Trust Center
Acceptable Use Policy
Last Updated: June 2026
1. Permitted Use
RequirementsHub is built to help business analysts, product teams, consultants, and adjacent roles capture, analyze, and improve software requirements. You may use the service to:
- Upload, organize, and analyze your own requirements, project documents, and supporting artifacts.
- Collaborate with workspace members you invite, including internal teammates, clients, and engaged contractors.
- Generate AI-assisted analysis, gap detection, traceability, and intelligence outputs in support of your own projects.
- Export your data at any time in machine-readable form.
- Use outputs as decision-support inputs for your own engineering, product, and delivery decisions.
2. Prohibited Content
The following categories of data must not be uploaded to RequirementsHub. This list is not exhaustive — exercise judgment.
| Category | Detail |
|---|---|
| Protected Health Information (PHI) | RequirementsHub is not a HIPAA-covered service. Do not upload patient records, clinical notes, medical imaging, or any data that would be PHI under HIPAA. |
| Payment Card Data | Raw cardholder data (PAN, CVV, magnetic stripe data, PIN). Payment processing is handled exclusively by Stripe; the platform does not need cardholder data. |
| Special Category Personal Data | GDPR Article 9 categories: racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, sex life, sexual orientation — unless you have a documented lawful basis and have notified us in writing. |
| Government ID Numbers | National identification numbers (SSN, NI number, etc.), passport numbers, driver's license numbers — unless strictly required for the requirement under analysis and minimized. |
| Export-Controlled Technical Data | Technical data subject to ITAR, EAR, or equivalent export-control regimes. |
| Classified/Sensitive Government Information | Any data classified by a government authority or marked as sensitive but unclassified (SBU, CUI) without prior written approval from RequirementsHub. |
| Minors' Personal Data | Personal data of children under 16 (or the applicable local threshold) without verified parental consent and a documented lawful basis. |
| Third-Party Confidential Data Without Authorization | Confidential data belonging to a third party (client, partner, vendor) that you are not authorized to share with a SaaS processor. |
3. Prohibited Conduct
Security and integrity
- Do not probe, scan, or test the vulnerability of the service without prior written authorization. See the Vulnerability Disclosure section of our Security page for the responsible-disclosure path.
- Do not attempt to gain unauthorized access to any account, workspace, system, or data.
- Do not interfere with or disrupt the integrity, performance, or availability of the service.
- Do not upload malware, exploits, or content designed to compromise other users or systems.
- Do not reverse engineer, decompile, or attempt to extract the underlying models, prompts, or proprietary logic of the service.
Platform abuse
- Do not resell, sublicense, white-label, or repackage the service or its outputs as a competing or substitutable product.
- Do not use the service to train, evaluate, or benchmark a competing AI or analysis product.
- Do not use automated means (scrapers, bots, headless browsers) to access the service except through documented APIs.
- Do not circumvent usage limits, billing controls, plan entitlements, or trial restrictions.
Legal compliance
- Do not upload content you do not have the legal right to process.
- Do not use the service in violation of applicable law, including export controls, sanctions, anti-discrimination law, or intellectual property rights.
- Do not use the service to facilitate illegal activity.
Community and integrity
- Do not use the service to harass, defame, threaten, or harm any individual or organization.
- Do not use the service to generate or distribute content that is unlawful, deceptive, fraudulent, or designed to mislead.
- Do not impersonate another person or organization within the platform.
4. Reporting a Violation
To report suspected abuse of the service or violation of this policy:
- Email: security@requirementshub.ai
- Subject line:
[AUP] Brief description
Reports may be submitted anonymously, though providing contact details helps us investigate and follow up.
5. Enforcement
RequirementsHub may take any of the following actions in response to a violation, at our reasonable discretion and proportionate to the severity of the conduct.
| Action | Typical Trigger |
|---|---|
| Warning | First-time minor violation or ambiguous conduct that may have been unintentional. |
| Content removal | Specific content found to violate this policy; affected items removed with notice to the workspace owner. |
| Temporary suspension | Repeated violations, active investigation of suspected abuse, or conduct that risks the platform or other customers. |
| Account or workspace termination | Severe or repeated violations, refusal to remediate, or conduct that is illegal or egregiously harmful. |
| Referral to law enforcement | Conduct that appears to constitute a crime, where required by law, or where necessary to protect the safety of others. |
If your account or workspace is suspended or terminated and you believe the action was taken in error, you may appeal by contacting legal@requirementshub.ai within 14 days of the action. We will review and respond.
6. Modifications
We may update this Acceptable Use Policy as the platform and the threat landscape evolve. Material changes will be communicated by email to workspace owners at least 14 days before they take effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.
Effective Date & Contact
Effective date: June 2026 · Contact: security@requirementshub.ai
Last updated: June 2026