Acceptable Use Policy
Last updated: 14 September 2026. Standard governing all digital storefronts, client portals, APIs, and Corewisecorp OS environments.
1. Purpose and Scope
This Acceptable Use Policy ("AUP") defines the rules and restrictions governing access to and use of all software applications, digital storefronts, automated webhooks, inventory synchronizers, and operating interfaces provided by Corewisecorp Partners Ltd ("Corewisecorp").
This policy applies to all business clients, authorized staff users, API consumers, and end-customers interacting with Corewisecorp infrastructure. By accessing any part of our platform or deploying operational code commissioned through our consultancy, you agree to comply with this AUP.
2. Prohibited Activities
You may not access or use our platform or infrastructure for any of the following prohibited purposes:
Security & Infrastructure Interference
Attempting to probe, scan, or test the vulnerability of any system, network, or API endpoint; circumventing authentication mechanisms; launching denial-of-service (DoS/DDoS) floods; or transmitting worms, trojans, ransomware, or malicious payload scripts.
Financial & Invoice Abuse
Using our automated invoicing modules to issue fraudulent or fictitious invoices; processing payment card details without full FCA/PCI-DSS compliance; or tampering with Making Tax Digital (MTD) VAT reporting ledgers.
API & Webhook Resource Exhaustion
Executing aggressive automated polling routines that bypass webhook push protocols; high-frequency scraping of catalogue inventories; or deliberate degradation of the sub-50ms deterministic multi-channel engine.
Unlawful Trade & IP Infringement
Selling prohibited goods, counterfeit items, or unlicenced products under UK law; transmitting unsolicited marketing spam; or infringing copyrights, trade secrets, or patents belonging to Corewisecorp or third parties.
3. Account Security & Credential Hygiene
Clients are responsible for all activity conducted through their accounts, API tokens, and administrative credentials:
- Strong Passwords & 2FA: Administrative accounts must employ multi-factor authentication (2FA) and high-entropy passwords.
- Role-Based Access: Merchant staff access (e.g. kitchen display operators, EPOS cashiers, rota supervisors) must be configured with minimal required privilege.
- Immediate Notification: If you suspect that an API key, terminal token, or administrative account has been compromised, you must inform us immediately at security@corewisecorp.co.uk.
4. Rate Limits and Fair Usage
To ensure consistent sub-50ms performance for all UK merchants on the cluster, API endpoints are subject to rate limiting:
- Standard Webhook Ingestion: Up to 1,200 requests/minute per client instance.
- Storefront Catalog Querying: Unmetered via edge CDN cache; uncached origin calls limited to 200 requests/second.
- Burst Allowance: High-traffic retail peaks (e.g. Black Friday, Boxing Day sales) are automatically accommodated with prior notification to your Senior Growth Consultant.
5. Vulnerability Disclosure & Ethical Research
We welcome responsible security research. If you believe you have discovered a vulnerability within our public endpoints, digital storefronts, or operating software, please disclose it to security@corewisecorp.co.uk. We commit to acknowledging reports within 24 hours and do not pursue legal action against researchers acting in good faith without data exfiltration or service disruption.
6. Enforcement & Incident Resolution
Corewisecorp reserves the right to suspend or terminate service access without liability in the event of severe breaches of this policy. Where practicable, we will issue a written warning and allow a 24-hour remediation window before temporary isolation of an affected endpoint.
General Legal Desk: contact@corewisecorp.co.uk
Corewisecorp Partners Ltd, 45 Charlotte Street, London W1T 1RR