SummaGuard — Acceptable Use Policy & Security Exhibit

Version 1.0 — Effective 2026-09-09 — incorporated into the SummaGuard Subscription Terms v1.0

SummaGuard is a product of SummaCore LLC.

This file contains two documents: (A) the Acceptable Use Policy and (B) the Security Exhibit. Each is incorporated by reference into the SummaGuard Subscription Terms. Capitalized terms not defined here have the meanings given in the SummaGuard Subscription Terms ("Agreement", "Service", "Customer", "Customer Data", "AI Outputs", "Order", "Subscription Term", "Establishment").



(A) Acceptable Use Policy

SummaGuard Acceptable Use Policy ("AUP")

This AUP governs use of the SummaGuard Service by Customer and everyone acting on Customer's behalf — including Customer's users, administrators, contractors, API clients, and AI agents operating under Customer's credentials or tokens. Customer is responsible for all such activity. If a term here conflicts with the SummaGuard Subscription Terms, the Subscription Terms control.

1. Lawful and Intended Use

1.1 Lawful use only. Customer may use the Service only in compliance with applicable law and only for its intended purpose: managing Customer's own environment, health, and safety records and related workflows.

1.2 Rights in uploaded data. Customer may not upload, submit, or transmit any data to the Service that Customer does not have the legal right to collect, process, and store. Customer warrants that Customer Data and Customer's use of the Service comply with applicable law, as further described in the SummaGuard Subscription Terms.

1.3 No unlawful content. Customer may not use the Service to store or transmit content that is unlawful, infringing, defamatory, or malicious (including malware or code intended to disrupt or harm the Service or others).

2. Prohibition on Re-Identifying Anonymous Reporters

This is a named, standalone prohibition because it protects a core function of the Service.

The Service supports anonymous and privacy-protected reporting (including OSHA privacy-case handling under 29 CFR 1904.29(b)(6)–(9) and anonymous near-miss reporting where enabled). Customer and its users may not attempt to identify, unmask, deduce, or re-identify the identity of any individual who has submitted a report anonymously or whose identity is masked by the Service — whether through the Service's features, metadata analysis, timing correlation, access-log inspection, API queries, AI-assisted inference, or any other means. Violations of this Section 2 may result in immediate suspension under Section 5 without prior notice.

3. System Integrity and Abuse

Customer may not:

4. API and Automated (Agent) Access

The Service exposes documented interfaces for programmatic and AI-agent access. The following rules apply, consistent with the API and Automated Access section of the SummaGuard Subscription Terms:

4.1 Issued credentials only. Automated access is permitted only through the documented interfaces, using the Access Credentials issued through the Service.

4.2 Customer responsibility. Customer is responsible for all activity of its users, API clients, and AI agents acting under its Access Credentials, as if Customer performed the activity itself.

4.3 Credentials are Confidential Information. Access Credentials are Confidential Information under the Agreement. Customer must protect them, must not embed them in client-side or public code, and must promptly rotate or revoke any Access Credential it believes is compromised and notify SummaCore.

4.4 Permissions and rate limits. Automated access uses the same role-based permissions as the User whose credentials it uses, and is subject to rate limits SummaCore applies to protect the Service. Customer must not attempt to exceed those permissions or circumvent rate limits.

4.5 Audit attribution. Write actions performed by automated clients are recorded in the Service's audit trail, attributed to the User or credential under which they were performed. Customer must not take steps to obscure or falsify this attribution.

4.6 Throttling and suspension. SummaCore may throttle, restrict, or suspend automated access that is abusive, that degrades the Service, or that violates this AUP, and will restore access when the issue is resolved.

5. Enforcement

SummaCore applies a graduated enforcement ladder, proportionate to the violation:

  1. Notice — SummaCore notifies Customer of the violation and requests correction within a stated period;
  2. Throttle — SummaCore may rate-limit or restrict the offending users, tokens, or features;
  3. Suspend — SummaCore may suspend the offending access or, for serious violations, the affected account;
  4. Terminate — for material violations not cured after notice, SummaCore may terminate as provided in the SummaGuard Subscription Terms.

SummaCore may skip steps and act immediately (including suspension without prior notice) where reasonably necessary to protect the Service, other customers, individual safety or privacy (including under Section 2), or to comply with law. SummaCore will use commercially reasonable efforts to notify Customer promptly of any such action and to limit its scope and duration. Suspension does not relieve Customer of payment obligations for the affected period except as provided in the Subscription Terms.

6. Reporting

Report suspected violations, vulnerabilities, or compromised tokens to [email protected]. Good-faith vulnerability reports made through this channel are not violations of Section 3(a).



(B) Security Exhibit

SummaGuard Security Exhibit

This Security Exhibit describes the technical and organizational measures SummaCore maintains for the SummaGuard Service. It is incorporated into the SummaGuard Subscription Terms and referenced by the Data Processing Addendum. SummaCore may improve these measures over time and will not materially degrade the overall protection described here during a Subscription Term.

1. Hosting and Physical Security

The Service's application and database tiers run on dedicated cloud servers in the United States, with data-center physical security managed by our cloud hosting provider. AI inference runs on separate hardware SummaCore owns and operates in the United States and physically secures.

2. Tenant Isolation — Database-per-Tenant

Each Customer's data is stored in a dedicated, per-Customer database (database-per-tenant isolation), not in shared tables partitioned by tenant ID. This provides hard isolation of Customer Data at the storage layer, tenant-scoped backups, and clean per-tenant export and deletion.

3. Encryption

All data in transit between users (or automated clients) and the Service is encrypted using TLS 1.2 or higher. Sensitive personal information (as catalogued in the product's sensitive-field registry) is encrypted at rest at the column level using AEAD encryption with keys held outside the database engine, except for a small number of fields the registry marks as cleartext by design because the Service must match on them (such as name and email address); database backups inherit this protection and backup media are additionally encrypted (AES-256).

4. Authentication and Access Control

5. Auditability and Record Integrity

6. Backups and Resilience

7. AI Security (eva)

The Service includes an AI assistant ("eva"). Its security posture:

8. Agent and Automated Access Security

Automated access is authenticated with the same credentials and role-based permissions as interactive use. Write actions by automated clients are recorded in the audit trail. SummaCore may throttle or suspend automated access that degrades the Service.

9. Vulnerability and Change Management

Dependencies and platform components are reviewed and updated on a regular cadence, and security patches are prioritized. Changes are tested before production deployment. SummaCore does not currently hold a SOC 2 or ISO 27001 certification and does not claim one.

10. Personnel Access

Access to production systems and Customer Data is limited to authorized SummaCore personnel on a need-to-access basis, over a private network, and administrative access is logged.

11. Incident Response and Breach Notification

SummaCore maintains an incident response process covering detection, containment, remediation, and customer communication. In the event of a security breach affecting Customer Data, SummaCore will notify Customer without unreasonable delay, and in any case consistent with applicable law (including Tex. Bus. & Com. Code §521.053), as further detailed in the Data Processing Addendum.

12. Data Export and Deletion

Customer may self-serve export its data at any time during the Subscription Term, and for 60 days after termination or expiry, using the export tools in the Service at that time, which today are: (a) CSV export of the event register and KPI data; (b) CSV export of the OSHA 300 Log and the OSHA ITA submission files (the 300A summary and case files); (c) a printable Form 300A; and (d) any additional export the Service offers at the time. For data without an export tool (including roster, inspections, CAPA, investigation, and audit-trail records, and attachments other than one-at-a-time download), SummaCore will provide a copy on written request as described in the Subscription Terms. After that window, Customer Data is deleted per the deletion schedule in the SummaGuard Subscription Terms, allowing up to about 40 additional days as backup media rotate (one offsite copy is write-protected for a fixed period and cannot be deleted early). Retention periods and legal holds are configured by SummaCore on Customer's instruction. Customer is responsible for identifying the records it must retain or place under hold, including the five-year retention duty under 29 CFR 1904.33, and for instructing SummaCore accordingly before deletion occurs.


Questions about this Security Exhibit: [email protected].