Skip to main content
Data Protection
Microsoft 365 Backup BCDR File Backup Vault
Cybersecurity
Vulnerability Scanning
Log In Start Free

Data Protection

Microsoft 365 Backup BCDR File Backup Vault

Cybersecurity

Vulnerability Scanning

More

Pricing Resource Center Contact
Log In Start Free

Legal

Acceptable Use Policy

Last updated: August 6, 2026

This Acceptable Use Policy forms part of the EnterProtect Terms of Service. It sets out what the platform may not be used for, and what happens if it is. Terms defined in the Terms of Service carry the same meaning here.

It applies to every organization with an EnterProtect account, to every user they authorize, and, where a partner resells EnterProtect, to that partner's own customers. A partner is responsible for the conduct of the accounts under their management.

1. Authorization is the whole policy

EnterProtect copies data off systems and scans systems for weaknesses. Both are ordinary administrative acts when done to your own estate, and both are serious matters when done to somebody else's. Almost everything below follows from that single distinction.

You may use the Service only against systems and data you own, or that you are authorized in writing to administer on the owner's behalf. If you are a managed service provider, that authorization is your agreement with your customer. You are responsible for holding it, and for being able to produce it if we ask.

2. Vulnerability scanning

Our vulnerability scanning features find weaknesses by probing systems. That is their purpose, and nothing in this policy prohibits it when it is done properly. What is prohibited is aiming it at anything you have no right to touch.

You must not:

  • scan, probe or test any host, network, address range or application that you do not own and are not authorized to assess;
  • continue scanning a target after the owner's authorization has been withdrawn, or after a customer relationship has ended;
  • use scan output to gain access to a system beyond what the assessment itself requires;
  • use the Service to conduct an assessment you have been engaged to perform for a third party, unless that third party is set up as an organization under your account and the authorization in section 1 covers them.

Scanning infrastructure you do not control may be a criminal offence under the Criminal Code of Canada, the United States Computer Fraud and Abuse Act, and comparable law elsewhere. This policy is not the only thing standing between you and that.

3. Backup, replication and stored data

You must not use the Service to store, back up or transmit:

  • material you have no lawful right to hold or copy;
  • content that is illegal to possess in the jurisdictions where you and your data reside;
  • malware, exploit kits or command and control infrastructure, other than samples held for legitimate security work and isolated so they cannot execute;
  • data you are contractually or legally barred from moving outside a particular jurisdiction, unless you have configured the Service so it does not.

We do not inspect the contents of protected data as a matter of course. We are not in a position to police what you back up, which is precisely why the obligation sits with you.

4. The platform itself

You must not:

  • access or attempt to access any part of the Service, or the systems behind it, other than through the interfaces we provide;
  • circumvent, disable or interfere with authentication, authorization, rate limiting, quotas, licensing or audit logging;
  • access data belonging to another organization, or attempt to determine whether such data exists;
  • place unreasonable load on the Service, including automated request volumes no human user could generate, other than through documented interfaces at their documented limits;
  • resell, sublicense or provide the Service to a third party except under a partner agreement with us;
  • reverse engineer the Service, except to the extent that restriction is unenforceable where you are;
  • use the Service to build a competing product, or to benchmark it for publication without telling us first.

5. Accounts and identity

You must not misrepresent who you are or who you act for, share credentials between people, or keep access for anyone who has left your organization or a customer you no longer serve. Each person who uses the platform needs their own account, because an audit trail that cannot tell two people apart is not an audit trail.

6. Testing our security

We would rather hear about a weakness than not. You may test the security of your own account and the interfaces it reaches, provided you do not access another organization's data, do not degrade the Service for anyone else, do not run denial of service or volumetric tests, and report what you find to [email protected] before disclosing it publicly.

We will not pursue a researcher who works within those limits and reports in good faith. Section 4 applies to everyone else.

7. What we do about it

Where we believe this policy has been broken, we may suspend the account or the specific feature involved, and in serious or repeated cases terminate the agreement. Where the circumstances allow it we will tell you first and give you a chance to put it right. Where they do not, because data or another customer is at immediate risk, or because the law requires us to act, we may act first and tell you after.

Suspension does not delete your data. Protected data is retained through a suspension and remains subject to the retention and deletion terms in the Terms of Service, so that a dispute about acceptable use never becomes the reason a recovery fails.

We may report unlawful activity to the relevant authorities, and we will comply with lawful orders to preserve or produce records.

8. Reporting a problem

To report abuse of the Service, write to [email protected]. To report a security weakness, write to [email protected].

9. Changes

We will post any change here and update the date at the top. If a change materially narrows what is permitted, we will give account holders notice by email before it takes effect.

All documents

  • Privacy Policy
  • Terms of Service
  • Acceptable Use Policy
  • Service Level Agreement
  • Additional Services Terms

Data protection and cybersecurity for MSPs. Recovery you can prove.

Data Protection

  • Microsoft 365 Backup
  • BCDR
  • File Backup
  • Vault

Cybersecurity

  • Vulnerability Scanning

Resource Center

  • Breach news
  • Threat advisories
  • Insights
  • Guides and white papers
  • Free Tools

Company

  • About
  • For MSPs
  • Pricing
  • Trust & evidence
  • Resources & downloads
  • Contact

Get Started

  • Request a Demo
  • Get Partner Pricing
  • The console tour
  • Datasheets
  • Console login
© 2026 Enterprotect Inc.
Privacy Legal