Acceptable Use Policy
Cedent AI, Inc. · Version 1.0 · Effective September 1, 2026
Incorporated into the Cedent AI Terms of Service. “You” means the Customer firm and every Authorized User.
1. The Principle
Cedent is a professional tool for licensed U.S. attorneys handling privileged client material. Use it for your law practice, on matters you are authorized to handle, with data you are entitled to submit. Most of what follows is that principle applied.
2. Eligibility
You may use the Service only if you are:
- (a) a licensed attorney in good standing in a U.S. jurisdiction; or
- (b) an employee or contractor of a Customer firm working under the supervision of such an attorney.
You must not use the Service if you are suspended, disbarred, or otherwise not authorized to practice; you are a self-represented litigant seeking help with your own matter; or you are a non-lawyer seeking to provide legal services to others.
If an Authorized User’s license lapses or is suspended, notify us and deprovision the seat.
3. Prohibited Uses
3.1 Unauthorized practice of law
Do not use the Service to practice law without authorization, or to assist anyone else in doing so.
Do not give a person who is not an Authorized User access to the Service, and do not supply Outputs as a substitute for that person obtaining their own subscription — including by reselling Outputs, operating a document-preparation or self-help service, or acting as an intermediary for a non-lawyer’s legal work.
This does not restrict delivery of your own work product. Sending a reviewed draft to your client, filing it with a court, serving it on another party, or sharing it with co-counsel, an expert, or a vendor in the course of representing a client is the ordinary and intended use of the Service. Section 2 governs who may use the Service. It does not limit who may receive the work you produce with it.
3.2 Data you are not entitled to submit
Do not connect an account or submit data you lack authority to disclose to a vendor. This includes:
- mailboxes or calendars you are not authorized to administer;
- material subject to a protective order or confidentiality agreement that prohibits third-party disclosure;
- material from a matter you do not represent;
- classified or export-controlled information;
- protected health information for which your firm acts as a HIPAA business associate — see Terms Section 14.6; and
- data obtained unlawfully, including through unauthorized access to another person’s account or device.
3.3 Unlawful and abusive purposes
Do not use the Service to:
- harass, stalk, surveil, threaten, or intimidate any person, including an opposing party or a party protected by a restraining order;
- locate or track an individual who has sought protection from your client;
- facilitate fraud, identity theft, or concealment of assets from a court or an opposing party;
- prepare a filing you know or should know to be false, or assist a client in making a false statement under oath;
- violate any court order; or
- violate any applicable law or rule of professional conduct.
We call these out specifically because this is family law. A tool that organizes information about parties and their whereabouts can be misused against a vulnerable person. Do not use ours that way.
3.4 Security and integrity
Do not:
- probe, scan, or test the vulnerability of the Service without our prior written authorization (see Section 6);
- circumvent authentication, authorization, rate limits, or usage caps;
- access another firm’s account or data, or attempt to;
- upload malicious code;
- interfere with or degrade the Service or its infrastructure; or
- use automated means to access the Service other than through documented interfaces.
3.5 Reverse engineering and competitive use
Do not reverse engineer, decompile, or attempt to derive source code, model weights, prompts, or rule logic; use the Service or its Outputs to train, fine-tune, or evaluate any machine learning model; build a competing product; or publish benchmarks without our prior written consent.
3.6 Account and seat integrity
Do not share credentials, allow a seat to be used by anyone other than its assigned individual, permit concurrent use of one seat, or resell or provide the Service to a third party. Seats may be reassigned when someone leaves; they may not be shared.
3.7 Misrepresenting Outputs
Do not represent an unverified AI Output as verified attorney work product, or represent to a client, a court, or anyone else that Cedent has reviewed, approved, or vouched for any Output. We have not.
4. Your Operational Obligations
- Deprovision promptly. Remove seats for departed personnel without delay.
- Configure automation to match your actual supervision. See the AI Addendum, Section 6.
- Secure your devices. Scratchpad content lives in the browser on the device. Full-disk encryption, screen lock, and secure disposal are your responsibility.
- Review before connecting. Understand what connecting a mailbox or calendar exposes — including personal calendar events and third-party confidences. See Privacy Policy Sections 6 and 7.
- Maintain independent systems of record for docketing, conflicts, and client files.
- Report security concerns to security@cedent.ai promptly.
5. Fair Use and Operational Limits
The Service applies request rate limits, a daily cap on manually regenerating a brief for a given matter, and maximum file sizes, to protect availability for all customers. AI processing volume and email ingestion are not metered. Current limits are in the Documentation.
We will not apply a limit so as to render the Service unfit for ordinary use by a firm of your seat count, and we will give reasonable notice before materially reducing a published limit. If your legitimate use consistently approaches a limit, contact us — we will discuss accommodation before taking any restrictive action. Limits exist to stop abuse and runaway automation, not to ration normal practice.
Do not attempt to evade limits through multiple accounts, credential sharing, or automated circumvention.
6. Security Research
We welcome good-faith security research. Contact security@cedent.ai for written authorization before testing. Authorized research must not access, modify, or exfiltrate any data belonging to another customer, degrade the Service, or use social engineering against our personnel or vendors. Report findings to us privately and give us reasonable time to remediate before disclosure. We will not pursue legal action against researchers who follow this section in good faith.
7. Enforcement
7.1 What we may do
On a violation we may contact you and request remediation; restrict or suspend the affected feature, user, or account; or terminate under Terms Section 20.5.
7.2 Proportionality
We prefer to contact you first. We will suspend without prior notice only where a violation presents an immediate risk to the security of the Service, to another customer’s data, or to a person’s safety, or where the law requires it. Where we suspend without notice, we will tell you why as soon as practicable.
7.3 Your data is not a sanction
Suspension or termination for an AUP violation does not forfeit your Matter Data. The thirty-day export window in Terms Section 20.3 applies regardless of the reason for termination, because your obligations to your clients do not depend on your standing with us.
8. Reporting
Report suspected violations, security issues, or misuse of the Service against a vulnerable person to security@cedent.ai or legal@cedent.ai. Reports involving an immediate threat to safety are prioritized.
9. Changes
We may update this Policy on thirty (30) days’ notice for material changes, or immediately where necessary to address an emerging security or safety risk, with prompt notice after.