Finic
Sign In

Acceptable use policy

Effective October 5, 2026 · Version 1.0

This Acceptable Use Policy (the "Policy") sets the rules for using the Grayson API and models, and the Finic portal and its playground, provided by Finic Technologies Inc. ("Finic") (the "Services"). It applies to every customer organization, its Authorized Users and anyone else the organization lets use the Services (together, "you"). It is part of the Master Services Agreement (the "Agreement"), and capitalized terms not defined here have the meanings given there.

Grayson exists to help detect, investigate and prevent fraud and financial crime. Analyzing data about fraud, scams, money laundering, trafficking or other harmful activity in order to detect, investigate, prevent or report it is permitted. What this Policy prohibits is using the Services to carry out, enable or conceal harm. The examples below are not a complete list: Finic may act on uses that are not listed but carry similar risks.

1. Unlawful and harmful activity

You may not use the Services to:

  • violate any law or regulation, including anti-discrimination, consumer protection, privacy, anti-money-laundering, sanctions and export control laws;
  • infringe or misappropriate anyone's intellectual property, privacy or publicity rights;
  • commit, facilitate or conceal fraud, theft, money laundering, terrorist financing, sanctions evasion or any other financial crime;
  • deceive people, including through phishing, impersonation, spoofing or pyramid schemes;
  • threaten, harass, stalk, intimidate or defame anyone, or incite violence or hatred against any person or group; or
  • facilitate human trafficking, sexual exploitation, or the sale of illegal goods, services or substances.

2. Fraud and risk decisions

Output consists of probability estimates that support your decisions; it does not make them. You may not use the Services to:

  • design, test or refine ways to get past fraud, anti-money-laundering, sanctions or identity controls, whether your own or anyone else's, other than to test and strengthen controls you operate;
  • make or support a decision about an individual on the basis of a characteristic protected by law, such as race, color, religion, national origin, sex, sexual orientation, gender identity, marital status, age, disability or receipt of public assistance, or ask questions intended to infer such a characteristic;
  • make a Consequential Decision based solely on Output, without the human review, adverse action notices, dispute processes and other safeguards that the law and your own policies require;
  • surveil, profile or target people for activity protected by law, such as lawful protest, union activity or journalism; or
  • misrepresent to anyone whether a decision or communication was made with the help of automated tools, where the law or your own commitments require you to disclose it.

3. Data you submit

Submit only data you have the right to submit and that your questions need. You may not submit:

  • data collected or shared in violation of law, or of the notices you have given and choices you have offered the people it concerns;
  • full payment card numbers, card security codes or PINs; use masked, truncated or tokenized values instead;
  • passwords, answers to security questions, one-time codes, API keys or other authentication secrets;
  • protected health information, or biometric identifiers or templates;
  • full government identification numbers, such as Social Security numbers, unless your question requires them and the law permits you to share them; or
  • malware, or content crafted to manipulate, disrupt or exploit the Services.

4. Children

You may not use the Services to exploit or endanger children, or to target minors for fraud, grooming or abuse. Using the Services to detect and report the exploitation of children, for example payments linked to child sexual abuse, is permitted, but you may never include child sexual abuse material in what you submit.

5. Security and integrity of the Services

You may not, and may not attempt to:

  • access the Services other than through the API and the Portal as documented, or scrape or crawl the Portal;
  • use another person's account or API Key without authorization, share your account, or access another customer's data or account;
  • circumvent or disable authentication, rate limits, usage limits or other security or access controls;
  • probe, scan or test the vulnerability of the Services, or load-test them, without Finic's written permission (email support@finic.ai to arrange a test);
  • monitor or intercept traffic to or from the Services, other than your own requests and responses;
  • interfere with or disrupt the Services, including by sending malware or an excessive volume of requests;
  • embed API Keys in client-side code or in software you distribute to others; or
  • reverse engineer the Services, attempt to extract model weights or training data, or use Output to build a competing model, except to the extent the law permits this despite this restriction.

6. Helping others

You may not help, encourage or allow anyone else to do anything this Policy prohibits.

7. Enforcement

Finic may investigate suspected violations of this Policy. Because Finic does not retain Input or Output, an investigation relies on account records, Usage Data and information you or others provide. If Finic reasonably believes you have violated this Policy, or are about to, it may suspend or restrict your access to the Services as described in the Agreement.

Finic may report activity it reasonably believes is unlawful to law enforcement, regulators or other appropriate authorities, share with them the information it holds that relates to the activity, and cooperate with their investigations.

8. Reporting violations

If you learn of a violation of this Policy, email support@finic.ai with the details. Finic may ask for your help investigating or stopping it, and you agree to cooperate reasonably.

9. Changes

Finic may update this Policy by posting a new version and notifying you in the Portal or by email. An update takes effect thirty (30) days after notice, or immediately if it addresses a legal or security risk or a newly identified form of misuse.