Acceptable Use Policy

The rules for using Vistra safely and responsibly.

Last updated: 14 September 2026

This Acceptable Use Policy (“AUP”) governs the use of Vistra’s websites, applications, APIs, software, artificial intelligence features, and related services (collectively, the “Services”).

This AUP forms part of the Vistra Terms of Service. By accessing or using the Services, you agree to comply with this policy.

If you use Vistra on behalf of an organisation, you are responsible for ensuring that authorised users within your organisation comply with this policy.

1. Purpose

Vistra provides tools for capturing field information, documenting inspections, managing evidence, creating reports, collaborating with teams, and sharing professional documentation.

You must use the Services lawfully, responsibly, and in a manner that does not compromise Vistra, other users, third parties, or the integrity of information created through the platform.

2. Lawful use

You may not use the Services to conduct, facilitate, promote, or assist activities that violate applicable laws or regulations.

You are responsible for determining whether your use of Vistra complies with laws, regulations, contractual requirements, professional standards, and industry requirements applicable to you.

3. Content you upload

You may upload information such as:

  • Photographs
  • Videos
  • Inspection findings
  • Site information
  • Property information
  • Client information
  • Documents
  • Reports
  • Notes
  • Comments
  • Signatures
  • Attachments
  • Other field records

You must have the necessary rights, authority, permissions, or lawful basis to collect, upload, process, store, and share such content through Vistra.

You must not upload content that unlawfully infringes another person’s privacy, confidentiality, intellectual property, contractual, or other legal rights.

4. Personal and confidential information

Vistra may be used to process business and client information.

You are responsible for determining whether information should be collected and for obtaining any notices, permissions, or consents required by applicable law.

You must not intentionally use Vistra to collect or store information that you are prohibited from possessing or processing.

Where photographs or reports contain identifiable individuals, addresses, access information, vehicle registrations, confidential documents, or other sensitive material, you are responsible for handling that information appropriately.

5. Inspection and report integrity

You must not knowingly use Vistra to create materially false, deceptive, fabricated, or misleading inspection records. This includes intentionally:

  • Falsifying inspection findings
  • Misrepresenting whether an inspection occurred
  • Fabricating evidence
  • Altering evidence to create a misleading impression
  • Falsifying dates or locations
  • Falsifying signatures or approvals
  • Impersonating another inspector or professional
  • Presenting AI-generated information as verified evidence when it has not been verified

Vistra provides documentation tools. Users remain responsible for the professional integrity of their reports.

6. Artificial intelligence features

Vistra may provide AI-assisted features for tasks such as:

  • Drafting descriptions
  • Improving notes
  • Structuring information
  • Categorising findings
  • Summarising content
  • Assisting with report preparation

AI output may contain mistakes, omissions, or inaccurate interpretations.

You must review AI-generated output before relying on it for professional, contractual, compliance, safety, financial, insurance, engineering, property, or other consequential purposes.

You must not deliberately use AI features to fabricate inspection evidence or misrepresent an AI-generated conclusion as an independently verified professional finding.

7. Professional judgement

Vistra does not replace:

  • Qualified inspectors
  • Engineers
  • Surveyors
  • Builders
  • Safety professionals
  • Insurance assessors
  • Compliance professionals
  • Legal professionals
  • Other licensed or qualified professionals

You remain responsible for determining whether qualified professional review is required.

8. Prohibited content

You may not knowingly upload, distribute, publish, or generate content through Vistra that:

  • Is unlawful
  • Infringes intellectual property rights
  • Violates privacy rights
  • Contains malicious software
  • Facilitates fraud
  • Facilitates identity theft
  • Constitutes unlawful harassment or threats
  • Contains illegally obtained confidential information
  • Facilitates exploitation or abuse
  • Violates applicable court orders or legal restrictions

9. Platform security

You must not interfere with or attempt to compromise the security, availability, integrity, or operation of Vistra. Prohibited activities include:

  • Attempting unauthorised access
  • Circumventing authentication
  • Bypassing access controls
  • Testing vulnerabilities without written authorisation
  • Exploiting security vulnerabilities
  • Introducing malware
  • Introducing ransomware
  • Deploying malicious scripts
  • Conducting denial-of-service attacks
  • Interfering with network infrastructure
  • Accessing another user’s data without authorisation

Security research involving Vistra requires prior written authorisation unless we provide a separate vulnerability disclosure program permitting such testing. See our Security page.

10. Automated access and scraping

Unless expressly permitted by Vistra, you may not use automated systems to excessively access, scrape, crawl, copy, or extract information from the Services. This includes:

  • Bots
  • Scrapers
  • Crawlers
  • Automated extraction tools
  • Automated account creation systems

Legitimate use of an officially provided Vistra API is permitted subject to the applicable API terms and usage limits.

11. Reverse engineering

Except where applicable law expressly permits it, you must not:

  • Reverse engineer the Services
  • Decompile software
  • Attempt to discover source code
  • Circumvent technical protections
  • Reproduce proprietary functionality
  • Extract proprietary models or system logic
  • Use unauthorised methods to replicate Vistra’s technology

12. Excessive or abusive usage

You must not intentionally consume resources in a manner that materially interferes with other users or the operation of Vistra. Examples include:

  • Excessive automated requests
  • Deliberately oversized workloads
  • Repeated abusive API requests
  • Attempts to circumvent usage limits
  • Artificially generating excessive processing loads

We may implement reasonable technical limits to protect platform stability.

13. Account security

You are responsible for protecting your account credentials. You must not:

  • Sell accounts
  • Transfer accounts without authorisation
  • Share credentials to bypass licensing restrictions
  • Allow unauthorised persons to access your account
  • Attempt to obtain another user’s credentials

You should notify Vistra promptly if you suspect unauthorised access.

14. Impersonation

You may not impersonate:

  • Another user
  • Another company
  • A government authority
  • An inspector
  • A licensed professional
  • A client
  • A Vistra employee or representative

You must not falsely represent your authority, qualifications, identity, or relationship with another organisation.

15. Intellectual property

You must respect intellectual property rights when using Vistra.

You may not knowingly upload or distribute copyrighted, trademarked, patented, confidential, or proprietary materials unless you have the necessary rights or legal authorisation.

16. Fraud and deception

You may not use Vistra to facilitate fraud or deliberate deception. Examples include:

  • Fake inspection reports
  • Fraudulent insurance documentation
  • Fabricated property evidence
  • False compliance records
  • Forged approvals
  • Fraudulent invoices or supporting documents
  • Misrepresentation of completed work

17. Safety-critical uses

Reports generated through Vistra may relate to buildings, workplaces, equipment, properties, construction activities, or other environments where safety matters.

Vistra should not be treated as the sole authority for safety-critical decisions. Users remain responsible for:

  • Conducting appropriate inspections
  • Verifying findings
  • Escalating hazards
  • Following applicable safety procedures
  • Obtaining specialist advice where required

AI-generated suggestions must not substitute for required professional assessment.

18. Compliance and regulatory use

Vistra does not guarantee that a report automatically satisfies any particular:

  • Building code
  • Insurance requirement
  • Safety regulation
  • Industry standard
  • Government requirement
  • Contractual obligation
  • Professional reporting standard

Users are responsible for configuring and reviewing their workflows according to applicable requirements.

19. Client and third-party data

Organisations using Vistra may process information belonging to clients, property owners, contractors, employees, tenants, insurers, or other third parties.

You are responsible for ensuring that you have an appropriate lawful basis and authority for such processing.

You must apply appropriate access permissions and avoid unnecessarily exposing third-party information.

20. Sharing reports

Vistra may allow users to share reports through links, downloads, exports, email, or other mechanisms. You are responsible for:

  • Selecting appropriate recipients
  • Verifying recipient details
  • Managing report permissions
  • Protecting confidential information
  • Revoking access where appropriate

Vistra is not responsible for disclosure resulting from a user intentionally sharing information with an incorrect or unauthorised recipient, except where applicable law provides otherwise.

21. Integrations

If you connect Vistra to third-party services, you are responsible for:

  • Authorising the integration
  • Understanding what information will be exchanged
  • Configuring permissions appropriately
  • Complying with applicable third-party terms

You must not use integrations to obtain unauthorised access to third-party systems or information.

22. Monitoring and enforcement

To protect the Services, Vistra may investigate suspected violations of this AUP in accordance with applicable law and our Privacy Policy.

Where appropriate, we may:

  • Restrict particular functionality
  • Rate-limit activity
  • Remove unlawful content
  • Suspend access
  • Terminate accounts
  • Preserve relevant records
  • Respond to valid legal requests

We will consider factors such as severity, risk, repeated violations, and applicable legal obligations when taking enforcement action.

23. Emergency security measures

Where activity creates an immediate or material threat to Vistra, its users, third parties, or infrastructure, we may temporarily restrict access without prior notice where reasonably necessary to contain the threat.

24. Reporting abuse

If you believe Vistra is being used in violation of this policy, contact us or email hello@vistra.report.

Include sufficient information for us to investigate the issue.

25. Changes to this policy

We may update this Acceptable Use Policy to reflect changes to:

  • Our Services
  • Applicable laws
  • Security practices
  • Technology
  • Operational requirements

The updated version will display a revised “Last updated” date.

Where required by law or contract, we will provide appropriate notice of material changes.

26. Contact

For questions regarding this Acceptable Use Policy:

Questions about this policy? Contact us or email hello@vistra.report.