Legal
Acceptable Use Policy
Last updated: 31 August 2026 · v1.0. This policy is part of the Terms of Service. It exists to protect the service and every tenant on it — including you.
Don't
- Use the service to violate law, or connect content you have no right to connect.
- Probe, scan, or test the service's isolation — attempt to reach another organisation's data, forge webhook deliveries or tokens, or bypass authentication, rate limits, or plan limits.
- Interfere with the service: denial-of-service, resource abuse, or automated load far outside normal review traffic.
- Resell, sublicense, or offer the service to third parties as your own, or use it to build a directly competing review service by systematic extraction of its outputs.
- Misrepresent Deltz's output — presenting findings, receipts, or compliance tags as a certification of security or compliance is both untrue and a breach of this policy.
- Use AI-drafting features to generate content that is unlawful or intended to harm systems you do not control.
Security research
We welcome good-faith security research against your own tenant. Found something? Write to hello@winchlabs.io with "Security" in the subject. Give us a reasonable window to fix before public disclosure; don't access other tenants' data (if isolation fails, stop and report); and we will not pursue good-faith research conducted within these bounds.
Enforcement
We prefer a conversation; we may suspend first where protection of the service or other tenants requires it, and terminate for serious or repeated violations, per the Terms.