Last Updated: April 25, 2026
This Acceptable Use Policy governs your use of the oakallow API and related services. oakallow exists to make AI agent execution safer through permissions, approvals, and audit trails. We expect all users to use the Service responsibly and in a manner consistent with its security-first purpose.
oakallow is designed to ensure AI agents ask before they act. When the permission system returns requires_approval, your system must route that request to a human decision-maker. Automatically approving these requests defeats the purpose of the permission system and violates this policy.
Tools with disabled permission must not be executed under any circumstances. If a tool is disabled, do not attempt to bypass the restriction.
oakallow is not designed to store personally identifiable information (PII). The rules below apply to fields you submit through the runtime API: tool-call arguments, approval reasons, and any free-text context attached to a permission check or approval request. They do not apply to your own account profile (your name and email are required to operate the service).
Do not submit the following inside tool-call arguments or approval reasoning:
oakallow performs automated PII redaction as a safety net. Any detected PII patterns are removed before processing and storage. The redaction is best-effort. You bear responsibility for ensuring PII is not transmitted through the API. Use the reference_id field to correlate approval requests back to records in your own system rather than including identifying information in request fields.
You can configure oakallow to send approval-event notifications to third-party services you choose. The destinations you configure are services you, not oakallow, are responsible for. By configuring a channel you confirm that:
Notification payloads are intentionally minimal — event type, tool name, PII-scrubbed reason, and the oakallow reference id. Tool parameters and customer data are never sent. Approval decisions remain governed by oakallow's mobile app with enforced multi-factor authentication; no third-party destination has authority to decide an approval. Configuring a channel that purports to make decisions, automating "approval" from a chat surface, or otherwise bypassing the mobile-app decision flow violates this policy.
We will always attempt to contact you before taking action, except in cases involving immediate security risk or legal obligation.
If you become aware of any violation of this policy or a security incident, please report it immediately to security@oakallow.io. We take all reports seriously and will investigate promptly.
Policy Questions
legal@oakallow.ioSecurity Reports
security@oakallow.io