Skip to content
ComputingAmerica

Legal

Acceptable use

The rules for using systems we run for you. Short, and mostly what you would guess.

Effective

Who this applies to

This policy applies to clients and their staff using services provided or operated by Hyrax LLC d/b/a Computing America — managed IT, hosted systems, and anything else we run on your behalf. It is incorporated into the engagement agreement.

It also applies, in the parts that can apply, to anyone using this website. The website rules are in the terms.

The principle

Use the services lawfully and responsibly, and in a way that does not harm other users, the systems we manage, or third parties. Most of what follows is that sentence made specific.

What you must not do

Do not use the services to:

  • Break the law, or help someone else break it.
  • Access systems, accounts or data you have not been authorized to access.
  • Distribute malware, or disable, evade or interfere with security controls we operate.
  • Send spam, phishing or deceptive communications.
  • Infringe someone else's intellectual property.
  • Store or transmit material that is unlawful, or that we are required to remove.
  • Consume shared resources in a way that degrades the service for others.

Your security responsibilities

Security is shared, and these are the parts only you can do:

  • Keep credentials confidential and do not share accounts between people.
  • Keep multi-factor authentication enabled where we have deployed it.
  • Tell us promptly when someone leaves, so their access can be removed.
  • Report a suspected compromise as soon as you suspect it, not once you are sure.
  • Do not circumvent protective measures — patching, filtering, encryption, logging — because they are inconvenient. Tell us instead, and we will find another way.

Security testing

Do not run penetration tests, vulnerability scans or red-team exercises against systems we operate without written authorization and an agreed scope and window. This is not bureaucracy: an unannounced scan is indistinguishable from an intrusion, and we will respond to it as one, at your cost.

Authorized testing is something we do for a living. If you want it, the cybersecurity division scopes and runs it properly.

What we monitor

We monitor the health and security of the systems we manage: availability, errors, patch state, security events and the logs that make an incident reconstructible. We do not read your content beyond what is needed to operate and protect the service, or where you have asked us to look at something, or where the law requires it.

Enforcement

If something here is breached we will normally tell you and give you a chance to put it right. Where there is an active threat to you, to us or to a third party, we may suspend access first and explain immediately afterwards, because the alternative is letting harm continue while we compose an email.

Serious or repeated breaches may end the agreement, on the terms that agreement sets out.

Reporting

Report abuse, a suspected compromise or a security issue to info@computingamerica.com. If you are reporting a vulnerability in something we run, tell us what you found and how to reproduce it; we do not pursue good-faith researchers who give us a reasonable chance to fix an issue before disclosing it.