
Acceptable Use Policy

1. Purpose of the Service
Vigilon is a cybersecurity awareness training platform designed to help organizations run authorized employee training, internal phishing simulations, policy acknowledgment workflows, and audit-ready reporting.
Vigilon is intended to support lawful security awareness, human risk reduction, compliance documentation, and internal training programs. It is not designed or offered as a platform for real-world phishing, fraud, unauthorized credential collection, malware delivery, or offensive cyber activity.
2. Authorized Use Only
Customers may use Vigilon only for legitimate and authorized business purposes, including:
- internal cybersecurity awareness training,
- authorized phishing simulation campaigns for employees or contractors,
- policy acknowledgment and training completion tracking,
- internal reporting for management, auditors, compliance teams, insurers, or regulators.
Customers must have the legal right and organizational authority to include recipients in any campaign or training workflow run through Vigilon.
3. Prohibited Uses
Customers may not use Vigilon to:
- send real phishing emails or conduct unauthorized social engineering;
- deceive, defraud, or manipulate persons outside a legitimate internal training context;
- collect real passwords, MFA codes, payment data, government identification numbers, or other sensitive credentials through simulation content;
- distribute malware, malicious links, spyware, ransomware, or harmful attachments;
- target recipients who are not lawfully included in the customer’s internal training program;
- impersonate third parties for unlawful purposes;
- violate applicable law, employment rules, privacy rules, or contractual obligations;
- test, probe, harass, or target individuals or organizations without proper authorization;
- use purchased, scraped, or unrelated mailing lists;
- use the platform in any way that may facilitate abuse of email infrastructure, domains, or sender reputation.
4. Recipient Eligibility and Customer Responsibility
Customers are responsible for ensuring that:
- recipient lists are accurate, current, and authorized;
- campaigns are limited to their own employees, contractors, or other authorized participants;
- training campaigns are run within a lawful employment, contractor, or organizational context;
- internal stakeholders are informed as required by the customer’s legal, HR, compliance, or security policies;
- all use of the platform complies with applicable laws and regulations.
Customers remain responsible for recipient selection, internal approvals, and lawful operation of their awareness program.
5. Safe Simulation Standards
To reduce risk and prevent misuse, Vigilon requires that customers use the platform for safe training simulations only.
Customers must not configure campaigns to harvest or retain real credentials or secrets. Where landing pages or forms are used in simulations, they must be used only for training feedback, awareness measurement, or other lawful internal training purposes, and not for collecting real passwords or sensitive authentication data.
Customers should avoid simulation designs that could cause operational disruption, financial loss, reputational harm, or confusion outside the intended internal training audience.
6. Compliance and Review
Vigilon may review accounts, campaigns, domains, content patterns, complaint signals, or usage activity to verify compliance with this Acceptable Use Policy, platform rules, and applicable law.
We may request additional information, including:
- business identity details,
- website or domain ownership information,
- intended use case,
- internal authorization model,
- compliance or security documentation.
Failure to provide accurate information may result in restrictions or suspension.
7. Suspension and Enforcement
We may restrict, suspend, or terminate access to Vigilon at any time if we reasonably believe that an account is being used:
- in violation of this Policy,
- in a way that threatens recipients, providers, or third parties,
- in a way that creates abuse, complaints, or sender reputation risk,
- for unlawful phishing, fraud, or harmful activity.
We may also suspend specific campaigns, domains, or sending activity pending review.
8. Cooperation with Service Providers and Authorities
Vigilon may cooperate with email service providers, hosting providers, security partners, and lawful authorities where necessary to investigate abuse, enforce platform rules, protect infrastructure, or comply with legal obligations.
9. Changes to This Policy
We may update this Acceptable Use Policy from time to time. The current version will be published on vigilon.pl. Continued use of the service after an update means acceptance of the revised Policy.
10. Contact
If you have questions about this Acceptable Use Policy or want to verify an intended use case, please contact:
Vigilon.pl
Email: kontakt@vigilon.pl
Website: vigilon.pl

