01
Document and respect your authority
Use Phantom Helix only for a lawful purpose and within authority you can explain and document. Your authority may come from ownership, a client engagement, your job duties, or consent. It may also come from a public-interest mandate or another valid legal basis. Information being public does not give permission for every type of collection, profiling, disclosure, contact, or action.
Phantom Agent users must be at least 18. They must act for a business, organization, public-interest body, or independent professional practice. You must follow relevant laws, contracts, platform terms, source licenses, rate limits, and professional duties.
02
Do not harm, deceive, or intrude
You must not use a Phantom Helix service to:
- stalk, harass, threaten, intimidate, dox, discriminate against, or unlawfully profile a person.
- steal credentials, evade security, access systems without permission, deliver malicious payloads, commit fraud, or hide unlawful activity.
- impersonate another person, fabricate evidence, present an unverified allegation as fact when you know it is unverified, or manipulate a source or subject.
- bypass access, billing, rate-limit, provider, safety, or authorization controls.
- collect, retain, disclose, or sell personal information in violation of law, contract, source terms, or another person's rights.
03
Use additional care for sensitive work
Consequential decisions
Do not use Phantom Helix output as the sole basis for a decision that affects a person. This includes decisions about employment, credit, insurance, housing, immigration, medical care, or law enforcement. A qualified person must review the identity match and sources. They must also review uncertainty, relevance, and the rules that apply.
Minors and vulnerable people
Investigations concerning a minor are prohibited by default. They are allowed only for a documented protection purpose or with clear legal authorization. Limit collection and disclosure to what that purpose requires.
Sensitive and regulated information
Some information may have extra legal protection. This includes health, biometric, political, religious, sexual, criminal, financial, and precise-location information. Submit or disclose it only when your professional purpose and legal authority justify doing so.
04
Keep active security work inside scope
Active techniques require documented authorization.
Active techniques include scanning, exploitation, payload execution, credential testing, and radio or network interaction. Your authorization must identify the systems, methods, time window, and limits. Stop when the scope or ownership is uncertain.
A selectable capability is not automatically authorized. You remain responsible for each request, including its method, target, provider terms, rate limits, and impact.
05
Respect service integrity
Do not automate access to authenticated or non-public parts of the service. Do not extract outputs in bulk outside documented exports or APIs. Written authorization is required before you probe non-public interfaces or conduct stress or security testing. Do not use multiple accounts, credentials, or access paths to avoid a service limit.
Ordinary manual product evaluation and lawful procurement comparison are allowed. Authorized professional use of outputs and approved integrations are also allowed. The Terms of Service contain all software, automation, and testing restrictions. They also preserve rights that applicable law does not allow us to exclude.
06
Treat outputs as leads, not verdicts
AI-assisted outputs, tool results, summaries, scores, and graph links may be incomplete, outdated, unclear, or wrong. Check important findings against the original sources and independent evidence. Do this before you rely on a finding or share it with another person.
Check identity matches carefully. Shared names, reused identifiers, network infrastructure, inferred relationships, and model-generated explanations are not enough on their own. Do not use them alone to attribute conduct to a person or organization.
Demos and professional advice
Product examples and walkthroughs are synthetic or fictional unless we clearly state otherwise. Phantom Helix does not provide legal, compliance, financial, medical, or investigative advice.
07
Minimize and protect investigation data
Submit only information needed for the authorized purpose. Limit access, sharing, downloads, and public links. Use secure accounts and devices. Delete material when it is no longer needed. A noindex instruction or bearer link does not guarantee confidentiality.
Cloud-backed capabilities may send request fields to external services in other countries. Review the Service Providers and Research Sources and do not use a source when its terms, destination, or data handling conflict with your obligations.
08
Questions, reports, and enforcement
Phantom Helix may restrict, suspend, or terminate access, request proof of scope, preserve required records, or report conduct. We may do this when reasonably needed to address a violation, security risk, or legal duty. Enforcement decisions consider context and evidence, not a list of target-specific keywords.
For permitted-use questions, abuse reports, or safety concerns, contact support@phantomhelix.com. The full contractual terms are in the Terms of Service.