Skip to content

Acceptable use policy

Effective 21 September 2026. This policy forms part of the Terms of Service. Customer is responsible for its Authorized Users' compliance with it.

1. Do not use Luna to

  • break any law, or to help anyone else break one;
  • create, alter or backdate a record in order to mislead a regulator, an examiner, an auditor, a client or a court;
  • conceal a violation, rather than to identify and remediate one;
  • access another firm's data, or attempt to;
  • probe, scan or test the security of the Services without Luna's prior written permission, or circumvent any authentication, rate limit or access control;
  • submit malicious code, or content designed to manipulate the Services' model outputs in a way that would mislead another user;
  • scrape, crawl or bulk-extract the Services other than through features Luna provides for that purpose;
  • resell or provide the Services to a third party as a service of Customer's own, unless Customer has a written arrangement with Luna permitting it;
  • reverse engineer the Services, or use them to develop a competing product; or
  • submit content Customer has no right to submit.

2. Data Customer must not submit

Individuals located outside the United States. Customer will not submit the personal information of anyone located in the European Economic Area, the United Kingdom or Switzerland without Luna's prior written agreement. The Services are offered in the United States and Luna makes no GDPR representations. See Section 10 of the Data Processing Addendum.

Data Customer has no lawful basis to hold. If Customer could not lawfully hold it in a filing cabinet, Customer should not put it in Luna.

Government identifiers and payment instruments beyond what a module needs. Luna's modules ask for the fields they need. Customer should not paste Social Security numbers, full account numbers or payment card numbers into free-text fields, notes or uploaded documents where the module does not ask for them.

3. Email archiving, if Customer enables it

Archiving captures communications content, including messages from people outside Customer's firm who have not agreed to anything with Luna.

Customer is responsible for: giving its personnel whatever notice the law and Customer's own policies require; configuring which accounts and channels are in scope; and understanding that channel coverage is Customer's responsibility. Luna captures the channels Customer connects and configures. It does not capture a channel Customer has not connected, and it cannot capture a communication that never touched a connected channel. Luna makes no representation that archiving alone satisfies Customer's obligations under Rule 204-2 or any equivalent rule.

4. Reporting

Report a suspected vulnerability to security@lunacompliance.io. Luna will not pursue a good-faith researcher who reports privately, does not access another customer's data, and gives Luna a reasonable period to fix the issue before publishing.

Report suspected misuse to abuse@lunacompliance.io.

5. Enforcement

Luna may suspend access where use presents a security risk or where continued use would place Luna in breach of law, and will tell Customer why. For anything less urgent, Luna will raise it with Customer and allow a reasonable period to correct it before suspending.

Luna does not monitor the content of Customer Data looking for violations of this policy. Luna acts on what it is told, and on what its security systems surface.