Acceptable use.
Last updated: 20 June 2026
This Acceptable Use Policy governs how you may use FlareX and the materials you bring to it. It supplements, and forms part of, our Terms of Service, and it applies to everyone who imports a project, runs a scan, receives a readiness report, uses managed hosting, or accesses any legacy builder feature. Capitalised terms not defined here have the meaning given in the Terms. If you do not accept this policy, you must not use FlareX.
1. Purpose and scope
FlareX is a managed service that assesses and helps launch AI-built web applications. You import an existing application that you own, by public GitHub repository URL or ZIP upload, and FlareX fetches it, indexes it, runs deterministic security and configuration scans, executes it in an isolated throwaway sandbox by running install, build, and boot, and generates an AI-written production readiness report. FlareX offers two paid one-time engagements, the Production Readiness Report and Production Setup, and, for applications that pass readiness, managed hosting plans onboarded with founder assistance.
This policy supplements the Terms. It sets out what you may and may not do with FlareX, the responsibilities you accept when you import code, and the boundaries of what our scan and hosting services are. Where this policy and the Terms address the same subject, both apply together; the Terms govern in the event of a direct conflict.
Who this covers. This policy applies to the import, scan, report, setup, and managed-hosting services, and to the legacy AI app and Discord-bot builder features still used by some existing accounts. The same Terms and Privacy Policy cover both the current and legacy products.
2. Import authorisation: bring only code you are entitled to scan
Importing a project gives FlareX permission to fetch, store, execute, and analyse that code. You must only import code you are genuinely entitled to put through this process.
- Ownership or authorisation. You may only import an application that you own, or that you are clearly and demonstrably authorised by the owner to scan, host, and analyse.
- No third-party private code. You must not import another party's private, confidential, or proprietary code without their permission. Selecting a public GitHub URL does not by itself make you authorised to subject that code to scanning, execution, and AI analysis.
- Your representation. By importing a repository or uploading an archive, you represent that you own it or are authorised to scan it, and you authorise FlareX to fetch, store, execute, and analyse it to produce the readiness report and, where applicable, to provide hosting.
- Rights in third-party content. Where your imported code includes third-party libraries, assets, or services, you are responsible for holding the licences and rights needed for FlareX to process them as part of the service.
Committed secrets are your responsibility. Imported source code may contain credentials or secrets you have committed to it. You are responsible for what you choose to import. We delete the raw imported archive immediately after each scan completes, and any secrets or environment values you choose to store are encrypted at rest using AES-256-GCM; even so, you should rotate any credentials that were exposed in code you no longer control.
3. Prohibited content and conduct
You must not use FlareX, the import and scan pipeline, the sandbox, the readiness report, managed hosting, or any legacy builder feature to do, host, or enable any of the following.
Unlawful, harmful, or infringing material
- Malware and malicious code. Import, host, or distribute viruses, worms, ransomware, spyware, or any code designed to damage, disrupt, or gain unauthorised access to systems or data.
- Illegal content. Import, store, or host content that is unlawful, including child sexual abuse material, content that incites violence, or material that breaches applicable export, sanctions, or other laws.
- Infringing content. Import or host content that infringes the intellectual property, privacy, or other rights of any person, or that you do not have the rights to process.
Attacks, abuse, and circumvention
- Attacking third parties. Use imported code or the sandbox to attack, scan, probe, exfiltrate from, or otherwise interfere with any third-party system, network, or data.
- Attacking FlareX. Use any part of FlareX to attack, scan, probe, exfiltrate from, or interfere with FlareX's own systems, databases, infrastructure, or other customers.
- Abusing the sandbox. Attempt to escape, break out of, persist beyond, overload, or otherwise abuse the isolated execution sandbox, or attempt to reach FlareX databases or other tenants from within it.
- Code designed to harm us. Import code that is built or configured to harm, compromise, or destabilise FlareX's systems, including code that targets the runner host, the scanning pipeline, or our network controls.
- Circumventing limits. Bypass, disable, or work around quotas, rate limits, resource limits, security controls, or access controls, including Turnstile or other anti-abuse protections.
- Sharing credentials. Share, sell, or transfer your account credentials or access, or access FlareX through anyone else's account without authorisation.
- Misusing stored secrets. Use the secret and environment storage feature to stage attacks, store unlawful material, or hold credentials you are not entitled to possess.
4. What the scan is and is not
It is important that you understand exactly what the FlareX scan and readiness report provide, so you can rely on them appropriately.
What the scan is
- Automated and deterministic. FlareX runs deterministic security and configuration scans over your imported code, indexes it, and executes it in an isolated throwaway sandbox by running install, build, and boot to assess whether and how it runs.
- Best-effort assessment. The output is an AI-written production readiness report with a 0 to 100 score and findings, generated from a bounded extract of your code. It is informational and best-effort, designed to help you understand your application's readiness to launch.
What the scan is not
- Not a security audit or penetration test. The scan and report are not a security audit, a penetration test, a formal code review, a certification, or any guarantee, assurance, or warranty that your application is safe, secure, compliant, or fit for any purpose. The score and findings are an opinion, not a statement of fact about the condition of your application.
- Not complete. Because the process is automated and best-effort, it can miss real issues and can produce false positives and false negatives. A high score does not mean your application is free of vulnerabilities, and a finding does not always indicate a genuine problem.
- Not a transfer of responsibility. You remain solely responsible for your application, including its security, its compliance with applicable laws, and its fitness for your purpose. You should apply your own judgement and obtain independent professional advice where appropriate, and you must not treat the report as a substitute for that judgement or advice.
Disclaimer and your consumer rights. To the maximum extent permitted by law, FlareX provides the scan and the readiness report without any warranty of accuracy, completeness, or fitness for purpose, and is not liable for any loss arising from your reliance on them. Nothing in this policy excludes, restricts, or modifies any consumer guarantee, right, or remedy that you have under the Australian Consumer Law or other law and that cannot lawfully be excluded; where a guarantee that cannot be excluded applies, our liability is limited, to the extent the law allows, to resupplying the relevant service or paying the cost of having it resupplied.
5. Managed hosting acceptable use
Managed hosting plans are offered after an application passes readiness and are currently onboarded with founder assistance. When you host an application with FlareX, the rules in this policy continue to apply, and the following additional conditions apply to hosted applications and the traffic they serve.
- No illegal or abusive content. You must not host applications or content that are unlawful, infringing, deceptive, or abusive, or that expose others to harm.
- No cryptocurrency mining. You must not use hosting resources for cryptocurrency mining or other disproportionately resource-intensive activity unrelated to operating your application.
- No spam. You must not use hosting to send spam, conduct phishing, distribute malware, or carry out bulk unsolicited messaging.
- No attacks or abuse from hosting. You must not use hosted infrastructure to attack, scan, or interfere with third parties, FlareX, or other tenants, or to act as a relay, proxy, or staging point for such activity.
- Operate responsibly. You are responsible for the security, configuration, content, and lawful operation of any application you host with FlareX, and for the conduct of its users.
6. Resource limits and fair use
FlareX runs on shared infrastructure, including a cloud VPS hosting provider and Cloudflare services. To keep the service reliable for everyone, your use is subject to resource limits and fair use expectations.
- Respect applicable limits. Imports, scans, sandbox execution, hosting, and any legacy builder usage are subject to compute, memory, storage, time, and rate limits, including those associated with your plan or engagement.
- No overloading. You must not deliberately or recklessly overload, degrade, or destabilise the scanning pipeline, the sandbox, the runner host, or the hosting platform, whether through your imported code, automated requests, or excessive volume.
- Reasonable and intended use. Use FlareX for its intended purpose. Sustained use that is disproportionate to normal assessment and hosting activity, or that interferes with other customers, may be limited.
7. Enforcement
We may act to protect FlareX, our customers, and third parties where we reasonably believe this policy or the Terms have been breached, or where action is needed to address a security, legal, or operational risk.
- Warning. We may contact you to require that you stop or correct conduct.
- Removal of content. We may remove, disable, or quarantine imported code, stored data, reports, or hosted content.
- Suspension. We may suspend a scan, an import, hosting, or your access, including immediately where the risk is serious.
- Termination. We may terminate your access to FlareX in accordance with the Terms.
Where it is practicable and lawful to do so, we will aim to act proportionately and to give you notice, but we may act without prior notice where necessary to address an urgent or serious risk. Enforcement action under this policy does not limit any other rights or remedies available to us under the Terms or at law.
8. Reporting abuse
If you become aware of any content or conduct that breaches this policy, including a hosted application, an imported project, or activity targeting FlareX or a third party, please report it to [email protected]. Include enough detail for us to identify and investigate the issue. We take reports seriously and will review them in good faith.
9. Changes to this policy
We may update this Acceptable Use Policy from time to time, for example to reflect changes to the service, new abuse patterns, or legal requirements. When we make material changes, we will update this page and, where appropriate, notify you. Your continued use of FlareX after a change takes effect means you accept the updated policy.
10. Contact us
FlareX operates from Australia. You can reach us at the following addresses for matters relating to this policy and your use of the service.
Acceptable use, terms, and legal: [email protected]
Privacy and data requests: [email protected]
Reporting abuse and general support: [email protected]