Rever Finance Inc.
This Acceptable Use Policy ("AUP") governs use of the Rever platform - agentic AI finance operations in which AI agents reconcile transactions, prepare the close, and identify recoverable amounts, and in which postings and outbound actions are held for approval by your authorized users.
This AUP applies as a condition of access to the Service. Where you access the Service under a subscription agreement, master subscription agreement, order form, or other agreement with Rever Finance Inc., this AUP is incorporated into that agreement, and capitalized terms not defined here have the meanings given in it.
Because Rever's agents act on live financial records, the integrity of the control model is a shared responsibility. This AUP exists to protect it.
1. Use the Service only for authorized finance work
You may use the Service only for the internal finance operations of the legal entity or entities covered by your subscription. You undertake that you will:
- Connect only ERP systems, bank feeds, and document sources that your organization is authorized to access, using credentials issued to your organization;
- Ensure connections are established at the permission level intended by Rever's design, being read-only by default, with write-back only through the audited approval path;
- Designate approvers who hold genuine authority in your organization to approve journal entries, payments, claims, and other postings;
- Configure agent autonomy levels, materiality thresholds, and approval routing in a manner consistent with your own internal control framework, and review that configuration when your control environment changes;
- Not process the records of any legal entity that is not covered by your subscription, whether or not the Service prevents you from doing so.
2. Never undermine the control floors
The following control floors apply to all use of the Service. You must not circumvent, disable, or work around them:
- The AI cannot post. You must not attempt to cause any agent to post to a ledger, transmit funds, send external communications, or change bank details without a human approval recorded on the audit trail.
- Preparer is never approver. You must not structure accounts or roles so that the same person or agent both prepares and approves the same work, and you must not share approver credentials.
- Dual approval on material amounts. You must not split, restructure, or mislabel transactions to evade materiality thresholds or dual-approval requirements.
- Every decision replays. You must not delete, alter, obscure, or falsify audit-trail records, evidence links, or approval history.
3. No manipulation of the agents
You must not:
- Attempt prompt injection, jailbreaking, or adversarial inputs designed to make agents ignore their charters, fabricate evidence, misstate findings, or take unapproved actions;
- Plant falsified documents, invoices, or records in connected sources with the intent of generating false findings, false recoveries, or misleading value reporting;
- Use agent outputs to prepare financial statements or recovery claims you know to be false, or to further fraud, money laundering, embezzlement, tax evasion, or sanctions violations;
- Probe, scan, or test the Service for vulnerabilities except under a written authorization from Rever. Responsible disclosure: legal@rever.ai.
4. Fair use of usage-based plans and credits
Rever is priced on scope and usage - entities, sources, and transaction volume - and value is reported as amounts identified and recovered and hours saved. You must not:
- Misrepresent the number of legal entities, sources, or transaction volumes covered by your subscription, or run multiple entities through a single-entity plan;
- Use our free plan to operate production finance workflows for entities that require a paid plan, or rotate accounts or workspaces to reset the history window available on the free plan or to repeat the proof-of-value period;
- Resell, sublicense, or provide the platform on a service-bureau basis to third parties without a written partner agreement. CPA firms should contact us regarding the partner program;
- Manufacture artificial activity to inflate or game usage, credits, or value metrics.
Service credits and promotional credits have no cash value, are non-transferable, and may be revoked if obtained through misuse.
5. General restrictions
You must not: (a) interfere with or disrupt the Service or other tenants; (b) upload malware or unlawful content; (c) infringe intellectual-property or privacy rights; (d) use the Service to build a competing product, or to benchmark it for publication without our consent; (e) exceed authorized access or use another organization's data; or (f) use the Service where prohibited by US export controls or sanctions, or make the Service available to any person or in any jurisdiction subject to such restrictions.
6. Your data responsibilities
You are responsible for having the rights, and for giving any required notices or obtaining any required consents, to connect your sources and to process the personal information contained in them, for example vendor and employee names appearing on transactions. You must not connect sources containing data you are prohibited from sharing with a service provider, and you must promptly disconnect any source you lose the right to use.
Sensitive data. The Service does not need special categories of personal data. You must not connect sources containing health records, biometric data, government identity numbers beyond what a payment record requires, or similar sensitive data.
Export-controlled technical data. Financial and ERP records in manufacturing environments frequently carry attachments, item master descriptions, drawings, and specifications that constitute technical data controlled under the International Traffic in Arms Regulations (ITAR) or the Export Administration Regulations (EAR). Rever's personnel and service providers may access the Service from locations outside the United States, and access to controlled technical data by a foreign national may itself constitute an export. Accordingly, you must not connect any source containing export-controlled technical data without a separate written arrangement with Rever addressing personnel screening, hosting location, and deployment model. Where your records include such data, a Private VPC or self-hosted deployment may be required.
7. Your responsibility for the accounting
Rever's agents prepare, reconcile, and recommend. They do not decide. Except as separately agreed with us in writing, the findings, reconciliations, prepared journal entries, recovery claims, and value reporting produced by the Service are not accounting, audit, tax, or legal advice. You remain responsible for your books of record, your financial statements, your internal control over financial reporting, and your statutory and regulatory filings, and for the review your approvers perform before approving.
8. Enforcement
We may investigate suspected violations. For serious violations - in particular any attempt to defeat the approval floors, tamper with the audit trail, or use the Service in furtherance of fraud - we may suspend or terminate access immediately, place affected agents into shadow mode, notify your organization's administrators, and, where legally required, notify authorities. Where practical, we will give notice and an opportunity to cure before suspension.
Reduction of agent autonomy following an error is a designed control behaviour of the platform. It is not a service failure and does not entitle you to service credits under the Service Level Agreement.
9. Reporting
To report abuse, suspected fraud in a workspace, or a security concern: legal@rever.ai. To report anything else under this policy: legal@rever.ai.
We may update this AUP from time to time. Material changes will be notified to account administrators.