Legal
AI Acceptable Use Policy
Effective and last updated: August 19, 2026
This policy governs use of the AI capabilities in Trunnion products and custom builds delivered by Trunnion AI, LLC ("Trunnion AI"). It is referenced by the Website Terms of Use and is incorporated by reference into master agreements that cite it, so it binds in the contract and not only on this website. Where an agreement imposes stricter terms, the stricter terms control.
Prohibited uses
Customers and users may not use Trunnion products to:
- Violate any law, regulation, court order, or the rights of any person, including privacy, intellectual property, and publicity rights.
- Generate or distribute content that deceives, such as impersonating a real person or organization without disclosure, fabricating records or provenance, or presenting AI output as an authoritative human determination.
- Develop, plan, or facilitate weapons, or produce content that provides material uplift for chemical, biological, radiological, nuclear, or explosive harm.
- Create, train on, or distribute malicious code, or probe, bypass, or defeat security, authorization, or audit controls, whether Trunnion's or a third party's, outside an authorized test.
- Conduct unlawful surveillance, tracking, or profiling of individuals, or target people based on protected characteristics for exclusion or harm.
- Make or support decisions that unlawfully discriminate, or process data the deployment's written scope does not permit, including classified information, export-controlled data, or regulated records without the required controls.
- Exceed authorized access, resell or expose the services to unauthorized parties, or remove, falsify, or tamper with audit records.
Human review obligations
Trunnion products are designed to prepare, draft, score, and route work for human decision, with consequential actions pausing at approval gates. Customers are responsible for keeping those gates staffed and effective: assigning qualified reviewers, defining which actions in their deployment are consequential, keeping approval thresholds current, and testing that the review path works under real operating conditions. Disabling or routinely rubber-stamping an approval gate defeats the control and is a misuse of the product.
Consequential decisions
AI outputs may be inaccurate, incomplete, biased, outdated, or unsuitable. Customers may not use a Trunnion product's output as the sole basis for a decision that produces legal or similarly significant effects on a person, including employment, credit, housing, insurance, health care, education, government benefits, or law enforcement outcomes, unless the specific use has been legally and operationally approved by the customer, effective human review is in place, and all notices, assessments, appeal paths, and records required by applicable law exist. Some jurisdictions grant individuals rights around automated decision-making; complying with those rights for the customer's use case is the customer's responsibility, and Trunnion AI provides reasonable product support for it.
Data boundaries
Do not submit data a deployment's written scope and controls do not permit. Public website forms are never an approved channel for classified information, CUI, export-controlled data, procurement-sensitive material, credentials, or customer tenant data. Whether a hosted or local model receives data in a given deployment, and what its provider may do with it, is documented per engagement; see the AI Transparency Notice and the Data Processing Addendum.
Security testing
Good-faith security research against Trunnion's public website is welcome through the process on the security page. Testing a contracted deployment requires prior written authorization that states scope, timing, and rules of engagement.
Enforcement
Trunnion AI may investigate suspected violations and may suspend or terminate access where a violation creates legal exposure, harms others, or compromises the integrity of governance and audit controls, following the notice and cure terms of the applicable agreement where they apply. Where feasible, Trunnion AI will notify the customer and work to restore compliant use.
Reports and questions
Report suspected misuse or ask about an intended use at contact@viceroynm.com. We update this policy prospectively by posting a revised effective date; material changes are highlighted for contracted customers.