Bearings · Legal

Acceptable Use Policy

Version 1.0Last updated 2026-08-07Effective 2026-08-14
Bearings is an analytical workspace for defense and national-security research work: aggregating evidence, building hypotheses, publishing judgments, and querying a workspace-scoped LLM. This policy names what Bearings is for, what it must never be used for, and what happens when a workspace or an individual Member crosses those lines.

What Bearings is for

  • Uploading publicly-available or customer-owned evidence documents and building analytical artifacts (hypotheses, judgments, intelligence assets) around them.
  • Retrieving and reasoning over that evidence via a workspace-scoped Navigator LLM with citation and guardrails.
  • Sharing analytical artifacts with named members of the customer's own organization under a role-based permission model.
  • Auditing who did what, when, over the immutable audit ledger.

Prohibited content

Bearings is NOT authorized to handle Controlled Unclassified Information (CUI), Controlled Defense Information (CDI), ITAR-controlled technical data, or classified information at MVP. Uploading any of the following is a material violation and results in immediate suspension pending review:
  • Classified information of any kind (Confidential, Secret, Top Secret, SCI, SAP, etc.).
  • Controlled Unclassified Information (CUI) as defined by 32 CFR Part 2002.
  • Controlled Defense Information (CDI) within the meaning of DFARS 252.204-7012.
  • ITAR-controlled technical data (22 CFR Parts 120-130) or EAR-controlled technology subject to license requirements (15 CFR Parts 730-774).
  • Third-party trade secrets or content the customer has no right to upload.
  • Personal data of natural persons beyond what is minimally needed for authorship attribution and audit — Bearings is not a system of record for HR, health, financial, or biometric data.
  • Malware, weaponized exploits, or content intended to attack Bearings or any other system.

Prohibited use

Identity + workspace integrity

  • No credential sharing. Every Member account is a natural person with a verified email; accounts do not transfer.
  • No workspace-boundary evasion. Attempting to read data from another workspace, whether by session manipulation, prompt injection targeting the Navigator, or any other means, is a material violation.
  • No permission-check bypass. The permission matrix + PermissionService are load-bearing controls; attempting to circumvent them (custom API clients, fabricated JWTs, header spoofing) is a material violation.

Navigator + LLM use

  • No prompt injection attempts against the Navigator to smuggle data across workspace boundaries, extract system prompts, or induce policy-violating output.
  • No re-embedding of Navigator responses into public training datasets or into a third-party model. Responses are for the customer's internal analytical use.
  • No high-volume synthetic prompt traffic intended to exhaust the workspace's LLM budget or otherwise disrupt service. Per-workspace rate limits and budget caps are engineered controls, not license to run them to the ceiling for its own sake.

Platform integrity

  • No security testing without written authorization. Report suspected vulnerabilities to security@nerdrums.com. Do not exploit, exfiltrate, or persist access.
  • No rate-limit evasion via multi-account, proxy rotation, or IP rotation.
  • No unauthorized automation. Scripted access to Bearings should go through the documented API key surface, subject to per-key rate limits and audit.

How violations are handled

  • Automated controls stop most abuse before it lands: ClamAV on every upload, per-workspace Navigator rate limits, PII scan on LLM output, per-workspace budget caps, cross-workspace fuzz coverage on every mutation route.
  • Admin review queue handles quarantined evidence and reports of policy-violating content. Timeline is typically 2 business days.
  • Escalation. Material violations (uploading classified material, uploading CUI/CDI/ITAR content, security testing without authorization) may result in immediate suspension of the workspace and, on confirmation, termination without refund.
  • Appeals. The workspace Owner is notified of any suspension with the reason, the evidence relied on (where sharing is compatible with security), and a contact path to appeal. Appeals go to legal@nerdrums.com.

Reporting misuse

  • Content in your workspace — the Owner or any Admin may withdraw an Asset, revert a state transition, or delete Evidence directly through the workspace UI.
  • Suspected policy-violating content or use abuse@nerdrums.com. Include the workspace slug, the artifact or account, and enough context to reproduce.
  • Suspected security issues security@nerdrums.com.

Changes

Material changes are announced via email to the workspace Owner and via the in-workspace notification matrix. Continued use of Bearings after a material change constitutes acceptance.