Version 1.0 --- Effective 2026-10-01 · Last updated 2026-09-12
This Acceptable Use Policy ("AUP") forms part of the BOMSync Terms of Service (the "Terms"). Capitalized terms not defined here have the meanings given in the Terms.
BOMSync is designed for legitimate business use in architecture, engineering, construction, manufacturing, procurement, operations, asset management, and related workflows. Customer is responsible for its Authorized Users and for ensuring that Customer Data and use of the Service comply with this AUP.
1. Lawful and authorized use
Customer and Authorized Users may use the Service only for lawful business purposes and may not use the Service to:
- violate applicable law, regulation, court order, sanctions restriction, export-control rule, or third-party right;
- facilitate fraud, deception, identity theft, money laundering, unlawful surveillance, or other illegal activity;
- upload, transmit, generate, or distribute material that Customer does not have the right to use;
- impersonate another person or entity, misrepresent authorization, or conceal the origin of activity for a fraudulent or unlawful purpose; or
- assist another person in conduct prohibited by this AUP.
2. Security and platform integrity
Customer and Authorized Users must not:
- gain or attempt to gain unauthorized access to the Service, another tenant, another user's account, BOMSync infrastructure, or any connected system;
- bypass or defeat authentication, authorization, tenant isolation, rate limits, licensing, seat controls, usage metering, security controls, or technical restrictions;
- probe, scan, exploit, or test vulnerabilities without BOMSync's prior written authorization, except through a vulnerability-disclosure or security-testing program expressly made available by BOMSync;
- introduce malware, ransomware, destructive code, unauthorized scripts, credential-harvesting tools, or other code intended to impair or compromise systems or data;
- conduct denial-of-service activity or intentionally impose an unreasonable load on the Service;
- use compromised, shared, stolen, or improperly obtained credentials;
- interfere with logs, audit records, security telemetry, or usage records; or
- use the Service to attack, compromise, or disrupt another system.
Good-faith vulnerability reports may be sent to security@bomsync.com.
3. Data restrictions
Unless BOMSync expressly agrees in a signed Order Form or addendum, Customer must not upload or process through the Service:
- information subject to the International Traffic in Arms Regulations (ITAR);
- classified information or controlled unclassified information requiring a government facility clearance or a specifically approved government environment;
- protected health information regulated by HIPAA;
- payment-card account data that would cause BOMSync to act as a PCI DSS cardholder-data environment;
- biometric identifiers used for identification or authentication;
- children's personal data where a specific parental-consent or child-directed service regime applies; or
- data subject to a contractual or statutory storage requirement that is inconsistent with the hosting locations described at </legal/regions>.
Customer must use available security, access, and regional controls appropriate to the sensitivity of its data.
4. Intellectual property and extraction restrictions
Except where expressly permitted by the Terms, an Order Form, applicable law, or documented BOMSync functionality, Customer must not:
- reverse engineer, decompile, disassemble, or attempt to derive BOMSync source code, models, algorithms, solver logic, or confidential technical information;
- scrape, crawl, bulk-extract, harvest, or systematically copy data from the Service outside documented APIs and export functions;
- use BOMSync confidential information, Documentation, Service functionality, or Output to build, train, benchmark, or materially improve a competing product or service;
- publish performance or comparative benchmarks without BOMSync's prior written consent;
- remove or obscure copyright, trademark, patent, confidentiality, or other proprietary notices; or
- resell, sublicense, rent, timeshare, or operate the Service as a service bureau unless expressly authorized in an Order Form.
Nothing in this Section restricts rights that cannot lawfully be waived, including applicable statutory interoperability rights.
5. Communications and network abuse
Customer must not use BOMSync or connected services to:
- send spam or unsolicited bulk communications;
- distribute phishing messages or deceptive links;
- transmit malware or malicious attachments;
- engage in abusive automated traffic;
- harvest contact information without authorization; or
- use BOMSync transactional communication systems as a general-purpose marketing delivery platform unless a BOMSync feature expressly supports that purpose.
6. AI features
AI Features are provided for business decision support and assistance. Customer must not use AI Features:
- for unlawful, fraudulent, deceptive, or abusive activity;
- to circumvent security or access controls;
- to make a decision having legal or similarly significant effect on an individual without appropriate human review where applicable law requires such review;
- to submit data Customer is not authorized to provide to the configured AI provider; or
- in a manner prohibited by the applicable AI provider's terms.
Where Customer uses its own AI credentials or API keys ("BYOK"), Customer is responsible for its relationship with and configuration of the selected provider. BOMSync's handling of Customer-provided credentials remains subject to the Terms, DPA where applicable, and BOMSync security controls.
AI Output may be incomplete or incorrect. Customer remains responsible for qualified human review before relying on Output for design, construction, manufacturing, procurement, safety, regulatory, financial, or other consequential decisions.
7. High-risk professional and operational use
BOMSync is an information-management and decision-support platform. Use of BOMSync does not transfer to BOMSync responsibility for:
- architecture, engineering, surveying, construction management, quantity surveying, professional estimating, or other licensed professional services;
- construction means and methods, site safety, code compliance, permitting, or inspection;
- fabrication or manufacturing quality control;
- supplier selection, purchasing authority, customs classification, or trade compliance;
- final quantities, dimensions, tolerances, loads, structural adequacy, production settings, or installation instructions; or
- legal, tax, accounting, insurance, or investment decisions.
Customer must maintain the professional review, approvals, inspections, and controls appropriate to its activities.
8. Automated use and APIs
Automated access must use documented APIs, supported integrations, or other mechanisms authorized by BOMSync. Customer must comply with published rate limits and must not create automated workflows designed to evade plan limits, licensing, usage metering, or security controls.
BOMSync may apply reasonable technical limits to protect availability, security, and other customers.
9. Suspension and enforcement
If BOMSync reasonably believes use of the Service violates this AUP, creates a material security or legal risk, or threatens the availability or integrity of the Service, BOMSync may take proportionate action under the Terms, including restricting specific activity or suspending affected access.
Except where immediate action is necessary to address an active threat or legal requirement, BOMSync will provide reasonable notice and an opportunity to cure. BOMSync will limit suspension in scope and duration to what is reasonably necessary and will restore access promptly when the issue is resolved.
10. Reporting misuse
Suspected misuse may be reported to:
Security: security@bomsync.com
Legal: legal@bomsync.com
Privacy: privacy@bomsync.com
11. Changes
BOMSync may update this AUP in accordance with the change provisions in the Terms. Superseded versions will be identified through the Legal Archive.