Draft — pending legal review
This document has not yet been reviewed by a qualified Australian lawyer. Do not rely on it as legal advice. It will be finalised before go-live.
Acceptable Use Policy
The rules governing how the Aussie Cyber platform may and may not be used.
Effective date: 1 April 2026 · Last updated: 1 April 2026
01.Purpose
This Acceptable Use Policy ("AUP") sets out the rules for using the Aussie Cyber platform. It applies to all customers, administrators, and users. By using the platform, you agree to comply with this policy. This AUP forms part of our Terms of Service.
02.Permitted use
The platform is provided for the following legitimate business purposes:
- Security awareness training for employees within your organisation.
- Simulated phishing campaigns targeting only users within your organisation who are enrolled on the platform.
- Monitoring endpoint and identity security posture for devices and identities within your organisation.
- Downloading and customising policy templates for internal use.
- Pursuing SMB1001 certification for your organisation.
03.Prohibited activities
You must not use the platform to:
- Conduct unauthorised phishing attacks — simulated phishing may only target users within your own enrolled organisation. Using the platform to attack third parties, other businesses, or individuals outside your organisation is strictly prohibited and may constitute a criminal offence under Australian law.
- Attempt to access other tenants' data — any attempt to query, access, exfiltrate, or interfere with data belonging to another customer of the platform is prohibited.
- Reverse engineer the platform — you must not decompile, disassemble, or attempt to derive source code or algorithms from the platform.
- Abuse the phishing simulation infrastructure — the phishing domain pool and email sending infrastructure may not be used to send unsolicited commercial email, spam, or any communication not authorised by the platform's intended purpose.
- Circumvent security controls — you must not attempt to bypass, disable, or undermine authentication, authorisation, audit logging, or any other security control on the platform.
- Impersonate Aussie Cyber — you must not use the platform's branding, templates, or infrastructure to misrepresent yourself as Aussie Cyber.
- Use the platform for unlawful purposes — including in violation of the Criminal Code Act 1995 (Cth), the Cybercrime Act 2001 (Cth), the Privacy Act 1988 (Cth), or any other applicable Australian law.
- Introduce malicious code — you must not upload, transmit, or introduce any virus, malware, ransomware, or other harmful code through the platform.
- Conduct denial-of-service attacks — including against the platform itself or any third party via the platform's infrastructure.
- Resell or sublicense without authorisation — you may not resell access to the platform to third parties unless you have a formal reseller agreement with Aussie Cyber.
04.Phishing simulation rules
If your plan includes phishing simulations, the following additional rules apply:
- Campaigns may only target users who are enrolled as members of your organisation within the platform.
- You must not manually configure simulations to target individuals in a way that constitutes harassment or bullying.
- Simulation results must be used for security awareness and remediation purposes only. They must not be used as the sole basis for disciplinary action without independent legal advice.
- You acknowledge that Aussie Cyber randomises templates and send times — you must not attempt to reverse-engineer or pre-announce simulations to users, as this defeats the purpose of the programme.
- The gotcha (landing) page shown to users who fail a simulation must remain educational in tone. Customers with white-label branding must not alter the page to be punitive or humiliating.
05.Administrator responsibilities
Platform administrators are responsible for:
- Ensuring all users within their organisation are made aware that security awareness training and phishing simulations are part of the organisation's security programme.
- Configuring the platform in accordance with this AUP and their organisation's own acceptable use policies.
- Promptly revoking access for users who leave the organisation.
- Reporting any suspected security incident or misuse to Aussie Cyber at enquiries@djc.com.au.
06.Reseller obligations
Organisations with a reseller agreement must ensure that each of their client organisations is bound by terms equivalent to this AUP. Resellers are responsible for the conduct of their clients on the platform. Aussie Cyber reserves the right to terminate reseller access if client conduct violates this AUP.
07.Reporting violations
If you become aware of any use of the platform that violates this policy — including by another user within your own organisation — please report it to enquiries@djc.com.au. We take all reports seriously and will investigate promptly.
08.Consequences of violation
Violation of this AUP may result in immediate suspension or termination of your account without refund. Aussie Cyber reserves the right to report suspected unlawful activity to the Australian Federal Police or other relevant authorities.
You agree to indemnify Aussie Cyber against any claims, losses, or damages arising from your violation of this policy.
09.Changes to this policy
Aussie Cyber may update this AUP from time to time. We will provide reasonable notice of material changes. Continued use of the platform after changes take effect constitutes acceptance.
© 2026 Aussie Cyber · Australian owned and operated