livewells A$699 a month excl. GST

livewells acceptable use policy

Version: 1.0 Effective: 11 October 2026 Version date: 11 October 2026

Contents
  1. 1. What livewells is
  2. 2. Permitted use
  3. 3. Prohibited use
  4. 4. How the Service limits use
  5. 5. Your duties
  6. 6. Enforcement
  7. 7. Changes and other terms
  8. 8. Security research

This policy is part of the livewells subscription terms. Maelstrom AI Pty Ltd (ACN 679 356 702) is "we" and "us". It is the trustee for the Maelstrom AI Holding Trust (ABN 61 633 823 792), and it uses the name livewells. The organisation that subscribes is "you". The terms "Subscription", "Service", "Analyst", "Administrator" and "Customer Content" have the meanings in the subscription terms. If this policy and the subscription terms conflict, the subscription terms prevail.

1. What livewells is

livewells opens a link in a disposable, sandboxed browser. Its scope is URL triage. An Analyst opens a suspicious link by hand, and the Service records what the page loaded and did. The record is a video, and a report of the redirect chain, the domains and the IP addresses.

2. Permitted use

You can use the Service only to assess links that your organisation received, for the defence of your organisation. Examples are a phishing link in the mailbox of an employee and a link in a security alert. Another example is a link in a report that a customer sent to your security team. Only people in your organisation can use your account. Support requests must be about your own use of the Service, and clause 6.6 of the subscription terms governs support.

3. Prohibited use

You must not use the Service, or let a person use it, to:

  1. attack, probe, scan or disrupt a system, a network or a person, including livewells and our infrastructure, except security research in clause 8;
  2. scrape or crawl websites, or collect data in bulk;
  3. defraud or deceive a person, including by testing stolen payment data or running scams, or profile, track or surveil an individual;
  4. sign in to, or seize control of, an account that you are not authorised to use, or enter credentials that belong to someone else;
  5. bypass a login, paywall, rate limit, geographic limit, bot check or other access control on a site that you do not own;
  6. bypass the limits of livewells, or the controls that keep the data of one customer apart from that of another;
  7. send traffic through the Service to hide your identity or the source of an attack;
  8. resell or share access to livewells, or give your sessions to another organisation;
  9. host, serve, stage or distribute malware or other malicious or unlawful content through the Service, or cause a download for that purpose;
  10. map, enumerate or fingerprint the Service, its network addresses or its sandbox, or submit a link built to test the sandbox in order to build evasion, except security research in clause 8; or
  11. submit a link that you are not entitled to open, or use the Service in breach of the law, including export control and sanctions law.

4. How the Service limits use

The Service enforces the monthly limit on submissions and the cap on concurrent sessions that your plan allowances set. It also enforces a limit of 15 minutes for each session and a limit of 5 minutes without activity. We keep an audit log of each run: who started it, when, which link, and the outcome. The link is Customer Content, and the record of who started the run is account data. Operator actions on your account are also logged. People in your organisation who sign in can read the log for your organisation.

5. Your duties

You must keep your Microsoft Entra ID accounts secure. You must remove access for people who stop working for your organisation. You are responsible for what your Analysts do in the Service. Analysts must open links only in the Service. They must not enter live credentials of their own, or of someone else, into a hostile page. The Service supplements the controls of your own organisation.

You must set a malicious verdict only after an Analyst has assessed the evidence and concluded in good faith that the link is malicious. You must not submit links in order to put false indicators into Threat Data. You can exclude a case, or all cases, from threat data in the subscription terms. You must handle downloaded reports and videos safely, with indicators defanged.

Tell us without delay at support@livewells.io if you find misuse, or if a session shows unlawful content. We then preserve the log and can suspend the account. We can preserve and disclose records where the law requires, and we tell you first unless the law forbids it.

6. Enforcement

We can suspend or end a Subscription for a material breach of this policy. This applies if you do not cure the breach within 14 days of notice. We can do so at once for abuse. "Abuse" means conduct in clause 3 that harms the Service, another customer or a person, or support that clause 6.6 of the subscription terms describes.

We can also suspend one Analyst, or your account, at once. We do so if we reasonably believe that it is necessary to protect the Service, another customer or a person. We tell you why promptly, and you can reply to support@livewells.io. Clause 12 of the subscription terms applies to the effect of termination and to refunds, and clause 7 applies to your Customer Content.

7. Changes and other terms

This policy changes in the manner that clause 11 of the subscription terms states. This policy does not change a liability clause or a right that the law does not allow to be excluded.

8. Security research

Security research on livewells is welcome. Report findings to support@livewells.io. Our security contact details are at livewells.io/.well-known/security.txt. Research on the Service is permitted if it gives no one unauthorised access to livewells, to our infrastructure or to the data of a customer.