HLD Group
Acceptable use policy
Rules for using our websites, demos, and any systems we make available to you in a pre-contract or public context.
Last updated: 24 July 2026
Version 2.0 · Review cycle: 365 days · View all frameworks
1. Purpose
This Acceptable Use Policy defines how HLD Group information systems, networks, devices, and data may and may not be used. Its purpose is to protect HLD Group, its personnel, and its customers from harm arising from misuse, whether deliberate or inadvertent, and to set clear expectations so that everyone understands their responsibilities.
2. Scope
This policy applies to all personnel, contractors, and third parties who use HLD Group systems, networks, devices, accounts, or data, and to all use of company resources whether on or off company premises. It also sets expectations for members of the public who use our public websites and trial environments.
3. General responsibilities
- Use company resources lawfully, ethically, and for legitimate purposes
- Protect credentials and access, and never share them
- Handle information according to its classification
- Comply with all applicable company policies and the law
- Report suspected security incidents and misuse promptly
4. Permitted use
Company systems and networks may be used for authorised business purposes, professional development directly related to role, and limited personal use that does not interfere with work, breach policy, or consume material resources.
- Accessing systems with assigned credentials only
- Storing customer data only in approved locations
- Installing software only from approved sources or through IT
- Following classification and handling rules when sharing information
5. Prohibited use
The following activities are strictly prohibited on HLD Group systems and networks:
- Unauthorised access, port scanning, or penetration testing without written approval
- Introducing malware, ransomware, cryptominers, or denial-of-service tools
- Circumventing security controls, MFA, logging, or monitoring
- Harassment, discrimination, hate speech, or threatening communications
- Accessing, storing, or distributing illegal content or pirated software
- Handling export-controlled data without authorisation
- Sharing credentials or using another person’s account
- Excessive personal streaming, gaming, or cryptocurrency mining
- Operating Tor exit nodes or anonymisers on corporate networks
- Using company resources for personal commercial ventures without approval
6. Internet and email
Internet access is filtered and logged. Email must not be used to transmit chain messages, spam, or Confidential data to personal accounts, and must comply with the Email Security Policy. Suspected phishing must be reported within one hour of suspicion.
7. Software and intellectual property
Only licensed software is installed, and open-source use follows licence compliance review. The intellectual property of HLD Group, its customers, and third parties is respected, and no unauthorised copying to personal devices or services is permitted.
8. Monitoring and privacy
HLD Group monitors systems and networks for security and policy compliance, consistent with applicable law and our internal privacy notices. Personnel should have no expectation of privacy for business communications on company systems. Monitoring is proportionate and is not used to inspect personal data beyond what is necessary for those purposes.
9. Public websites and trial environments
Visitors to our public websites must not abuse contact forms, scrape at scale, or attempt unauthorised access. Trial environments are for evaluation only, and production or personal data must not be loaded into them without anonymisation approval. Good-faith security testing is governed by the Responsible Disclosure Policy.
10. Consequences of misuse
Violations may result in suspension of access, disciplinary action up to termination, contractual remedies for third parties, civil remedies, and referral to law enforcement. Report abuse to contact@hldgroup.org, and security issues through the Responsible Disclosure Policy.
11. Framework alignment
- ISO/IEC 27001:2022 Annex A control 5.10 (acceptable use of information and other associated assets)
- NIST SP 800-53 Rev. 5 control family PL (Planning) and AC (Access Control)
- SOC 2 Trust Services Criteria CC1.1 and CC2.2
12. Roles, exceptions, and review
The CISO owns this policy. Exceptions require documented CISO approval with compensating controls and an expiry date. This policy is reviewed at least annually and acknowledged by personnel.
For contractual attestations or audit packs, contact security@hldgroup.org.