OmnaSense Acceptable Use Policy
Effective Date: August 26, 2026
Last Updated: August 26, 2026
This Acceptable Use Policy ("AUP") governs use of the OmnaSense Services and is
incorporated into the OmnaSense Terms of Service. Capitalized terms not defined here have
the meanings in the Terms.
The core rule is simple: use OmnaSense only on systems you are authorized to test, within
the authorized scope, using safe test data and reasonable traffic.
1. Authorized Targets Only
You may monitor or connect only a website, domain, application, account, endpoint, tag
manager, server-side container, marketing destination, or customer journey that you own,
control, or have express authorization to test.
Authorization must cover the actual activity configured in OmnaSense, including:
• pages, subdomains, environments, accounts, and endpoints;
• crawl depth, page limits, frequency, concurrency, and schedule;
• journey actions such as navigation, clicking, typing, form submission, and account
changes;
• evidence collection, screenshots, and server-side polling;
• third-party integrations and credentials; and
• the duration of monitoring.
Agencies and consultants must maintain documented permission from each client. You must
stop monitoring immediately if permission expires, is withdrawn, or is disputed. A public page,
accessible endpoint, or working credential does not by itself authorize testing.
2. Prohibited Security and Access Activity
You may not use the Services to:
• access or attempt to access a system, account, data, or function without authorization;
• exceed granted permission or evade a target's access controls;
• bypass authentication, paywalls, consent controls, CAPTCHA, rate limits, bot controls,
or technical restrictions;
• guess passwords, conduct credential stuffing or brute-force activity, enumerate
accounts, or test stolen credentials;
• scan for or exploit vulnerabilities, deliver malware, execute malicious code, establish
persistence, or exfiltrate data;
• interfere with, disable, degrade, overload, or disrupt a system, including through
denial-of-service activity;
• probe internal networks, private addresses, cloud metadata services, or infrastructure
not expressly included in an approved scope;
• impersonate another person or falsify source, authorization, or ownership information; or
• use a finding to harm, extort, deceive, or improperly pressure another person.
Good-faith security testing of OmnaSense itself requires prior written authorization. Report
suspected vulnerabilities privately to the in-product Help & support channel.
3. Prohibited Data Collection and Content
You may not intentionally use the Services to collect, store, expose, or transmit:
• real payment-card numbers, card authentication data, bank credentials, or
financial-account passwords;
• protected health information or patient records;
• Social Security numbers, passport numbers, driver's-license numbers, or comparable
government identifiers;
• biometric identifiers or templates;
• production passwords, private keys, secret answers, session tokens, or unrestricted API
credentials in recorded inputs or visible artifacts;
• precise geolocation tied to an identifiable person;
• information from a child-directed service or personal information of a child under 13;
• unlawfully obtained personal, confidential, proprietary, or trade-secret information;
• content that is illegal, defamatory, infringing, fraudulent, deceptive, or that promotes
violence or abuse; or
• other sensitive or regulated data that OmnaSense has not expressly approved in a
signed writing.
Incidental personal information may appear in pages, events, URLs, data layers, requests, or
screenshots. You must minimize collection, use synthetic or masked data, restrict test routes
and accounts, review artifacts, and promptly delete or report prohibited data.
4. Safe Journey Monitoring
Recorded and replayed journeys may take actions on a target. Unless a target is expressly
configured for safe automated testing, you may not use journey monitoring to:
• complete real purchases, transfers, donations, wagers, bookings, applications, or
subscriptions;
• send messages or publish content to real users;
• create, delete, or materially change a real person's account or rights;
• accept legal terms, consent, or disclosures on behalf of another person;
• change production pricing, inventory, permissions, security settings, or business
records; or
• trigger emergency, safety-critical, medical, financial, employment, housing, insurance,
or government decisions.
Use dedicated test accounts, test payment methods, sandbox endpoints, idempotent actions,
and cleanup procedures. You are responsible for downstream effects, including analytics
events, audience membership, advertising attribution, automated campaigns, logs, and
provider fees.
5. Responsible Crawling and Traffic
You must configure monitors to produce reasonable, proportionate traffic. Do not intentionally
create excessive load, evade target rate limits, or coordinate monitors to overwhelm a target.
Use the minimum crawl scope, frequency, concurrency, and page count needed for the
monitoring purpose.
You are responsible for reviewing applicable client instructions, target terms, robots directives
where legally or contractually applicable, and provider policies. If a target asks you to reduce
or stop traffic and you cannot establish clear authority, pause the monitor and resolve the
issue before continuing.
OmnaSense may throttle, limit, pause, or block traffic to protect a target, the Services, or third
parties.
6. Third-Party Integrations and Server-Side Evidence
You may connect only accounts and integrations you are authorized to access. Use the
narrowest permissions that support the monitor, store credentials only through approved
secret functions, and revoke credentials when no longer needed.
You may not use integration or evidence-polling features to:
• read another customer's or account holder's data;
• enumerate unrelated events, users, containers, or destinations;
• bypass provider access restrictions;
• retrieve raw payloads unrelated to the configured test; or
• violate a provider's terms or developer policies.
Where OmnaSense supports hashed or minimized identifiers, use those methods. Do not
place secrets in monitor names, URLs, assertions, screenshots, support messages, or other
fields not intended for secret storage.
7. Privacy and Consent
You must comply with privacy, interception, communications, employment, and
data-protection laws applicable to your monitoring. You are responsible for required notices,
permissions, consents, contracts, data-subject requests, and retention decisions.
You may not use OmnaSense for covert surveillance of real users, employees, contractors, or
competitors; to build profiles about identifiable people; or to infer sensitive characteristics.
OmnaSense is designed for synthetic observability, not session replay of real visitors or
behavioral advertising.
You must not disable or circumvent a target's consent-management behavior merely to create
evidence, unless the test scope expressly authorizes that condition and the activity is lawful.
Clearly distinguish tests of consent states from real user consent.
8. Alerts and Communications
Provide alert recipients only when you are authorized to do so. Do not use OmnaSense to
send spam, phishing, misleading messages, harassment, or unlawful marketing. Maintain
current recipient lists and remove people who should no longer receive alerts.
You may not manipulate monitoring results or alerts to deceive a client, vendor, regulator, or
other person.
9. Misuse of OmnaSense or Other Customers
You may not:
• attempt to access another customer's workspace, monitor, evidence, artifact, or secret;
• test tenant isolation or OmnaSense infrastructure without written authorization;
• scrape or systematically extract the Services, documentation, or non-public product
data;
• reverse engineer the Services except where a restriction is prohibited by law;
• interfere with authentication, billing, logging, alerts, or abuse controls;
• submit malicious files, instructions, URLs, redirects, or payloads;
• conceal the source or purpose of abusive traffic; or
• help another person violate this AUP.
10. Regulated and High-Risk Uses
Without a signed written agreement expressly approving the use, you may not use
OmnaSense in a manner that makes it a required component of:
• emergency or life-safety systems;
• medical diagnosis, treatment, or clinical decisions;
• credit, lending, insurance, housing, employment, education, or government-benefit
eligibility decisions;
• securities trading or movement of funds; or
• legal compliance certification.
You may use OmnaSense to gather technical evidence related to an authorized site, but the
Services do not replace qualified professional review or independent controls.
11. Reporting Concerns
Report suspected abuse to the in-product Help & support channel and security vulnerabilities to [SECURITY
EMAIL]. Include the relevant domain, monitor or workspace identifier if available, dates, a
concise description, and non-sensitive evidence. Do not send passwords, private keys,
payment-card data, or another customer's artifacts by email.
OmnaSense may investigate suspected violations and may request evidence of authorization.
You agree to cooperate reasonably with an investigation.
12. Enforcement
OmnaSense may warn, throttle, limit, pause, remove data, suspend, or terminate access
based on the nature, urgency, frequency, and impact of a violation. We may act immediately
when necessary to protect a target, customer, third party, or the Services; comply with law; or
address unauthorized activity.
Where practical and lawful, OmnaSense will provide notice and an opportunity to cure. We
may preserve relevant records, notify an affected customer or provider, or report conduct to
authorities when legally required or reasonably necessary to prevent harm.
13. Changes to This AUP
We may update this AUP as the Services and risks evolve. We will post the revised version
and update the date above. Material changes will be communicated as required by the Terms
or applicable law.
14. Contact
OmnaSense
Mailing address available through the in-product Help & support channel.
Abuse: the in-product Help & support channel
Security: the in-product Help & support channel
Legal: the in-product Help & support channel