Skip to content

Exhibit to the Platform Agreement

Last updated September 2, 2026

Acceptable Use Policy

This Acceptable Use Policy ("AUP") governs access to and use of the software, platforms, applications, artificial intelligence features, integrations, websites, and related services provided by Salus Solutions, Inc. ("Salus") (collectively, the "Services"). It applies to each customer, institution, organization, and individual that accesses or uses the Services ("Customer" or "User," as applicable).

This AUP forms part of the agreement governing Customer's use of the Services and is incorporated by reference into the Salus Platform Agreement. Capitalized terms not defined here have the meanings given in that agreement. Where this AUP conflicts with a separately executed written agreement between Salus and Customer, including an Order Form, subscription agreement, or master services agreement, the separately executed agreement controls as to the subject matter it expressly addresses. By accessing or using the Services, each User agrees to comply with this AUP.

Sections

1. Authorized Use

1.1

Customer and its Users may access and use the Services only:

  • for Customer's legitimate internal institutional, administrative, compliance, public safety, or related business purposes;
  • in accordance with the Agreement, applicable documentation, and applicable law;
  • through accounts and access credentials authorized by Customer and Salus; and
  • within any applicable usage, access, technical, or other limitations associated with the Services.
1.2

Customer is responsible for the use of the Services by its Users and for ensuring that Users comply with this AUP.

2. Account and Access Security

2.1

Users must safeguard account credentials and may not share individual login credentials with unauthorized persons.

2.2

Customer and its Users must not:

  • permit unauthorized persons to access the Services;
  • impersonate another User or misrepresent their identity or authority;
  • circumvent authentication, authorization, role based access controls, or other security mechanisms;
  • attempt to access data, accounts, systems, features, or functionality for which the User has not been authorized; or
  • knowingly use compromised credentials to access the Services.
2.3

Customer should promptly notify Salus at security@trysalus.com if it becomes aware of unauthorized access to an account or other suspected compromise relating to the Services.

3. Prohibited Conduct

3.1

Customer and its Users may not use, and may not permit any third party to use, the Services:

  • in violation of applicable law, regulation, court order, or the legal rights of another person;
  • for any fraudulent, deceptive, defamatory, harassing, abusive, discriminatory, or otherwise unlawful purpose;
  • to upload, transmit, distribute, or introduce malware, malicious code, viruses, ransomware, corrupted files, or other harmful or destructive technology;
  • to disrupt, disable, damage, interfere with, impair, or place an unreasonable burden on the Services or any systems, networks, infrastructure, or services used to provide the Services;
  • to circumvent or attempt to circumvent security measures, usage restrictions, rate limits, access controls, or other technical protections;
  • to obtain or attempt to obtain unauthorized access to the Services, another customer's environment or data, or any Salus or third-party system;
  • to use automated means, including bots, crawlers, scrapers, or similar technologies, to access or extract information from the Services except through functionality expressly provided or authorized by Salus;
  • to transmit unsolicited bulk communications or use the Services for spam, phishing, or other deceptive communications; or
  • in any manner that materially interferes with Salus's ability to provide the Services securely or reliably to Customer or other customers.

4. Security Testing

4.1

Unless expressly authorized in writing by Salus, which Salus will not unreasonably withhold where Customer's own security review requires it, Customer and its Users may not:

  • probe, scan, penetrate, or test the vulnerability or security of the Services or systems used to provide the Services;
  • conduct penetration testing, red team exercises, vulnerability scanning, or similar security testing against the Services;
  • attempt to defeat, bypass, or circumvent security or authentication mechanisms; or
  • exploit or attempt to exploit any suspected vulnerability.
4.2

Nothing in this section prevents a User from responsibly reporting a suspected security vulnerability to Salus. Suspected vulnerabilities or security concerns should be reported to security@trysalus.com.

5. Customer Data and Content

5.1

Customer is responsible for ensuring that it and its Users have all rights, permissions, consents, and authority necessary to submit, upload, transmit, access, or otherwise make data and other content available through the Services.

5.2

Customer and its Users may not knowingly submit or use through the Services:

  • information obtained or disclosed unlawfully;
  • content that infringes or misappropriates the intellectual property, privacy, confidentiality, or other rights of a third party;
  • data that Customer or the applicable User is not authorized to access, disclose, or process; or
  • malicious or intentionally corrupted content intended to interfere with the Services.
5.3

Nothing in this AUP changes the ownership of Customer Data or Salus's obligations regarding Customer Data under the applicable Agreement or Data Processing Addendum.

6. Artificial Intelligence and Compliance Functionality

6.1

The Services use artificial intelligence, machine learning, automation, rules based systems, and other technologies to assist Users with reviewing information, identifying potential issues, categorizing or reconciling incidents, generating recommendations or drafts, and supporting compliance and administrative workflows.

6.2

Customer and its Users acknowledge that outputs, recommendations, classifications, alerts, drafts, analyses, or other results generated or assisted by the Services ("Outputs") are intended to support, and not replace, appropriate human review and professional judgment. Users are responsible for reviewing Outputs as appropriate before relying upon, approving, submitting, publishing, or acting upon them.

6.3

Unless expressly agreed otherwise in writing, Customer remains responsible for its institutional decisions and compliance determinations, including decisions concerning Clery Act classification, geography, reporting, daily crime log entries, timely warnings, emergency notifications, annual security reports, and other regulatory or institutional obligations.

6.4

Users may not intentionally:

  • manipulate, falsify, or misrepresent information submitted to the Services for the purpose of producing a deceptive or improper Output;
  • represent an unreviewed AI generated Output as having been independently approved by Salus or by a qualified institutional official;
  • attempt to bypass confidence based review routing, unknowns flagging, or the human approval step the Services are designed to require before an Output is published to a daily crime log, counted toward annual security report statistics, sent as a timely warning, or otherwise finalized; or
  • use the Services to circumvent review, approval, or oversight requirements established by Customer or applicable law, including role restrictions such as limiting unfounding determinations to sworn officers.
6.5

Outputs are not used to adjudicate conduct, impose discipline, or take any action toward an identified individual. Users may not repurpose Outputs for disciplinary, adjudicative, or law enforcement charging decisions outside a User's own institutional authority to make such decisions.

6.6

AI features are provided for Customer's compliance, campus safety, and administrative workflows in volumes consistent with the fair use expectations in the Service Level Exhibit. Users may not use the in-product AI assistant as a general purpose language model unrelated to Customer's records, or make its capacity available to a third party.

7. Sensitive Information and Authorized Institutional Purposes

7.1

The Services may provide access to sensitive institutional, incident, safety, conduct, compliance, or other information. Users may access and use such information only to the extent authorized by Customer and for legitimate institutional purposes.

7.2

Users may not use information obtained through the Services:

  • for unauthorized personal purposes;
  • to harass, threaten, stalk, discriminate against, or improperly surveil another person;
  • to disclose confidential or sensitive information to unauthorized persons; or
  • for any purpose materially inconsistent with the User's authorized institutional responsibilities.

8. Intellectual Property and Protection of the Services

8.1

Except to the extent expressly permitted by the Agreement or applicable law, Customer and its Users may not:

  • copy, modify, translate, adapt, or create derivative works of the Services;
  • reverse engineer, decompile, disassemble, decode, or otherwise attempt to derive or discover source code, underlying models, algorithms, architecture, non-public APIs, prompts, system instructions, or other non-public components of the Services;
  • remove, obscure, or alter proprietary notices contained in the Services;
  • sell, sublicense, rent, lease, distribute, commercially exploit, or provide the Services to third parties except as expressly authorized by Salus;
  • use the Services on a service bureau, outsourcing, or similar basis for the benefit of an unauthorized third party;
  • access or use the Services for the purpose of developing, training, improving, or providing a product or service that competes with the Services;
  • systematically extract Outputs, functionality, workflows, interfaces, or other elements of the Services for the purpose of replicating or developing a competing product or service; or
  • publish or disclose performance tests, benchmarking results, or comparative analyses concerning the Services without Salus's prior written consent, except where such restriction is prohibited by applicable law.
8.2

Nothing in this AUP transfers ownership of Customer Data to Salus or alters intellectual property rights expressly established under the applicable Agreement.

9. Integrations and Third-Party Systems

9.1

Where the Services connect with Customer systems or third-party systems, Customer is responsible for ensuring that it has authority to authorize the applicable connection and access. Except where the Agreement expressly provides otherwise, Salus accesses Customer's connected source systems, such as a records management, conduct, or Title IX system, on a read-only basis and does not write to, modify, or delete records within them.

9.2

Customer and its Users may not use an integration provided through the Services to:

  • access information beyond the scope authorized by Customer or the applicable third party;
  • circumvent restrictions imposed by a connected system;
  • interfere with the operation or security of a connected system;
  • cause Salus to access, retrieve, modify, transmit, or process information that Customer is not authorized to make available to Salus; or
  • attempt to cause the Services, or any Salus sync agent or service account, to write to, modify, or delete records in a connected source system outside the read-only scope described above.
9.3

Customer's use of third-party products or services may also be subject to the applicable third party's terms and policies.

10. Hosted Public Pages

10.1

The Services may host pages that Customer publishes to the public, including a daily crime log, a campus safety transparency page, and other pages Customer elects to publish, which Salus may serve at a domain Customer controls. Customer determines what is published through the review and approval settings it configures, and Customer is responsible for the content it publishes.

10.2

Customer and its Users may not publish through a hosted public page:

  • information that applicable law or institutional policy requires be withheld from public disclosure, including information identifying a victim of a sexual offense where disclosure is restricted;
  • content that is unlawful, defamatory, harassing, or that infringes the rights of a third party; or
  • content unrelated to Customer's compliance, campus safety, or institutional transparency purposes.
10.3

Customer may correct, withhold, or retract published content through the Services at any time. If Salus becomes aware that content on a hosted public page is unlawful or creates a material legal risk, Salus will notify Customer's designated administrator and work with Customer to correct or remove it. Salus will remove such content unilaterally only where required by law or where Customer has not responded and the risk is immediate, and will notify Customer promptly if it does.

10.4

Because a hosted public page may satisfy a legal publication obligation, Salus will not remove or disable a page for a billing or fair use matter, and will handle continuity on termination as provided in the Platform Agreement.

11. Outreach and Communications

11.1

Certain modules send communications on Customer's behalf, including outreach to law enforcement agencies, notices to campus security authorities, and reminders to Authorized Users. These communications may be sent using a sending identity at Customer's own domain while being transmitted through sending infrastructure that Salus operates and shares across its customers.

11.2

Customer authorizes Salus to send those communications on its behalf and, where sending occurs from Customer's domain, will maintain the authentication records Salus identifies as necessary, including sender authentication and alignment records, so that mail is properly authenticated.

11.3

Customer and its Users may not use the outreach and communication features:

  • for any purpose other than Customer's compliance, campus safety, and institutional administrative workflows;
  • to send unsolicited bulk email, marketing, solicitations, or political communications;
  • to send communications that misstate the sender's identity or the institution on whose behalf they are sent;
  • to send to purchased, harvested, or otherwise improperly obtained recipient lists; or
  • in volumes materially beyond what Customer's compliance workflows reasonably require.
11.4

Customer is responsible for the content of templates it supplies or approves and for compliance with laws applicable to its communications. Misuse can result in delivery failures, sender reputation damage affecting Customer's own domain, and degraded deliverability on shared sending infrastructure used by other Salus customers. Salus may apply sending limits, require review of templates, or pause a specific campaign to protect deliverability, and will notify Customer's designated administrator when it does.

12. Enforcement and Suspension

12.1

Salus may investigate suspected violations of this AUP. Where Salus identifies a violation, it will ordinarily contact Customer's designated administrator and work with Customer to resolve it.

12.2

This AUP does not expand the circumstances in which Salus may suspend access. Suspension of Customer's access to the Services is governed by the Platform Agreement, and Salus will suspend only on the grounds and subject to the conditions stated there, including limiting any suspension in scope and duration to what the circumstances require, notifying Customer's designated administrator, and restoring access promptly once the cause is resolved.

12.3

Salus may take proportionate measures short of suspending Customer's access to address a violation, including restricting the access of an individual User, disabling a specific feature or campaign, or applying rate limits, and will notify Customer's designated administrator where reasonably practicable.

12.4

Nothing in this section limits any right Salus has under the Agreement or applicable law.

13. Reporting Violations

13.1

Customer and Users should promptly report suspected violations of this AUP, unauthorized access, or suspected misuse of the Services to security@trysalus.com.

14. Changes to This AUP

14.1

Salus may update this AUP from time to time and will post the then-current version with the date of the most recent update. To the extent required by the applicable Agreement or applicable law, Salus will provide notice of material changes.

© Salus Solutions, Inc. · Questions: legal@trysalus.com