Legal

Acceptable Use Policy

Version 1.0 · Effective 21 August 2026

1. Scope

This Acceptable Use Policy (“AUP”) governs your use of the Cirrova platform and any related APIs, documentation and support channels (together, the “Service”). It applies to you, to every user you invite or provision, and to anyone using credentials issued under your account.

Where you have purchased the Service through Microsoft Marketplace, this AUP is incorporated into your agreement with Cirrova by the Cirrova amendment to the Microsoft Standard Contract. Where you have purchased directly, it is incorporated by our Terms of Service. In either case it is a contractual term, not guidance.

You are responsible for your users’ compliance with this AUP. A breach by a user of your account is a breach by you.

2. General restrictions

You must not, and must not permit anyone else to:

  • Use the Service for any unlawful purpose, or in breach of any law, regulation or third-party right that applies to you;
  • Reverse engineer, decompile or disassemble the Service, or attempt to derive its source code, except to the extent this restriction cannot be excluded by law;
  • Separate, extract or independently use any component of the Service;
  • Circumvent, disable or interfere with any technical limitation, access control, rate limit or security measure in the Service;
  • Rent, lease, lend, sell, transfer, sublicense or host the Service for the benefit of a third party, except as expressly permitted in section 5;
  • Publish or disclose the results of any benchmark or performance test of the Service without our prior written consent;
  • Use the Service in a way that damages, disables, overburdens or impairs it, or that degrades it for any other customer.

3. Azure connections

Cirrova reads cost and resource data from Azure subscriptions you connect to it. You must not connect an Azure tenant or subscription unless you are authorised by its owner to grant Cirrova read access to it and to have its cost and resource data processed by Cirrova.

You must not use the Service, or attempt to use it, to access data belonging to any tenant, subscription or Cirrova organisation other than those you are authorised to access. If you become aware that the Service has exposed data you are not authorised to see, you must stop using the affected feature and notify us immediately at security@cirrova.io.

Where you connect a tenant on behalf of a customer of yours, you are responsible for holding that customer’s authority to do so and for your own obligations to that customer in respect of their data.

4. Platform limits

  • API access is subject to published rate limits. You must not exceed them, and you must not attempt to evade them by distributing requests across multiple keys, accounts or organisations;
  • You must not scrape, crawl or systematically extract data from the web interface. Where you need bulk access to your data, use the API or the export features provided;
  • You must not use the Service to store or transmit material that is unlawful, or that contains malware or other harmful code;
  • API keys are issued to a named user and inherit that user’s access scope. You must not share a key across users, embed one in client-side code, or use a key to grant access beyond the scope of the user it was issued to.

5. Resale and service bureau use

You must not resell, sublicense or otherwise make the Service available to third parties, and must not operate it as a service bureau, without our prior written consent.

This does not restrict multi-organisation use by a managed service provider operating under a Cirrova Partner agreement, which is expressly permitted within the scope of that agreement.

6. Security testing

You must not conduct penetration testing, vulnerability scanning, load testing or any other security or availability testing against Cirrova infrastructure without our prior written consent. Requests should be sent to security@cirrova.io and will not be unreasonably refused.

This restriction does not prevent you from reporting a vulnerability you discover in the ordinary course of using the Service. We welcome such reports and will not pursue a customer who reports a genuine finding in good faith and does not exploit it further.

7. Enforcement

Where you have purchased the Service through Microsoft Marketplace, clause 6 of the Cirrova amendment to the Microsoft Standard Contract governs enforcement of this AUP. It provides:

“Cirrova’s Acceptable Use Policy at cirrova.io/legal/aup applies. Cirrova may suspend under SC 10.4 on such notice as is reasonable, including without notice where necessary to address a security or legal risk.”

Where you have purchased directly, the equivalent right is in section 8 of our Terms of Service and is exercised on the same basis: on such notice as is reasonable, and without notice only where necessary to address a security or legal risk.

Where we suspend without prior notice, we will tell you promptly afterwards and explain what is required to restore access.

8. Reporting abuse

To report suspected misuse of the Service, abusive content, or a suspected security vulnerability, contact security@cirrova.io. Please include enough detail for us to reproduce or locate the issue.

For all other questions about this policy, contact hello@cirrova.io.

9. Version history

Superseded versions of this policy remain available at the URLs below. If you purchased a subscription while an earlier version was in force, that version continues to apply to you for the remainder of your term.