Acceptable Use Policy
Effective July 23, 2026
This Acceptable Use Policy ("AUP") applies to every user, agency, client-portal user, integration, automation, and API accessing OneagencyOS. Capitalized terms not defined here have the meaning in the applicable agreement.
1. Lawful and Authorized Use
You may use OneagencyOS only for lawful insurance-agency and related business activities within your authority. You must comply with licensing, appointment, privacy, consumer-reporting, electronic-signature, communications, advertising, records, and insurance requirements that apply to your work. You may not impersonate another person, misrepresent authority, or access an agency, client, carrier, mailbox, phone system, document, or account without permission.
2. Prohibited Conduct
- Submitting false, deceptive, incomplete, or fabricated applications, signatures, claims, quotes, policy information, payments, or documents.
- Binding, changing, canceling, renewing, or representing insurance without appropriate authority.
- Attempting to bypass carrier controls, security checks, rate limits, consent requirements, or access restrictions.
- Scanning, probing, exploiting, disrupting, reverse engineering, or introducing malicious code into OneagencyOS or a connected service.
- Sharing credentials, using stolen credentials, or allowing an unauthorized person to use an account.
- Using Customer Data for personal purposes, discrimination, harassment, surveillance, identity theft, fraud, or an unlawful adverse decision.
- Uploading unlawful, infringing, defamatory, obscene, or malicious content.
- Reselling, sublicensing, benchmarking for a competitor, or creating a competing product from the service unless OneagencyOS gives written permission.
3. Insurance and Consumer Reports
You may request insurance scores, credit-based insurance information, motor-vehicle records, claims reports, or other consumer-report information only with a lawful purpose, required authorization, and required disclosures. You must not direct OneagencyOS or a connected provider to obtain a report before the appropriate acknowledgment or authorization is recorded. Users remain responsible for carrier-specific disclosures, adverse-action requirements, and limits on use.
4. Email, SMS, and Calling
You may send communications only when you have a lawful basis and any required consent. Commercial email must use accurate sender and subject information, identify advertising when required, include a valid postal address when required, provide a functioning opt-out method, and honor opt-out requests. Automated or prerecorded calls and texts require the level of consent applicable to the communication. Do not send spam, purchased-list campaigns, phishing messages, or deceptive communications. Maintain suppression and do-not-contact records and comply with carrier, provider, CAN-SPAM, TCPA, state, and industry rules.
5. Artificial Intelligence and Automation
AI and automation must remain under appropriate human supervision. You may not use AI output as the sole basis for an unlawful or high-impact decision, represent unreviewed AI output as verified fact, fabricate carrier responses, or automate a transaction you are not authorized to perform. Review extracted application data, coverage values, quotes, legal disclosures, client communications, and carrier submissions before relying on them.
6. Personal and Sensitive Information
Collect and use only information reasonably needed for an authorized workflow. Do not upload full payment-card data, authentication secrets, or highly sensitive information unless a supported field or documented workflow is specifically designed for it. Protect downloaded files and exports, follow role-based access, and remove access promptly when duties change. Agencies must configure retention and client-portal sharing consistent with their obligations.
7. Integrations, Scraping, and Carrier Access
Use only credentials, APIs, websites, and data sources that the agency is authorized to access. Automated access must comply with the provider's terms, technical restrictions, and applicable law. You may not use OneagencyOS to defeat CAPTCHAs, evade provider controls, overload a service, or scrape restricted information. A carrier or provider connection may be disabled if authorization is unclear or the provider objects.
8. Security Cooperation
You must use reasonable endpoint and account security, promptly install relevant updates, maintain accurate contact information, and report suspected unauthorized access or data exposure to hello@oneagencyos.com. Do not conceal an incident, destroy relevant evidence, or interfere with an investigation.
9. Enforcement
OneagencyOS may investigate suspected violations and may restrict an integration, remove unlawful content, suspend access, preserve evidence, or notify the controlling agency, provider, or authorities when reasonably necessary. When practicable, we will provide notice and an opportunity to cure. Serious, repeated, fraudulent, or dangerous violations may result in immediate suspension or termination.
10. Reporting
Report abuse or security concerns to OneagencyOS LLC at hello@oneagencyos.com.