Legal
Acceptable use
What is and is not permitted when using this website, and what Kerah may do in response. These rules form part of the website terms.
If you believe you have found a security vulnerability, Kerah would rather hear from you than not. Reporting one privately and in good faith is not a breach of these rules — but reporting does not authorise testing, active testing needs Kerah's prior written authorisation, and publishing a finding needs a separate written agreement.
Effective from 2026-08-23.
- 01
What this policy covers
This policy governs use of the website at kerah.ae, the enquiry form on it, and the contact addresses published on it. Where you use the site or send us something through the form, you are asked to accept it, and it forms part of the Website Terms of Use — breaching it then breaches those terms.
You may reach one of our addresses without ever having seen this page — from an email, a business card, or someone who passed it on. In that case treat this policy as notice rather than as a contract: it tells you what Kerah does and does not authorise, what conduct is out of bounds, and what Kerah may do in response. Kerah does not claim that every unwanted message is a breach of contract. It does not need to — the law provides its own remedies, and those apply whether or not there is an agreement between us.
It does not cover a system Kerah has built for a client. Use of that system is governed by the agreement between Kerah and that client, and by that client's own policies. A client's production system is never in scope of anything published here.
- 02
The general rule
Use this website for the purpose it is published for: to read about Kerah, to assess Kerah as a supplier, and to make contact.
Do not use it to reach anything it does not offer you. Do not use it to send anything unlawful. Do not use it in a way that degrades it for anyone else. Everything below follows from those three sentences.
- 03
What is not permitted
You must not do any of the following, or attempt to.
- Access, or try to access, any part of this website, any system behind it, any account or any data that has not been made available to you.
- Introduce, transmit or attempt to install malware, a virus, a worm, ransomware, a keylogger, a logic bomb or any other harmful code.
- Collect content from this site automatically — scraping, crawling, harvesting or bulk downloading — for any purpose other than the ones named in the next sentence. Search-engine indexing that respects the published robots directives is permitted, as is assistive technology acting for a reader, ordinary browser caching, and reading, printing or saving pages by hand while evaluating Kerah as a supplier — which is not a licence to crawl the site. Building a derived product, republishing the content, or training a machine-learning model on it is not.
- Where this and the Terms of Use appear to say different things about automated copying, this policy is the more specific statement and governs. Changing the robots directives later does not make collection that was permitted at the time retrospectively prohibited.
- Attack credentials by any means, including brute force, credential stuffing and password spraying, or use credentials you did not obtain legitimately.
- Probe, scan or test the vulnerability of this website or the infrastructure behind it, or try to discover, map or defeat its security controls, rate limits or access controls. Reporting a weakness does not authorise testing for one — the clause below says exactly what is and is not permitted.
- Impersonate Kerah, a Kerah role holder, a client, a partner or any other person, or misrepresent your affiliation with any of them — including by sending email that appears to come from a kerah.ae address.
- Use the enquiry form or a published contact address to send bulk, automated, repeated or unsolicited commercial messages, or to send anything fraudulent, deceptive or misleading.
- Submit another person's personal information, or any sensitive, confidential, commercially restricted, tender-restricted, export-controlled or classified material, or any credential, key or access token. This is a public enquiry route, and that prohibition is absolute — with one narrow exception, set out in the clause on reporting misuse below, for the minimum information needed to report an abuse of a Kerah address — having your employer's permission does not make a public channel the right place, does not stand in for the consent of the people the information is about, and is not a security release or an export authorisation. Send ordinary business contact details and a description of your problem; nothing more.
- Copy, republish or reuse this site's text, design, diagrams or code beyond what the Terms of Use permit. Doing so breaches this policy; whether it also infringes copyright is a separate question with its own answer, since not everything on a page is protected and the law allows some uses regardless of what a policy says.
- Send material that infringes someone else's intellectual property rights.
- Send or transmit unlawful, defamatory, harassing, threatening, hateful, extremist or violent content, or content that incites any of those.
- Send, transmit, link to or describe in graphic terms any child sexual abuse or exploitation material — including material that is generated, simulated or presented as fiction — or anything facilitating the grooming, enticement, sextortion, trafficking or exploitation of a child. If you encounter such material anywhere, do not download it, retain it, screenshot it, forward it or attach it to a message. Where it involves a Kerah address or something Kerah controls, send us only the Kerah address or message reference, the time, and a plain non-graphic description — nothing else, and never the material itself. Where it does not involve Kerah, report it to the competent authorities and not to us: this is a business mailbox, and it is not a reporting channel for material Kerah has no control over.
- Use this website or its content for a commercial purpose Kerah has not authorised, including reselling it, framing it inside another service, or presenting it as your own.
- Circumvent a rate limit, a filter or any other technical control applied to this website, or interfere with its operation by any means, including by overloading it.
- Do anything else through this website that is unlawful under the law of the United Arab Emirates, or under any other law that applies to your own conduct. Kerah remains responsible for its own compliance with the laws that bind Kerah; that is not an obligation this policy moves onto you.
- 04
Security testing and vulnerability reporting
Kerah wants to hear about a security weakness in this website, and security@kerah.ae is the route for telling us.
REPORTING A VULNERABILITY DOES NOT AUTHORISE YOU TO TEST FOR ONE. Unless Kerah has given you prior written authorisation naming the asset, the permitted methods and the period, you may report only a weakness you noticed through ordinary, intended use of this website. Anything beyond that is unauthorised, and this policy does not make it otherwise.
Infrastructure operated by our hosting and delivery providers is never in scope: it is not ours to open up. Neither is any system Kerah built for a client — a client's production system is that client's incident, and testing it is a matter between you and them.
If you do report something, do not access, alter, exfiltrate or retain anyone else's data, do not degrade or interrupt the service, and do not use social engineering against any person.
Kerah will not treat a good-faith report made within those limits as a breach of this policy, and will not bring a contractual or civil claim against you for it. That is a commitment about what KERAH will do, and it is the only thing Kerah is able to promise. It is not immunity: Kerah cannot bind the police, a prosecutor, a regulator, a client, or the providers who run the infrastructure this site sits on, and nothing here affects the criminal law.
Please tell us privately first. Publishing a finding is a separate step that needs a separate agreement with us about timing and content — time passing on its own does not make disclosure permissible. Whatever is agreed, personal data, credentials, intercepted messages, client information and working exploit code must never be published.
None of this restricts you from reporting to the police, to a regulator, or to your own legal adviser. Nothing in this policy is intended to stop you doing that, and nothing in it should be read as trying to.
Kerah does not operate a bug-bounty programme, and does not offer or owe a reward for a report unless Kerah agrees one separately in writing. That is said plainly because silence invites the question, and then invites the invoice.
- 05
What Kerah may do
Where Kerah reasonably believes this policy has been breached, or where it needs to protect this website, its contact routes or another person, it may do any of the following. It will act in good faith and do no more than the situation needs, and it will normally tell you first — acting without notice only where the matter is urgent or where the law requires it, and telling you afterwards where that is safe and practical. None of this limits any other right or remedy Kerah has.
- Block or suspend access from an address, a network or a client application. A block is normally temporary, and Kerah will avoid blocking a shared network where doing so would cut off people who have done nothing wrong. If you think you have been blocked in error, write to us and we will look at it.
- Refuse a submission, discard it, or decline to act on it — where it is spam, carries malware, or is an abusive ordinary enquiry. This does not apply to a message that has legal effect: a privacy-rights request, a formal notice, an intellectual-property complaint, a communication from a regulator or the police, a security report, or a notice sent under a route in a signed client agreement. Kerah will not discard one of those. What it undertakes is to identify it and route it to the right address — not that any mailbox is monitored for formal service, and not that a message claiming to be one of these is treated as genuine before its sender and authority have been checked.
- Apply, tighten or extend a rate limit.
- Preserve logs and records relevant to the conduct, for as long as is necessary to investigate it, to defend a claim, or to meet a legal obligation.
- Report the conduct to a law enforcement agency or a regulator, or to another person directly affected by it, and cooperate with a lawful investigation or a lawful request for information. Any such disclosure is limited to what is lawful, necessary and proportionate, and to the information actually relevant to the matter. How this sits with the privacy notice is set out in that notice, under the clause on abuse and security reports.
- Take legal action to stop the conduct, or to recover loss caused by it that Kerah can prove and that the law allows it to recover. This is not a penalty and it is not an agreed sum: it is whatever a court would award, and nothing more.
- 06
No obligation to monitor
Kerah does not undertake to monitor use of this website, and nothing in this policy creates a contractual obligation to do so. Not acting on a breach on one occasion does not waive the right to act on it on another.
That is a statement about what Kerah promises, not a limit on what the law requires. It does not affect any duty to remove or block material, to preserve evidence, to act on actual knowledge of something unlawful, to handle a child-safety matter, to keep personal information secure, to report, or to cooperate — whether that duty comes from the law, from a lawful order, or from an agreement Kerah has signed.
- 07
Reporting misuse
If you see this website being misused, or you receive a message that claims to come from Kerah and does not, tell Kerah at security@kerah.ae. Where you have them, include the full message headers — they are usually the only part that shows where a message actually came from. This is the narrow exception to the rule above about other people's information: send the minimum needed to identify the abuse, only where the headers are lawfully yours to send, and remove anything unrelated to the report where you reasonably can. Headers carry other people's addresses and routing details, so send them for this purpose and no other.
- 08
Changes to this policy
This is version 1.0 of the acceptable use policy, effective 2026-08-23. It carries its own version number rather than borrowing the one on the Terms of Use, because a reader — a security researcher especially — needs to be able to establish which text of THIS policy applied when they acted.
Kerah may change it. The version in force is the one published on this website; a change applies from the date it is published and does not reach back over conduct that has already happened. Where a change materially affects someone we hold an address for, we tell them directly rather than relying on publication alone.