Acceptable use policy
What the RFP.co platform may not be used for: prohibited conduct, procurement integrity, honest use of generated content, technical limits, security research and enforcement.
Last updated August 8, 2026
Governed by Arkansas law
This policy is part of the terms of service and applies to everybody who uses RFP.co, including external reviewers invited through a link. It exists so the boundaries are stated rather than inferred — most of it is what you would expect, and two sections are specific to what this product does.
1. The general rule
Use the platform for its purpose: finding procurement opportunities, deciding whether to bid, and preparing your own organization’s response. Do not use it to break the law, to harm somebody, to interfere with the service, or to do something you would not want to explain to a contracting officer.
2. Prohibited conduct
You must not, and must not permit anyone to:
- Break any applicable law or regulation, including procurement, export control, sanctions, anti-bribery and data protection law.
- Upload content you do not have the rights to, or that infringes anyone’s intellectual property, privacy or confidentiality — including a solicitation document you received under a restriction that forbids putting it in a third-party system.
- Upload classified information, export-controlled technical data, protected health information or cardholder data. The platform is not authorized for any of them unless we have agreed otherwise in a signed writing.
- Upload malware, or content designed to damage or gain unauthorized access to a system.
- Harass, threaten, defame or impersonate anybody, including in a comment on a proposal or in an invitation to an external reviewer.
- Access another organization’s workspace, or attempt to. Every workspace is isolated, and probing that isolation is covered by §6 rather than being fair game.
- Share credentials, or use one seat for several people. Add the people; seats are how the record of who did what stays true.
- Resell, sublicense or provide the platform as a service to a third party, except through a client workspace on a plan that includes them.
- Use the platform to build a competing product, or to benchmark it for publication without our written consent.
- Remove, obscure or falsify attribution, authorship or audit records — including the record of which parts of a document a model wrote.
3. Procurement integrity
This section exists because the product makes some things convenient that must not be done, and silence would read as permission.
- Do not coordinate bids between competitors. The platform must not be used to share pricing, strategy or content between organizations that are competing for the same award, or to allocate opportunities between them. Bid rigging and price fixing are criminal offences under U.S. antitrust law and their equivalents elsewhere.
- Client workspaces are separate for a reason. An agency responding on behalf of several clients must keep each client’s content in its own workspace. No query in the platform reads across that boundary, and you must not defeat it by hand — by copying one client’s pricing into another’s pursuit, for instance.
- Do not use the platform to obtain or exploit information you should not have. Source selection information, a competitor’s proposal, or anything covered by the U.S. Procurement Integrity Act does not belong in a workspace, whatever route it reached you by.
- Certifications are yours to make. Small business status, set-aside eligibility, past performance and every other representation to a buyer must be true of your organization and verified by a person. The platform holds what you tell it; it does not check it, and it cannot certify anything on your behalf.
- Teaming and subcontracting. If you invite a teaming partner as an external reviewer, you are disclosing your proposal to them. Make sure your agreement with them permits it, and that any confidentiality obligation you owe the buyer allows it.
4. Using generated content honestly
The platform drafts. You submit. The distance between those two is where this section lives.
- Review before you submit. Do not file a response, make a representation or certify compliance on the strength of text nobody has read. A generated compliance matrix is a starting point for your review, not evidence of compliance.
- Do not present unverified generated claims as fact. The platform refuses drafts asserting what no evidence supports and flags hand-written claims it cannot source. Overriding a flag is allowed — you may know something the platform does not — and doing so makes the claim yours.
- Disclose AI assistance where the buyer requires it. A growing number of solicitations ask. The platform records which blocks a model wrote so you can answer accurately; using that record to answer inaccurately is a breach of this policy.
- Do not fabricate past performance, references, personnel or certifications. Do not prompt the platform to invent them, and do not keep an invention it produced.
- Do not use the platform to generate content for a purpose it is not for — political campaigning, disinformation, spam, or anything unrelated to preparing your own procurement response.
5. Technical limits
- Do not attempt to circumvent a plan limit, a seat count, a usage allowance or a feature entitlement.
- Do not scrape the platform, or access it by automated means other than the API on a plan that includes one.
- Do not exceed published API rate limits, or take deliberate steps to obscure that you are.
- Do not use the platform in a way that degrades it for others, or that consumes resources out of proportion to your plan. Where “unlimited” appears in a plan it is subject to the fair use ceilings published on the pricing page, and those ceilings are stated rather than discovered.
- Do not re-publish the public directory in bulk, or use it to build a competing index. It is there for people evaluating opportunities.
6. Security research
We would rather hear about a vulnerability than not. Report one to security@rfp.co.
We will not pursue a claim against a researcher who acts in good faith and who:
- tests only against their own account and their own workspace;
- stops as soon as they have demonstrated a vulnerability, and does not access, modify, exfiltrate or retain another party’s data;
- does not degrade the service — no denial of service, no load testing, no automated scanning that amounts to one;
- does not use social engineering, phishing or physical intrusion against us or our staff;
- gives us a reasonable period to fix the issue before disclosing it, and coordinates the disclosure with us.
Testing outside those boundaries is not research; it is §2, and we will treat it as such.
7. Enforcement
Where we believe this policy has been breached we will normally contact you first and give you an opportunity to put it right, because most breaches are somebody moving fast rather than somebody acting badly.
Where the breach is causing active harm — to the platform, to another customer, or to a third party — we may act first and explain afterwards. That can mean removing content, suspending a user or a workspace, or terminating the agreement under the terms of service. Where the law requires it we will report conduct to the relevant authority.
We do not delete a customer’s data as a punishment. A suspension for a policy breach leaves the workspace intact and exportable; the retention and deletion terms in the terms of service are the only thing that removes content.
If you think we have got a decision wrong, say so at legal@rfp.co. We will look again, and we will tell you what would change the answer.
8. Changes
We may update this policy as the product changes and as we learn what needs saying. Material changes are notified with the terms of service, on the notice period stated there.
See what you are not bidding on.
Connect a source, describe what your company does, and look at the opportunities that come back before deciding whether any of this is worth your time.