Legal

Acceptable Use Policy

Last updated: March 11, 2026

This Acceptable Use Policy ("AUP") sets out the rules for using M-Theory Group’s Services and related systems. Its purpose is to protect our clients, their data, and our infrastructure, and to maintain compliance with security and privacy obligations. By using our Services, you agree to comply with this AUP. If you do not agree, you must not use the Services.

1. Purpose

This Acceptable Use Policy ("AUP") sets out the rules for using M-Theory Group’s Services and related systems. Its purpose is to protect our clients, their data, and our infrastructure, and to maintain compliance with security and privacy obligations.

By using our Services, you agree to comply with this AUP. If you do not agree, you must not use the Services.

2. Scope

This AUP applies to:

  • Clients who have entered into an agreement with M-Theory Group
  • Authorized users of our clients (such as employees, contractors, or agents) who access our portals, tools, or Services
  • Any individual or system that accesses or interacts with our infrastructure in connection with our MSSP offerings

3. Prohibited Activities

Users may not use our Services to:

  • Engage in illegal activities or violate any applicable law, regulation, or third-party rights
  • Attempt unauthorized access to any system, network, or data, including but not limited to hacking, password cracking, or similar activities
  • Conduct unauthorized or malicious scanning, exploitation, or penetration testing of any system without proper authorization and scope definition
  • Distribute malware, ransomware, spyware, or other malicious code
  • Interfere with or disrupt the integrity or performance of our Services or underlying infrastructure
  • Send spam, unsolicited bulk messages, or conduct phishing or social engineering campaigns, except as expressly authorized for controlled security awareness testing under a written agreement
  • Use our Services to store, process, or transmit data that they are not legally entitled to possess or share
  • Circumvent or attempt to circumvent security controls or monitoring mechanisms
  • Misrepresent their identity or affiliation in any way that could harm M-Theory Group or our clients

4. Client Responsibilities

Clients are responsible for:

  • Ensuring that only authorized users access the Services and that such users understand and comply with this AUP
  • Maintaining the confidentiality and security of their authentication credentials
  • Promptly notifying us of any suspected misuse, security incident, or breach involving the Services or credentials
  • Providing accurate, lawful data to be processed by the Services, and ensuring they have the necessary rights and consents to share that data with us
  • Configuring their own systems and networks to complement our security controls (e.g., firewall rules, access policies, patching)

5. Security and Access Controls

To maintain a secure environment, we may:

  • Enforce technical controls such as multi-factor authentication, session timeouts, IP restrictions, and role-based access
  • Log and monitor activity on our platforms for security, operational, and compliance purposes
  • Investigate suspected violations of this AUP or other agreements

Users must not attempt to disable or interfere with these security measures.

6. Monitoring and Logging

Use of the Services may be monitored and logged, including:

  • User access, authentication, and administrative activities
  • Configuration changes and actions taken within the portal
  • API usage, integrations, and automated actions

We use this information to maintain security, troubleshoot issues, support clients, and meet our compliance requirements. Logging is conducted in accordance with our Privacy Policy and contractual obligations.

7. Reporting Violations

If you become aware of any violation of this AUP, suspected misuse, or security incident relating to our Services, you must promptly notify us at compliance@m-theorygrp.com and provide details for us to investigate.

8. Enforcement

We reserve the right, at our discretion and without liability, to take appropriate action in response to violations of this AUP, which may include:

  • Issuing a warning
  • Temporarily suspending access to all or part of the Services
  • Terminating access or the underlying agreement in accordance with contract terms
  • Cooperating with law enforcement or other authorities where required or appropriate

We will take into account the severity and nature of the violation, potential impact on security and privacy, and our contractual obligations to clients.

9. Changes to This AUP

We may update this Acceptable Use Policy from time to time. When we do, we will update the "Last Updated" date below and, where appropriate, notify clients through our usual communication channels.

10. Contact Us

For questions regarding this AUP, contact compliance@m-theorygrp.com.