A1. Scope & Purpose
This Acceptable Use Policy ("AUP") applies to all use of the Lens platform ("Lens" or the "Service") provided by Crescent Value Partners, LLC ("CVP," "we," "us," or "our"). It is incorporated into the Lens Subscription Terms and any order, subscription agreement, or other agreement governing a Customer's use of Lens. If another signed agreement conflicts with this AUP, that signed agreement controls to the extent of the conflict.
Assessment activity can resemble or trigger signals associated with an unauthorized intrusion attempt. Lens may therefore be directed only at systems the Customer is authorized to assess.
A2. Authorization to Assess
Customer represents and warrants that it owns, or holds current documented authorization from the owner or a person authorized to grant it, for every network, system, domain, IP range, device, and related asset that Customer:
- submits to Lens as a target;
- includes within an assessment scope or Agent deployment; or
- permits Lens to discover and actively assess under the configured scope.
The authorization must cover the assessment methods Customer enables and any MSP, contractor, or other user performing the assessment on Customer's behalf. Customer is responsible for retaining evidence of authorization while the related assessment data remains in Lens.
CVP may request evidence of authorization before, during, or after an assessment and may delay, restrict, or suspend assessment activity pending verification. An interface confirmation or target entry does not itself establish that authorization exists.
A3. Prohibited Uses
Customer will not, and will not allow any user, integration, or Agent under its account to:
- Assess or direct the Service at a target without the authorization required by A2.
- Gain or attempt to gain unauthorized access to any system, account, credential, data, or another Lens tenant.
- Use Lens for destructive exploitation, denial-of-service activity, traffic flooding, persistence, data exfiltration, credential stuffing, password spraying, phishing, social engineering, cryptomining, or deployment of malicious code.
- Probe, load-test, scan, or otherwise test CVP infrastructure outside Lens's intended features, unless CVP has expressly authorized the activity in writing.
- Interfere with or disrupt the integrity, security, availability, or performance of the Service or any data, account, or tenant it contains.
- Circumvent or attempt to circumvent access controls, plan entitlements, quotas, concurrency limits, rate limits, or other technical restrictions.
- Resell, sublicense, or provide third-party access outside an approved direct-customer, MSP, or other contractually authorized account model.
- Upload, store, or transmit executable malware, malicious code, raw credentials, payment-card data, or unnecessary secrets. Ordinary assessment evidence may reference malware indicators but must not contain executable malware unless CVP expressly authorizes it in writing.
- Extract raw credentials or unsanitized device configurations for storage or transmission outside the Customer environment, or bypass, disable, or interfere with Agent-side sanitization.
- Reverse engineer, decompile, disassemble, or attempt to derive source code or non-public detection logic from the Service, except to the extent applicable law makes the restriction unenforceable.
- Use the Service in violation of law, regulation, sanctions, export controls, third-party rights, or a binding contractual obligation.
- Misrepresent the source, scope, authorization, ownership, or results of an assessment.
A4. Agent & Credential Handling
Lens Agents are designed to use SNMP, SSH, Telnet, enable, and similar collection credentials locally in the Customer environment. In ordinary supported operation, those raw collection credentials are not included in Agent uploads to Lens. Configuration artifacts are sanitized before upload, and Lens receives sanitized evidence and limited secret metadata rather than plaintext configuration secrets.
Customer is responsible for:
- Securing the host and local data directory where an Agent runs.
- Limiting credential permissions, target scope, and network reach to what the assessment reasonably requires.
- Using secure protocols where available and understanding the risks of legacy protocols such as SNMPv2c and Telnet.
- Rotating or revoking collection and Agent credentials when no longer needed or when compromise is suspected.
- Reviewing custom or manually uploaded files to ensure they contain no raw credentials, secrets, malware, or data outside the authorized scope.
- Not modifying, bypassing, or disabling credential-handling or sanitization controls.
A5. Customer Administration
Customer is responsible for its Authorized Users, Agents, integrations, delegated operators, and MSP personnel and for activity performed with their credentials. Customer must grant least-privilege access, remove access promptly when no longer required, protect credentials, and notify CVP of suspected compromise or unauthorized use.
A6. Enforcement
CVP may investigate suspected violations. Where CVP reasonably believes activity creates legal, security, safety, or operational risk, CVP may delay or stop an assessment; restrict targets, features, Agents, or access; preserve relevant records; or suspend the affected account immediately and without prior notice. CVP may also require remediation or evidence of authorization before restoring access.
These actions are in addition to remedies available under the governing agreement or law. When circumstances permit, CVP will limit a restriction to the affected activity or account and notify the relevant Customer contact.
A7. Reporting Abuse & Security Issues
Report suspected misuse, unauthorized scanning, or another AUP violation to report@cvpapp.com.
Report a suspected vulnerability or security incident affecting CVP or Lens to security@cvpapp.com. Include relevant dates, targets, source addresses, and assessment identifiers where available, but do not email passwords, private keys, or unnecessary sensitive data.
A8. Changes
CVP may update this AUP as the Service, assessment methods, risks, or legal requirements change. We will update the effective date and provide additional notice of material changes when appropriate under the governing agreement.