Anti-Abuse & Vendor Contract Policy
Effective immediately ยท Applies to Deep Audit, Follower Extraction, and Audience Audit tools
1. Why this policy exists
The Deep Audit engine can surface real follower lists for a target handle. Used against a handle you do not own or have not been contracted to audit, that capability becomes a harassment vector โ a way for bad actors to slander, dox, or pile-on third parties under the guise of "research." This policy exists to make that misuse structurally impossible inside our platform.
2. Two locks before any extraction runs
- Handle ownership. You must verify each handle you audit via OAuth, a DNS-TXT record on your verified domain, or a temporary bio code challenge. Verification is recorded in
handle_ownership_claimsand is required for every (platform, handle) pair you submit. - Vendor contract (this policy). If the handle belongs to a vendor, influencer, agency, partner, or any third party, you must upload the existing signed agreement with that vendor authorizing you to commission the audit before our engine will run a single page of extraction.
3. How vendor contract uploads work
Clients upload existing vendor contracts inside the portal at Resources & Invoices โ Vendor contract uploads. Each upload captures:
- Vendor / counterparty legal name
- Specific handles authorized for audit under that contract
- Contract type (Vendor Audit Authorization, MSA, DPA, NDA, other)
- Effective and expiration dates
- The signed PDF/DOCX/image file itself (โค15 MB)
Uploads land in a private storage bucket (vendor-contracts) scoped to your user folder. Only you and GreenStacks LLC admin reviewers can read the file via short-lived signed URLs.
4. Admin review gate
Every uploaded contract enters status pending_review. A GreenStacks LLC admin verifies that the contract is genuine, the signing parties match the vendor, the scope covers the listed handles, and the agreement is in effect. Until status is flipped to approved, the audit engine refuses extraction for any of the listed handles. Rejected or expired contracts also block extraction.
5. Output safeguards
- Extracted rows are PII-minimized (handle + authenticity score only).
- Every row is cryptographically watermarked to the requesting account for leak attribution.
- CSV exports are delivered via 7-day signed links with a 3-download cap.
- A 30-day cool-down per target handle is enforced at the database layer.
6. Prohibited use
You may not use Deep Audit, Follower Extraction, or any output thereof to harass, defame, dox, retaliate against, or target a person or organization. Uploading forged, altered, or unauthorized contracts is grounds for immediate account termination, refund forfeiture, and referral to law enforcement. GreenStacks LLC reserves the right to revoke approval for any contract at any time.
7. Questions
Email owner@greenstacksllc.com.