Policy bundle version: 2026-08-05.
This page describes the current engineering posture and explicit limitations. It is not a certification, service commitment, data-processing agreement, authorization for PHI use, or confirmation that customer signup is active. Customer use requires explicit launch activation and compliance with the applicable published policies. Institution-controlled or restricted use may also require a separately approved trust packet and written agreement.
1. Prohibited Data
- PHI, patient identifiers, patient-specific facts, records, images, audio, or case material.
- Credentials, secrets, private keys, tokens, or payment-card data.
- Content the user lacks authority to process.
- Malware, exploit payloads, or files intended to bypass upload controls.
- Restricted data not explicitly approved for the workspace.
2. Prohibited Conduct
- Attempting unauthorized access, tenant crossover, privilege escalation, or control bypass.
- Using outputs for autonomous clinical decisions, diagnosis, or emergency guidance.
- Presenting MARCUS output as an approved institutional policy when the source owner has not approved it.
- Reverse engineering or security testing outside an authorized disclosure process.
- Abusive automation, denial-of-service activity, spam, unlawful surveillance, or rights violations.
3. Enforcement and Reporting
We may restrict access, stop processing, quarantine or delete content, and investigate suspected violations. Report security issues to security@surgic.ai without including customer content, PHI, credentials, or secrets.