Legal

Dokima Acceptable Use Policy

Last updated: 3 August 2026

This Acceptable Use Policy (“Policy”) applies to every trial, subscription, free open-source licence and other authorised use of Dokima. It forms part of the applicable agreement with Northloom Ltd (“Northloom”).

1. Core rule: authorised defensive review only

Dokima may be used only for lawful, defensive source-code security review. You must own, control or have clear permission to assess every repository, codebase and related material processed with Dokima. A public repository is not automatically permission to conduct every form of security testing or disclosure.

You are responsible for the conduct of your users and for keeping evidence of relevant authority, scope and permissions.

2. Prohibited use

You must not use Dokima, its output or an integrated runner to:

  • access, test, target or interfere with systems, accounts, repositories or data without clear authorisation;
  • exploit a live system or deploy, weaponise or operationalise an exploit against a third party;
  • create, deliver or control malware, ransomware, destructive code, command-and-control capability, persistence, phishing or credential-theft tooling;
  • evade security controls, monitoring, attribution, sanctions, licensing or access restrictions;
  • steal, expose, sell or misuse credentials, personal data, confidential information, trade secrets or intellectual property;
  • disrupt service, degrade systems, corrupt data or cause unauthorised changes;
  • impersonate another person, misrepresent authority or conceal a prohibited end user, destination or end use;
  • provide an offensive security or targeting service to a third party unless Northloom has expressly approved the use in writing and you hold all necessary authority;
  • make automated decisions about individuals with legal or similarly significant effects;
  • violate export-control, sanctions, privacy, computer-misuse, intellectual-property or other applicable law; or
  • encourage, assist or enable another person to do any of the above.

Possessing a finding or proof-of-concept fragment generated during authorised source review does not authorise testing against a deployed system.

3. Repositories, secrets and personal data

Use least-privilege repository access and limit the review scope to what is authorised and necessary. Do not deliberately add unrelated personal data, production credentials, keys or secrets to prompts or support material.

If repositories legitimately contain secrets or personal data, you must assess whether the selected AI runner and its data location, retention and training practices are suitable before use. You must have a lawful basis and any required notices, agreements or permissions for processing personal data.

Northloom does not control Customer-selected runner providers. You are responsible for runner credentials, settings, charges, security and compliance.

4. Human validation and safe handling of findings

Dokima findings may be incomplete, incorrect or misleading. Before relying on, remediating or disclosing a finding, you must use suitably qualified human review to confirm the evidence, severity, affected scope and recommended action.

You must protect findings, reports and reproduction detail according to their sensitivity. Do not publish secrets, personal data, unnecessary exploit detail or confidential third-party material.

5. Vulnerability disclosure

Where a finding concerns third-party or open-source software, you must comply with applicable law, repository policies, contractual duties and any coordinated vulnerability-disclosure process. You must not use Dokima to pressure a maintainer, demand payment, threaten publication or obtain unauthorised access.

Unless you have the right and authority to publish, provide potentially sensitive findings privately to the relevant maintainer or vendor and allow a reasonable opportunity to respond. Publication must not include material you lack the right to disclose.

A Dokima free open-source programme may include a separately accepted 120-day automatic publication condition. Where it applies, that programme condition governs publication timing, but it does not authorise disclosure of secrets, personal data or third-party confidential material.

6. Territorial, sanctions and export restrictions

Dokima is offered only to approved organisations established in the United States, Canada, United Kingdom, Australia, New Zealand, Jersey, Guernsey or Isle of Man. It may be procured, deployed and ordinarily used only for approved operations and users in those places.

Temporary and incidental travel by an otherwise authorised user does not by itself breach this Policy, but it must not become installation, deployment or ordinary use for an establishment, operation, affiliate or person outside those places. You must not transfer, supply, divert or make Dokima available contrary to the applicable agreement or trade law.

You must not use or supply Dokima for a sanctioned or prohibited person, destination or end use, or for activities connected with weapons of mass destruction, prohibited military end use, unlawful surveillance, repression or human-rights abuse. You must promptly tell Northloom if ownership, end users, destination or intended use changes materially.

7. Security and licence integrity

You must:

  • keep installers, licence material and account credentials secure;
  • install security updates within a reasonable period;
  • maintain suitable endpoint, repository and backup controls;
  • promptly report suspected compromise of Dokima or licence credentials to security@northloom.ai; and
  • cooperate reasonably with investigation and containment of misuse or a security incident.

You must not probe or bypass Northloom’s licensing, delivery, website, update or access controls except under Northloom’s prior written vulnerability-testing authorisation.

8. Enforcement

Northloom may investigate suspected violations and request information reasonably needed to verify authority, location, end use and compliance. Northloom may limit, suspend or terminate access where it reasonably believes this Policy has been breached or where continued supply creates a legal, security, sanctions or misuse risk.

Where appropriate, Northloom will give notice and an opportunity to remedy. Serious, deliberate, unlawful or urgent conduct may result in immediate suspension or termination. Northloom may preserve evidence and report conduct to an affected party or authority where required or permitted by law.

9. Reporting concerns

Report suspected product or service vulnerabilities to security@northloom.ai. Report misuse or legal concerns to contact@northloom.ai. Product support is available at support@dokima.net.

10. Changes

Northloom may update this Policy to address legal, security or product developments. Material changes will be notified as stated in the applicable agreement.