US-based RMM platform · Lancaster, Pennsylvania Support Mon–Fri, 8:00 AM – 8:00 PM ET

Acceptable Use Policy

An RMM platform grants privileged access to computers. This policy defines the boundaries of legitimate use and what happens when they are crossed.

1. Authorization is the fundamental rule

You may enroll and manage a device only where you have lawful authority to do so — because you own it, because your organization owns it, or because the owner has given you documented authorization, for example under a managed services agreement. This applies to every function: monitoring, inventory collection, script execution, patch deployment and remote access.

Accessing a computer without authorization may violate the federal Computer Fraud and Abuse Act (18 U.S.C. § 1030), state computer-crime statutes, and wiretap or privacy laws. If you use our platform to do it, you are solely responsible, and we will cooperate with lawful investigations.

Where you manage devices used by employees or clients, you are responsible for providing whatever notice or consent applicable law and your own policies require — particularly for remote session monitoring or session recording. We provide end-user consent prompts and session indicators for attended sessions; using them appropriately is your obligation.

2. Prohibited activities

2.1 Unauthorized access and surveillance

  • Enrolling, monitoring or controlling any device without authorization from its owner
  • Using the platform for covert surveillance of individuals, including installing agents on personal devices without the owner's knowledge and consent
  • Deploying agents as part of "stalkerware" or any scheme to monitor a person rather than manage an organization's assets
  • Attempting to access another customer's tenant, data or API resources
  • Probing, scanning or testing the security of the platform without our written authorization, other than good-faith vulnerability research reported under our responsible disclosure process

2.2 Malicious and harmful use

  • Distributing malware, ransomware, cryptominers, keyloggers or spyware through scripts or software deployment
  • Using automation to disable endpoint protection, delete logs, or conceal activity from a device owner or from your own audit trail
  • Launching denial-of-service traffic, port scanning third-party networks, or participating in botnet activity
  • Circumventing licensing, activation or digital rights controls of third-party software
  • Exfiltrating data from managed devices for purposes outside your service relationship with their owner

2.3 Platform integrity

  • Reverse engineering, decompiling or tampering with the agent or console except where such rights cannot be excluded by law
  • Reselling, sublicensing or providing the platform to third parties except under an authorized reseller or MSP arrangement with us
  • Sharing console credentials between individuals, or bypassing multi-factor authentication
  • Deliberately generating excessive load, exceeding published API rate limits, or interfering with other customers' use of the service
  • Misrepresenting your identity, your organization, or your authority to act for a client

2.4 Legal and regulatory

  • Any use that violates US federal, state or local law, or the law of the jurisdiction where a managed device is located
  • Use in violation of US export control laws or sanctions programs administered by OFAC, including making the service available to prohibited parties or in embargoed territories
  • Storing content in the platform that infringes intellectual property rights or contains unlawful material
  • Using the platform to process regulated data in a manner that breaches your own obligations under HIPAA, PCI DSS, GLBA, FERPA or similar frameworks

3. Scripts, automation and change control

Automation at fleet scale can cause damage at fleet scale. You are responsible for the scripts you run and for their effects. We require that you:

  • Review script content before approving it, especially anything obtained from an external source
  • Use the approval workflow rather than granting organization-scope execution broadly
  • Test destructive or configuration-changing scripts on a pilot group before wide deployment
  • Not use automation to interfere with security controls that a device owner has deliberately configured
  • Retain script execution records for the period your own compliance obligations require, exporting them if longer than platform retention

We do not review or approve your scripts, and we are not responsible for their outcomes. Scripts we publish in the shared library are provided as examples for you to review and test in your environment.

4. Fair use of platform resources

Plans include reasonable use of the platform's capacity. We publish API rate limits and expect integrations to respect them, to back off on error responses, and to avoid polling patterns that request the same data continuously when webhooks are available. If your usage materially exceeds normal patterns for your endpoint count, we will contact you to discuss it before taking any action, and if a genuine capacity concern exists we will work out an accommodation or an appropriate plan rather than throttling you without warning.

5. Enforcement

Our approach is proportionate and, wherever possible, starts with a conversation:

  1. Notice. For most issues, we contact your administrative contact, describe the concern, and ask you to remediate within a stated period.
  2. Restriction. If the issue continues, we may restrict a specific capability — for example, disabling an API key or a script — while the matter is resolved.
  3. Suspension. For activity that poses an immediate security risk to the platform, to other customers, or to third parties, or that appears unlawful, we may suspend access immediately and notify you as soon as practicable with the reason.
  4. Termination. Repeated or severe violations may result in termination under the Terms of Service. The 30-day money-back guarantee does not apply to accounts terminated for breach of this policy.

Where we are legally required to preserve or disclose information in connection with an investigation, we will do so, and we will notify you unless prohibited by law. Suspension or termination for cause does not entitle you to a refund of prepaid fees, and does not limit any other remedy available to us.

6. Reporting abuse or a suspected violation

If you believe our platform is being used to access devices without authorization, to distribute malware, or otherwise in violation of this policy, report it to Info@itsupport-rmm.com with the subject line "Abuse report", or call +1 717 823 6666. Include any evidence you can share safely: agent identifiers, hostnames, timestamps with time zone, and how you became aware of the activity. We acknowledge abuse reports within two business days and investigate every credible report. Reports may be made anonymously, although a contact address helps us ask follow-up questions.

Security vulnerabilities in the platform itself should be reported under our responsible disclosure process rather than as an abuse report.

7. Changes to this policy

We may update this policy as threats and legal requirements change. Material changes are published here with an updated date, and active customers are notified by email at least 30 days before they take effect, except where an urgent security or legal issue requires an immediate change, in which case we notify you as soon as the change is made and explain why.

8. Contact

ITSupport RMM
401 W Lemon St
Lancaster, PA 17603
United States
Phone: +1 717 823 6666
Email: Info@itsupport-rmm.com