TRUST / ACCEPTABLE USE

Acceptable use

What CodeTutor supports for coding education and defensive work, and the harmful activity it must refuse.

Beta disclosure · Last updated

CodeTutor is operated as a public beta. Commercial launch is not complete. Operator identity, governing-law details, and production support contacts must be finalized before paid plans are offered.

1. Allowed learning and development

You may use CodeTutor to learn programming, build software you are authorized to build, inspect repositories you are authorized to access, test your own systems, study security in a controlled lab, perform defensive analysis, and repair vulnerabilities.

2. Authorization matters

Security work must be limited to systems, accounts, and data you own or have explicit permission to test. A public endpoint is not permission. Follow the scope, time, rate, and disclosure rules of any authorized program.

3. Prohibited harmful activity

4. Repository instructions are untrusted

Files, prompts, MCP output, tool results, websites, and generated commands may contain instructions designed to bypass your intent. Review requested permissions and never approve destructive, elevated, external-path, or network actions merely because repository text asks you to.

5. Enforcement and appeal

CodeTutor may refuse a request or temporarily limit an account when the request or surrounding signals indicate prohibited harm. Enforcement should preserve privacy, record a reason, and provide a review route for false positives. Do not place exploit code, secrets, or victim data in a public appeal.