This Acceptable Use Policy (the “Code of Conduct” for the Service) is part of, and incorporated into, the Terms of Use. Capitalized terms have the meanings given there.
1. Purpose
Wicket exists to put authorization in the path between AI agents and production systems. That mission only works if the Service itself is used responsibly. This policy describes how you may and may not use Wicket. It applies to everyone who accesses the Service — account owners, members, and the agents acting on their behalf.
2. Core principles
- Authorized use only. Connect and proxy only to systems you own or are clearly permitted to access.
- Don't subvert access controls. Wicket is an authorization layer; never use it to bypass, weaken, or circumvent anyone's access controls — including your own organization's, an upstream service's, or Wicket's.
- Respect the audit. The audit trail is a security feature. Do not tamper with, falsify, or attempt to evade it.
- Be a good tenant. Use the Service in a way that does not degrade it for others.
3. Prohibited uses
You may not use the Service to:
- violate any law, regulation, or third-party right, or to facilitate anyone else doing so;
- access, proxy calls to, or act on any system, account, or data without authorization from its owner;
- circumvent, disable, or interfere with authentication, authorization, rate limits, or audit logging — whether the upstream service's or Wicket's;
- violate the terms of service of any upstream service you connect (e.g. GitHub, Slack, Linear, and others);
- exfiltrate, leak, or improperly disclose data — including chaining individually permitted calls to move sensitive data to an unauthorized destination;
- upload, transmit, or proxy malware, exploits, or other harmful code;
- probe, scan, or test the security of the Service except as expressly permitted under our disclosure process below;
- overload, flood, or disrupt the Service, or attempt to gain unauthorized access to it or its infrastructure;
- share, resell, or expose member keys, or use another member's key without authorization;
- reverse engineer the Service except to the extent that restriction is prohibited by law;
- use the Service for high-risk activities where failure could lead to death, personal injury, or severe environmental or property damage, unless you have independent controls appropriate to that risk;
- infringe intellectual property, send spam, or harass, abuse, or harm others.
4. Credentials and keys
Member keys are issued to a person and shown once. Keep them secret, do not embed them where others can read them, and revoke any key you believe is compromised. You are responsible for all activity performed with your keys and connected-service credentials.
5. Security & vulnerability disclosure
We welcome good-faith security research. If you discover a vulnerability, please report it responsibly via the contact in our security.txt or at eng@wicket.sh, and give us a reasonable opportunity to address it before public disclosure. Do not access data that is not yours, degrade the Service, or pivot beyond the minimum needed to demonstrate the issue. Good-faith research conducted within these bounds will not be treated as a violation of this policy.
6. Beta conduct
During the beta we work closely with design partners. We ask that you report issues honestly, avoid representing roadmap or pre-GA features as generally available, and respect the confidentiality of non-public information as described in the Terms of Use.
7. Enforcement
If we believe use of the Service violates this policy, we may investigate and take action — including removing content, throttling, suspending, or terminating access — with or without notice, depending on the severity and the risk to others. We will use reasonable judgment and, where practical, give you an opportunity to remedy a violation. Serious issues (for example, active abuse, security threats, or legal risk) may warrant immediate action.
8. Reporting
To report a violation, abuse, or a security concern, contact eng@wicket.sh. We review every report.