Acceptable Use Policy
Rules for responsible use of Varajen services.
Authorized business use
Varajen may be used only by authorized users for lawful HR, recruiting, vendor, time, payroll, communications, analytics, and workforce operations consistent with the customer's agreement, configured roles, and applicable law.
Security abuse
Users may not gain unauthorized access; probe, scan, or test without written authorization; bypass tenant, role, rate, payment, or approval controls; introduce malware; interfere with availability; extract secrets; or access another person's or tenant's data.
Unlawful or harmful content
Users may not process content that is unlawful, fraudulent, infringing, defamatory, threatening, exploitative, or designed to facilitate harm. Spam, phishing, deceptive impersonation, credential theft, and unauthorized surveillance are prohibited.
Employment and discrimination
Users may not use Varajen to make unlawful discriminatory employment or workforce decisions. Customers must provide required notices, accommodations, consent, contestability, and human review for consequential decisions.
AI and automation
Users may not submit content they lack authority to process, attempt model extraction, generate malware, evade safeguards, or represent AI output as independently verified. Automated actions must remain within approved tenant policy and human-oversight requirements.
Integrations and communications
Users must respect provider terms, API limits, recipient consent, opt-out requirements, messaging laws, and job-board rules. Credentials and integration access may not be shared outside the authorized tenant context.
Sensitive and regulated data
Government identifiers, bank information, health information, children's data, and other regulated records may be processed only where the service, contract, customer policy, and law authorize it. Such data must not be placed in free-text fields, support tickets, or integrations not designed for it.
Enforcement
Varajen may investigate suspected violations, preserve relevant evidence, remove harmful content, restrict features, suspend access, or notify the customer and authorities where appropriate. Where practicable, actions are proportionate to risk and governed by the customer agreement.
Reporting
Report abuse through /contact/request/?type=security. Provide relevant tenant, URL, timestamp, and non-sensitive evidence; never email passwords, tokens, bank data, government identifiers, or unrelated personal records.
For vendor onboarding, security questionnaires, compliance review, data processing questions, or contract review, contact the Varajen team.