Bearings · Legal
Acceptable Use Policy
Version 1.0Last updated 2026-08-07Effective 2026-08-14
Bearings is an analytical workspace for defense and national-security research work: aggregating evidence, building hypotheses, publishing judgments, and querying a workspace-scoped LLM. This policy names what Bearings is for, what it must never be used for, and what happens when a workspace or an individual Member crosses those lines.
What Bearings is for
- Uploading publicly-available or customer-owned evidence documents and building analytical artifacts (hypotheses, judgments, intelligence assets) around them.
- Retrieving and reasoning over that evidence via a workspace-scoped Navigator LLM with citation and guardrails.
- Sharing analytical artifacts with named members of the customer's own organization under a role-based permission model.
- Auditing who did what, when, over the immutable audit ledger.
Prohibited content
Bearings is NOT authorized to handle Controlled Unclassified Information (CUI), Controlled Defense Information (CDI), ITAR-controlled technical data, or classified information at MVP. Uploading any of the following is a material violation and results in immediate suspension pending review:
- Classified information of any kind (Confidential, Secret, Top Secret, SCI, SAP, etc.).
- Controlled Unclassified Information (CUI) as defined by 32 CFR Part 2002.
- Controlled Defense Information (CDI) within the meaning of DFARS 252.204-7012.
- ITAR-controlled technical data (22 CFR Parts 120-130) or EAR-controlled technology subject to license requirements (15 CFR Parts 730-774).
- Third-party trade secrets or content the customer has no right to upload.
- Personal data of natural persons beyond what is minimally needed for authorship attribution and audit — Bearings is not a system of record for HR, health, financial, or biometric data.
- Malware, weaponized exploits, or content intended to attack Bearings or any other system.
Prohibited use
Identity + workspace integrity
- No credential sharing. Every Member account is a natural person with a verified email; accounts do not transfer.
- No workspace-boundary evasion. Attempting to read data from another workspace, whether by session manipulation, prompt injection targeting the Navigator, or any other means, is a material violation.
- No permission-check bypass. The permission matrix + PermissionService are load-bearing controls; attempting to circumvent them (custom API clients, fabricated JWTs, header spoofing) is a material violation.
Navigator + LLM use
- No prompt injection attempts against the Navigator to smuggle data across workspace boundaries, extract system prompts, or induce policy-violating output.
- No re-embedding of Navigator responses into public training datasets or into a third-party model. Responses are for the customer's internal analytical use.
- No high-volume synthetic prompt traffic intended to exhaust the workspace's LLM budget or otherwise disrupt service. Per-workspace rate limits and budget caps are engineered controls, not license to run them to the ceiling for its own sake.
Platform integrity
- No security testing without written authorization. Report suspected vulnerabilities to security@nerdrums.com. Do not exploit, exfiltrate, or persist access.
- No rate-limit evasion via multi-account, proxy rotation, or IP rotation.
- No unauthorized automation. Scripted access to Bearings should go through the documented API key surface, subject to per-key rate limits and audit.
How violations are handled
- Automated controls stop most abuse before it lands: ClamAV on every upload, per-workspace Navigator rate limits, PII scan on LLM output, per-workspace budget caps, cross-workspace fuzz coverage on every mutation route.
- Admin review queue handles quarantined evidence and reports of policy-violating content. Timeline is typically 2 business days.
- Escalation. Material violations (uploading classified material, uploading CUI/CDI/ITAR content, security testing without authorization) may result in immediate suspension of the workspace and, on confirmation, termination without refund.
- Appeals. The workspace Owner is notified of any suspension with the reason, the evidence relied on (where sharing is compatible with security), and a contact path to appeal. Appeals go to legal@nerdrums.com.
Reporting misuse
- Content in your workspace — the Owner or any Admin may withdraw an Asset, revert a state transition, or delete Evidence directly through the workspace UI.
- Suspected policy-violating content or use — abuse@nerdrums.com. Include the workspace slug, the artifact or account, and enough context to reproduce.
- Suspected security issues — security@nerdrums.com.
Changes
Material changes are announced via email to the workspace Owner and via the in-workspace notification matrix. Continued use of Bearings after a material change constitutes acceptance.