detail to reproduce and assess the issue. Do not publicly disclose a vulnerability before IRONKEEP has had a reasonable opportunity to investigate and remediate it.
7.2 Good-faith research expectations. Security research is permitted only when conducted in good faith and within the following boundaries:
- you must have prior written authorization from IRONKEEP before conducting any penetration testing, vulnerability scanning, or active probing of the Services (see Section 3.3);
- you must act only against accounts, Organizations, and data that you own or are expressly authorized to test;
- you must not access, modify, delete, exfiltrate, or retain Customer Data belonging to any other Customer or Authorized User;
- you must not degrade, disrupt, or impair the Services or other Customers’ use of them;
- you must not exploit a vulnerability beyond the minimum extent necessary to confirm its existence; and
- you must comply with all applicable laws.
7.3 No exfiltration. Under no circumstances may any person exfiltrate, publish, sell, or otherwise misuse data belonging to others discovered during research. Suspected unlawful access or data exposure must be reported under Section 7.1 and not exploited.
7.4 Good-faith protections. IRONKEEP does not intend to pursue action against security researchers who report vulnerabilities in good faith and in compliance with this Section 7. This section does not, however, grant authorization that overrides the requirements of Sections 3.1–3.3, and it does not waive the rights of any third party.
8. Regulated & Sensitive Data
8.1 Customer responsibility for lawful use. The Services are architected and designed to align with the FedRAMP Moderate baseline and NIST SP 800-53 controls and to support FedRAMP-oriented and government workloads. However, IRONKEEP is not currently FedRAMP authorized or certified, does not hold an Authorization to Operate (ATO), and is not listed on the FedRAMP Marketplace. Nothing in this AUP constitutes a representation of certification, authorization, ATO, or audited compliance with any standard. The Customer is solely responsible for determining whether its intended use of the Services — including the specific categories of data it handles and the legal, regulatory, and contractual requirements applicable to that data — is lawful and appropriate.
8.2 Regulated data. Before using the Services to process any data subject to heightened legal or regulatory requirements, the Customer is responsible for confirming that such use is permitted and that any required safeguards, agreements, or certifications are in place. Where the Customer requires a specific certification, authorization, or contractual control commitment, that must be addressed in a separate written agreement (for example, an ENTERPRISE agreement or Order Form); absent such a writing, the Customer must not rely on the Services for use cases that require commitments IRONKEEP has not made.
8.3 Export control and sanctions. The Customer and its Authorized Users must comply with all applicable export-control, import-control, and economic-sanctions laws and regulations. The Customer must not use the Services, or permit the Services to be used, in violation of any such laws, including by or for the benefit of any person, entity, or jurisdiction subject to applicable sanctions or embargoes, or to transmit controlled technical data in violation of applicable export controls.
8.4 Deployment region. Government workloads may be supported in specialized U.S. government cloud environments; standard deployments use U.S.-based infrastructure. The Customer is responsible for selecting and contracting for the deployment that meets its regulatory requirements and must not assume that any particular regulatory boundary applies absent a written agreement specifying it.
9. Enforcement
9.1 Investigation. IRONKEEP may investigate suspected violations of this AUP using available metadata, abuse signals, automated security results, audit logs, lawful reports, and information provided by the Customer. IRONKEEP does not routinely inspect message or file content, has no obligation to monitor or pre-screen Customer Data, and does not guarantee that automated controls will detect every violation. The Customer must cooperate with reasonable requests for information in connection with an investigation.
9.2 Remedial actions. Where IRONKEEP reasonably determines that a violation has occurred or to prevent imminent harm, IRONKEEP may, with or without prior notice as the circumstances warrant:
- remove, disable access to, quarantine, or restrict the offending content;
- throttle, suspend, or terminate affected sending, features, Authorized User access, or the Organization’s access to the Services in whole or in part;
- suspend or terminate the Customer’s account in accordance with the Terms of Service; and
- take any other action reasonably necessary to protect the Services, other Customers, IRONKEEP, or third parties.
IRONKEEP will endeavor to use the least disruptive measure reasonably appropriate to the violation, but reserves the right to act immediately where there is a risk of serious harm, ongoing illegality, threats to platform security or deliverability, or a legal obligation to act.
9.3 Preservation. IRONKEEP may preserve content and records relevant to a suspected violation or to actual or anticipated legal process. Where a compliance officer of the Customer’s Organization has applied a legal hold, affected data is retained until the hold is released, notwithstanding the standard retention periods described in the Terms of Service and Privacy Policy.
9.4 Cooperation with law enforcement and legal process. IRONKEEP may report suspected unlawful activity to, and otherwise cooperate with, law enforcement and other authorities, and will respond to valid legal process, in each case as permitted or required by applicable law and consistent with the IRONKEEP Privacy Policy and IRONKEEP Data Processing Addendum. Reporting obligations relating to CSAM under Section 2.4 apply regardless of any other provision.
9.5 No waiver; effect of termination. IRONKEEP’s failure to enforce any provision of this AUP is not a waiver of its right to do so later. Suspension or termination for an AUP violation does not entitle the Customer to a refund and does not relieve the Customer of amounts owed. Post-termination data export and deletion are governed by the Terms of Service.
10. Reporting Abuse
To report suspected abuse of, or a violation of this AUP on, the Services — including spam, phishing, malware, intellectual-property infringement, harassment, or other prohibited content or conduct — contact security@ironkeep.us. To report a security vulnerability, contact security@ironkeep.us as described in Section 7. Please include enough detail to allow IRONKEEP to identify and investigate the issue, such as relevant message identifiers, timestamps, URLs, and a description of the activity.
11. Changes to this AUP
IRONKEEP may update this AUP from time to time in accordance with the IRONKEEP Terms of Service. The “Last Updated” date above reflects the most recent revision. Continued use of the Services after an update takes effect constitutes acceptance of the revised AUP.
Contact
DatumWard Technologies, LLC, operating the IRONKEEP platform
- Abuse reports: security@ironkeep.us
- Security reports: security@ironkeep.us
- Support: support@ironkeep.us
- Legal notices: legal@ironkeep.us
- Privacy inquiries: security@ironkeep.us
- Mailing address: 2221 Yellowstone Ranch Court, Waxahachie, TX 75165, United States
- Phone: +1 703-338-6561
- Website: https://www.ironkeep.us/