Aiphish Acceptable Use Policy
Last updated: August 9, 2026
Aiphish (stylized "aiphish") is a security-testing and awareness-training tool. It exists to help organizations understand and defend against social engineering, including voice-based (vishing) and AI-assisted phishing attacks. Because the same capabilities that make Aiphish effective for defensive testing could be misused, your right to use it is conditional on the rules below. Using Aiphish means you agree to this policy.
1. Authorized use only
You may use Aiphish only to conduct security testing and awareness training that you are explicitly authorized to perform. In practice this means one of the following is true for every test you run:
- You are testing an organization you own or operate, or its personnel, systems, and accounts.
- You have prior written authorization from a party with the authority to consent on behalf of the targets and the systems involved (for example, a signed engagement, statement of work, or internal authorization from an appropriate officer).
- The individuals being tested are covered by that authorization — typically as a condition of employment, contract, or an existing security-awareness program.
If you cannot point to a specific authorization that covers a given test, you are not permitted to run it.
2. Eligibility and authority
By using Aiphish, you represent that:
- You are at least 18 years old, or the age of majority in your jurisdiction, whichever is greater.
- If you use Aiphish on behalf of an organization, you have the authority to bind that organization to this policy, and "you" refers to both you and that organization.
3. Consent and voice cloning
Aiphish can facilitate the generation or use of synthetic and cloned voices through third-party integrations. This carries specific obligations:
- You may only clone or synthesize a voice where you have the right to use that voice — either it is your own, a consenting participant's, a properly licensed voice, or a voice your authorization expressly permits.
- You may not use a cloned voice to impersonate a real, identifiable person (an executive, employee, vendor, official, or family member) outside the bounds of an authorized engagement whose scope specifically contemplates that impersonation.
- Voice cloning of a person without a lawful basis, or to deceive them or others for gain, is prohibited regardless of any other permission you believe you have.
- You understand and agree that using Aiphish to connect to third-party integrations does not absolve you of obligations you may have to the third party under their acceptable use policy, End-User License Agreement (EULA), or similar.
4. Prohibited uses
You must not use Aiphish, in whole or in part, to:
- Target any person, organization, system, or account you are not authorized to test.
- Commit or attempt fraud, theft, extortion, or any scheme to obtain money, credentials, data, or access under false pretenses for real (non-simulated) gain.
- Impersonate government agencies, law enforcement, financial institutions, or emergency services.
- Harass, intimidate, stalk, defame, or cause emotional distress to any person.
- Conduct real (non-consensual) phishing, vishing, or social-engineering campaigns of any kind.
- Interfere with elections, spread disinformation, or manipulate markets.
- Circumvent, disable, or strip out Aiphish's consent, authorization, logging, or safety controls, or redistribute a modified version for that purpose.
- Violate any applicable law, regulation, or third-party right.
This list is illustrative, not exhaustive. If a use would deceive a person who has not consented to being tested, assume it is prohibited.
5. Legal compliance is your responsibility
You are solely responsible for ensuring your use of Aiphish is lawful in every jurisdiction where you operate and where your targets are located. Depending on your activity and location, this may include laws governing:
- Automated calling and messaging (e.g., the U.S. TCPA and FTC/FCC robocall rules, and their equivalents elsewhere).
- Wire fraud, computer misuse, and unauthorized access.
- Call and communication recording, including one-party vs. all-party consent requirements.
- Data protection and privacy (e.g., GDPR, CCPA), including the processing of voice and personal data of test participants.
- Impersonation, identity, and likeness rights.
Aiphish does not provide legal advice. Consult qualified counsel before running any program that touches real people.
6. Your organizational obligations
Aiphish gives you the capability to run tests, but it does not and cannot verify that you have the necessary policies and consents in place. You are responsible for ensuring, before running any test, that your organization has:
- Appropriate employee acceptable-use, monitoring, and security-awareness policies that permit the testing you conduct.
- Any recording and monitoring consents required in the jurisdictions where your targets are located — for example, all-party (two-party) consent for call recording in jurisdictions such as California that require it.
- Any employee-notification, works-council, or similar requirements applicable in your jurisdiction (for example, within the EU/EEA).
The presence or absence of these controls is your responsibility, not ours, and we have no visibility into them.
7. Export controls and sanctions
You are responsible for complying with all applicable export-control and economic-sanctions laws. You represent that you are not located in, ordinarily resident in, or acting on behalf of any jurisdiction or party subject to comprehensive sanctions, and that you will not export, re-export, or use Aiphish in violation of any applicable export-control or sanctions regime.
8. Records and audit logs
Aiphish produces audit logs and campaign records. You are responsible for retaining these as records of your organization and for being able to demonstrate, on request, that a given test was authorized. Do not delete or falsify logs to obscure the scope or authorization of a test.
9. Enforcement
We may suspend or terminate your access to any hosted or supported components of Aiphish if we reasonably believe you have violated this policy, and we may report activity to the appropriate authorities where required by law. For self-hosted components, your right to use Aiphish is granted by, and subject to the terms of, its software license; use in violation of this policy also constitutes a violation of the use grant under that license.
10. Reporting
To report abuse, a suspected violation of this policy, or a security concern, contact abuse@aiphish.ca. For general inquiries, see https://aiphish.ing/contact.
11. No warranty; your liability
Aiphish is provided "as is," without warranty of any kind. You assume all responsibility for how you use it and for any consequences of that use. You agree to indemnify and hold harmless the project, its maintainers, and its contributors from any claims arising out of your use of Aiphish in violation of this policy or applicable law.
12. Changes
We may update this policy from time to time. Material changes will be reflected in the "last updated" date above, and continued use after a change constitutes acceptance.