Acceptable Use Policy

Last updated · Circo, Inc.

In plain English

  • Use Capable to keep honest, lawful records of your company’s equity.
  • Do not use it to mislead investors or employees, to run unlicensed securities activity, or to upload data you have no right to hold.
  • Do not attack, overload, scrape, or probe the service outside our disclosure policy.
  • If you break these rules, we may suspend access, but you keep the ability to export your data unless export is the problem.

This summary helps you read the document. The numbered sections below are what bind.

Contents

1. Who this policy applies to

This policy applies to every customer, admin, stakeholder, and connected application that uses Capable, which is operated by Circo, Inc. It is part of our Terms of Service. Customers are responsible for making sure their users follow it.

2. Honest records and lawful securities activity

You may not use Capable to:

  • create or present cap table records, certificates, valuations, or reports that you know are false, or that are designed to mislead investors, employees, auditors, lenders, acquirers, or regulators;
  • issue, offer, or sell securities in violation of securities laws, including by making unregistered public offerings or improper general solicitations through the stakeholder portal or email features;
  • act as an unregistered broker-dealer, funding portal, exchange, or investment adviser, or match buyers and sellers of private securities;
  • forge signatures, sign on behalf of someone without authority, or backdate documents in a way that misrepresents when they were signed or approved; or
  • commit fraud, launder money, evade taxes, or violate any other law.

3. Data you upload

You may not:

  • upload personal data you have no legal right to process or share with us, or without giving any notice the law requires;
  • upload special categories of personal data, such as health or biometric data, that are not needed for managing equity;
  • upload content that infringes someone else’s intellectual property or privacy rights; or
  • upload malware or any file designed to harm systems or data.

4. Protecting the service

You may not:

  • access or try to access another company’s data, or any data your role does not allow;
  • probe, scan, or test the security of the service, except as permitted by our responsible disclosure policy;
  • bypass authentication, two-factor requirements, rate limits, or role restrictions;
  • send traffic that degrades the service for others, or use automated means to scrape it, other than the APIs and connector we provide;
  • share accounts or credentials, or create accounts under false identities;
  • copy, frame, or reverse engineer the hosted service to build a competing product, except to the extent the law or the open-source license of our published components allows; or
  • resell or provide the service to third parties without a written agreement with us. Law firms and administrators may manage cap tables for their clients as those clients’ authorized users.

5. Invitations and email

Use invitations, signature requests, and notices only for real stakeholders and legitimate company business. Do not use them to send spam, phishing, harassment, or messages that impersonate another person or organization.

6. AI features

You may not:

  • use AI features to produce content that is unlawful, deceptive, or harmful;
  • try to extract other customers’ data, system instructions, or credentials through prompts or connected tools;
  • rely on AI output alone for decisions with legal or similarly significant effects on a person, such as terminating a grant, without human review; or
  • use the connector or APIs in a way that breaks the usage policies of the AI provider you connect.

7. Sanctions and export controls

You may not use Capable from, or on behalf of, a country, region, or person subject to comprehensive US sanctions, or appearing on a US government restricted-party list, or otherwise in violation of export control laws.

8. Enforcement and reporting

If we reasonably believe this policy has been broken, we may remove content, disable an integration, suspend a user or workspace, or terminate the account, as the Terms of Service describe. We act in proportion to the harm, tell you why when we can, and keep your ability to export your data unless the export itself is the problem. We may report unlawful activity to the authorities.

To report abuse, email support@capable.so. To report a security vulnerability, email security@capable.so.