Permitted use
- Authorized organization work and medical-device product operations
- Product, regulatory, and quality material within the contracted catalog
- Minimum necessary staff and business-contact personal data
- Draft or candidate generation subject to responsible human review
Prohibited use
- Using output for patient care, diagnosis, or treatment decisions
- Uploading patient or study-subject identifiers, health information, or source data without written authorization
- Uploading data or intellectual property without authority
- Attempting cross-tenant access
- Malware, automated attacks, or rate-limit bypass
- Presenting AI candidates as expert or regulatory approval
- Account sharing, MFA bypass, or log manipulation
Response
Access may be limited to contain an immediate security risk. Where possible, the customer receives notice and an opportunity to explain or correct. Events and decisions are logged.