Security works when every person with access understands the boundary. This policy keeps Proactive Risk services useful, safe, authorized, and respectful of the systems and people they are meant to protect.
Introduction
This Acceptable Use Policy (“AUP”) sets the rules for using proactivegrc.com, CyberAdvisor™ client materials, shared workspaces, and other systems made available in connection with a CyberAdvisor™ engagement by Proactive Risk Inc. (“Proactive Risk,” “we,” “us,” or “our”). It applies to clients, users, contractors, and anyone accessing a Proactive Risk environment.
Prohibited Activities
You may not use Proactive Risk systems or services to violate law, an agreement, or another person’s rights. Prohibited activities include unauthorized access, credential sharing, privilege escalation, interference, scanning, exploitation, or access to systems without documented authorization; introducing malware, ransomware, destructive code, or excessive traffic; bypassing authentication, monitoring, rate limits, or access restrictions; harassment, fraud, impersonation, threats, unlawful content, infringement, or facilitation of harm; and collecting, disclosing, or transferring personal, confidential, regulated, or controlled data without authority and appropriate safeguards.
Intellectual Property
Proactive Risk and its licensors retain all rights in CyberAdvisor™ service materials, methods, and content except for rights expressly granted in a written agreement. CyberAdvisor™ is a service mark of Proactive Risk Inc. You may not copy, modify, reverse engineer, resell, or use Proactive Risk marks or materials in a way that implies sponsorship or endorsement without written permission.
System Monitoring and Privacy
Proactive Risk may monitor, log, and review use of its systems and services to operate, secure, troubleshoot, investigate misuse, and comply with law. Monitoring may include access, authentication, administrative, network, endpoint, and security events. We handle personal information according to the Privacy Policy and applicable agreements; do not use Proactive Risk systems to transmit passwords or unnecessary sensitive information.
User Responsibilities
Use Proactive Risk systems only for lawful business purposes, within the scope of an applicable agreement or Work Order, and with the access rights assigned to you. Keep credentials confidential, use reasonable security controls, maintain accurate authorized-user and contact records, respect the privacy and rights of others, and obtain written authorization before requesting or conducting security reviews or other activities that could affect a system. Report suspected compromise or misuse promptly to your Proactive Risk contact or by calling (973) 298-1160.
Termination of Access
Proactive Risk may suspend, restrict, or terminate access when reasonably necessary to protect people, systems, data, clients, or the public, or to comply with law or an agreement. Where practical, we will provide notice and an opportunity to correct the issue. On termination, stop using the affected systems and return or securely delete Proactive Risk materials as required by the applicable agreement.
Changes
We may update this AUP when services, threats, or legal requirements change. The effective date in the header identifies the current version. Continued use of Proactive Risk systems after an update means you accept the revised AUP to the extent permitted by the applicable agreement.
Contact Us
Questions about acceptable use or a suspected violation should be directed to Proactive Risk Inc., 36 First Avenue, Suite 203, Denville, NJ 07834, phone (973) 298-1160. Do not include passwords or unnecessary sensitive information in an initial report.
Contact Proactive Risk
Proactive Risk Inc.
36 First Avenue, Suite 203
Denville, NJ 07834
