Legal
Acceptable Use Policy
Effective October 5, 2026
Superendpoint gives administrators privileged control over computers. This Acceptable Use Policy sets out the rules for using that control responsibly. It forms part of the agreement between SUPERENDPOINT LLC (“Superendpoint,” “we,” or “us”) and each customer, and it applies to everyone who uses the Service on a customer’s behalf. Capitalized terms not defined here have the meanings given in our Terms of Service.
Authorized administration
You may use Superendpoint only for lawful internal business purposes, and only to administer accounts, organizations, networks, software, and endpoints that you own, manage, or are authorized to control. You must give the people who use your managed endpoints any notices, and obtain any permissions, that the law or your own policies require.
Prohibited conduct
You must not use the Service to:
- access, monitor, modify, enroll, command, or install software on an endpoint without authorization;
- carry out surveillance, stalking, harassment, discrimination, retaliation, or interference with lawful labor activity, or anything else that violates the law or individual rights;
- collect or transmit protected health information, payment card data, government-classified or regulated data, export-controlled data, or any other category your agreement with us does not expressly permit;
- distribute malware, ransomware, spyware, credential-theft tools, destructive code, or software designed to evade endpoint security controls;
- bypass authorization, tenant boundaries, re-authentication, confirmation, staged rollout, health, rate-limit, audit, code-signing, or emergency-stop controls;
- extract, share, sell, or misuse credentials, private keys, device certificates, signed grants, enrollment files, or administrative tokens;
- probe, scan, test, reverse engineer, overload, or interfere with the Service, unless we have authorized security testing in writing;
- use false identity information, impersonate another person or organization, or conceal who is responsible for an administrative action;
- violate intellectual property, privacy, communications, employment, consumer protection, sanctions, or export control laws;
- resell, sublicense, or provide the Service as a managed service, unless your Order Form expressly permits it.
Security responsibilities
You must:
- limit administrator access to trained personnel with a business need, and use two-factor authentication;
- protect enrollment files, API keys, and credentials, remove access promptly when someone’s duties change, and investigate unexpected devices or actions;
- use approval and staged rollout controls for high-impact changes, and stop a rollout when health or failure controls indicate a problem;
- report suspected compromise, unauthorized use, or abuse of the Service promptly to security@superendpoint.com.
Enforcement
We may investigate suspected violations. We may limit or suspend the affected account, instruction, device, rollout, or integration when reasonably necessary to contain harm, protect the Service or other customers, or comply with law. When circumstances permit, we will notify you first and give you a reasonable opportunity to correct the violation. Serious or repeated violations may lead to termination under our Terms of Service.
Any restriction will preserve the access you need to export your data, uninstall the endpoint software safely, revoke credentials and certificates, settle billing, and contain an active security incident.
If you believe we have restricted your account in error, email legal@superendpoint.com. We will review your request promptly and tell you what we decide.
Reporting abuse
To report misuse of Superendpoint, including a device you believe is being managed without authorization, email security@superendpoint.com.
Changes
We may update this policy. If a change is material, we will notify customer account owners before it takes effect.