Acceptable Use
Acceptable Use Policy
Latch Vector builds identity infrastructure for serious, regulated software — healthcare, finance, and businesses like them. This page sets out who the platform is for, who it is not for, and what happens when an account is used outside that line.
Last updated 4 August 2026.
Who this is for
Latch Vector is built for legitimate, regulated, or professional software businesses — the kind of company that needs provable tenant isolation, an audit trail, and identity infrastructure it can put in front of an auditor. That is the customer we design for, and the only customer we want.
Prohibited uses
You may not use Latch Vector, or allow it to be used, to operate, support, or provide identity or access to any of the following:
Adult or 18+ content
Adult entertainment, escort or companionship services, and similar businesses.
Gambling & betting
Online casinos, sports betting, lotteries, and games of chance for money, unless independently and fully licensed — and even then, at our discretion.
Illegal activity
Any use that is unlawful in the jurisdiction it operates in — money laundering, fraud, scams, identity theft, malware, or software whose primary purpose is to break the law.
Weapons & controlled substances
Unlicensed sale or distribution of firearms, ammunition, explosives, drugs, or other controlled substances.
This list describes the categories, not the limit of our judgment — we can refuse or suspend service for any use that is illegal, that meaningfully endangers people, or that is plainly inconsistent with building serious, regulated software.
Scope: this applies down the whole chain
If you resell, white-label, or otherwise make Latch Vector available to your own customers or sub-organizations, this policy binds every one of them too. You are responsible for the organizations you provision, and for enforcing this policy against anyone you give access to. An end-customer we would refuse directly does not become acceptable because they sit three levels down someone else's organization tree.
Other things we don't allow
- Attempting to bypass, disable, or probe the isolation, rate-limiting, or authentication controls of the platform, other than through the sandbox tenants provided for exactly that.
- Reselling raw access to the platform's infrastructure itself (as opposed to your own product built on it) without a separate agreement with us.
- Using the platform to send spam, or to harass, defraud, or impersonate any person or organization.
- Submitting data you do not have the right to hold — including using demo or sandbox tenants for real patient, financial, or otherwise regulated production data.
How this is enforced
Most conversations start before enforcement does — if something looks like it might cross this line, we will usually ask first. Where a violation is clear, ongoing, or dangerous, we may suspend or terminate the account without advance notice, and we will tell you why once it is safe to do so. Suspending one organization in a white-labeled tree does not require suspending the rest of it, unless the violation is at the root.
Reporting a violation
If you believe an account, including one belonging to someone else's white-labeled customer, is being used in a way this policy prohibits, email [email protected] with "Acceptable Use" in the subject. We review every report.
Changes to this policy
We update this page as our judgment about what belongs on the platform evolves, and the date at the top reflects the last change. Continued use of the platform after an update means you accept the current version.