Acceptable Use Policy
Last updated: [DATE] · Applies to everyone with a SOPR account
Drafted to reflect exactly how the application works, not a substitute for legal review. Written as an internal policy for accounts created by an administrator — there is no public sign-up.
1. What SOPR is for
SOPR is an internal system for documenting IT infrastructure and operational procedures — server details, credentials, network configuration, and related runbooks — for the sites and clients your organization manages. Access is granted per person, scoped to the sites they're responsible for.
2. Your account is yours alone
- Do not share your username, password, or two-factor authentication device with anyone else, including colleagues who also have SOPR access. If someone else needs access, they need their own account — ask an administrator.
- You are responsible for keeping your credentials confidential and for activity that occurs under your account.
- If you believe your account has been compromised, change your password immediately and notify an administrator.
3. Activity is logged — this is a feature, not a warning to hide from
Every login, every record created, edited, or deleted, and every time a stored credential is revealed is logged with who, when, and from where. This protects everyone with access to the system, including you — it's how misuse gets caught and legitimate access gets distinguished from a genuine incident. This is disclosed here and on the sign-in screen itself.
4. What you can and can't do with what's stored here
- Only access sites and information you've been granted access to. Attempting to access data outside your assigned scope — including by guessing URLs or IDs — is a violation of this policy even if it happens to succeed due to a bug, and should be reported, not explored further.
- Credentials and sensitive data stored in SOPR exist to be used for their intended operational purpose, not copied out, screenshotted, or shared outside that purpose.
- Do not print sensitive records unless there's a genuine operational need, and treat any printed copy with the same care as the digital original — a paper copy isn't covered by the system's access controls or audit trail once it exists.
- Do not use SOPR to store anything unrelated to its operational purpose.
5. Security is a shared responsibility
- Use a unique password for SOPR — not one reused from another service.
- Enable two-factor authentication if it's available for your account.
- Report anything that looks like a security issue to an administrator promptly rather than testing it further yourself.
6. Access can be changed or revoked
Administrators may modify, restrict, or revoke your access at any time, including immediately upon end of employment or engagement, change of role, or a suspected security concern. This isn't punitive by default — it's routine access-lifecycle management.
7. No warranty
SOPR is provided as an internal operational tool on an "as-is" basis. While reasonable security and reliability measures are in place, [SHIRYON SECURITY — LEGAL ENTITY NAME] does not warrant that the system will be uninterrupted or error-free, and is not liable for losses arising from its use, to the extent permitted by applicable law.
8. Questions
[CONTACT EMAIL]