Acceptable use.
This policy covers use of the public Virasai AI website, its published materials, and the email routes offered here. Most of it is the short version of one idea: check our work, do not break our things, and do not use our records to make claims we did not make.
Last updated: 17 August 2026
Use the site responsibly
Use the site lawfully. Do not disrupt or damage it, attempt to gain unauthorised access, bypass access controls, or place an unreasonable technical burden on it in a way that could impair anyone else’s access.
Ordinary automated retrieval is fine and needs no permission. Crawling the site, fetching the published evidence reports, mirroring a page for offline reading, or reading it through an AI assistant are all expected uses — the reports exist to be re-checked, and robots.txt and llms.txt are there because we would like them read. Keep the request rate to something a small static site would not notice.
Security research is welcome, within limits
Testing this site or our published tools in good faith is not a breach of this policy, and we would rather hear about a weakness than not. What we ask:
Stay within your own data and your own instance. Do not run volumetric or denial-of-service testing, do not attempt to access anyone else’s information, do not social-engineer us or our service providers, and do not disclose an unfixed issue publicly before we have had a chance to respond.
Report a website issue to [email protected]. For Sentinel and Magus OpenSecMCP, the security guidance in each repository names the private route to use, including a dedicated address per component — use that rather than a public issue. Acknowledgement is best-effort: this is a small operation with no staffed security response, no bounty, and no guaranteed response time, which is stated so your expectations are accurate rather than implied.
For research that follows this policy and is reported to us privately, we will not pursue legal action over it, and we will credit you in any resulting fix unless you would rather we did not.
Do not misuse the contact routes
Do not send unsolicited bulk messages, phishing, malware, abusive or discriminatory material, unlawful content, or material that infringes another person’s rights. Do not send passwords, authentication tokens, production credentials, sensitive personal data, or confidential information unless a separate written engagement expressly asks for it and provides a secure route.
Do not turn our records into accusations
The Watch pages state what an exact published artifact declares and what changed between two of them. They do not assess intent, and most of what they record is ordinary release activity. Do not present a recorded change as evidence that a package is malicious, that a maintainer acted improperly, or that we have concluded either — and do not quote a finding while dropping the limitation published beside it.
Reaching your own conclusion from the evidence is exactly what it is for. Attributing that conclusion to us is not.
Respect rights and attribution
Do not present Virasai AI or VaHive Systems Lab research, diagrams, or software as your own work. Do not imply endorsement, affiliation, certification, or a commercial relationship that does not exist. Respect the individual licences and notices that apply to the open-source repositories and to third-party content, as set out under Licensing.
Separate engagements
If we agree to provide implementation help or a review, that work is governed by its own written scope and terms. An email enquiry alone does not grant access to software services, create a support obligation, or change this policy.
Enforcement and contact
Where we believe this policy has been breached, we may restrict access, remove links, or take other reasonable steps to protect the site and the people using it. To report suspected misuse, email [email protected].