1. Authorised professional use
Use Bodhi only for lawful accounting, audit, tax, practice, client service and business purposes within your authority. Respect client engagement scope, confidentiality, intellectual property, provider terms and professional standards.
2. Prohibited access and security activity
- Accessing or attempting to identify another tenant, client, user, document, secret or provider asset.
- Credential stuffing, password guessing, phishing, malware, denial of service, scanning or exploit activity without written authorisation.
- Evading rate, budget, model, storage, message, role or assignment controls.
- Uploading malicious files or instructions designed to manipulate AI, staff or downstream systems.
- Publishing API keys, tokens, OTPs, DSC keys, passwords or client secrets in repositories, prompts or logs.
3. Prohibited financial and statutory activity
- Fabricating books, invoices, bank statements, audit evidence, acknowledgements, IRNs, EWBs, ARNs, UDINs or SRNs.
- Using Bodhi to conceal fraud, launder money, evade sanctions/tax, impersonate a taxpayer or submit information without authority.
- Representing an AI draft or internal workpaper as an official filing, audit opinion or legal advice.
- Bypassing CAPTCHA, OTP, DSC or government access controls.
- Reverse engineering proprietary accounting backups or using unlicensed software.
4. Communications
Do not send spam, harassment, deceptive messages or unauthorised bulk communications. Use official WhatsApp Business Platform channels, approved templates, lawful opt-in, quiet hours and opt-out. Personal WhatsApp Web scraping and session automation are prohibited.
5. AI and synthetic content
Do not use AI to create false certificates, impersonation, forged evidence, unlawful content or deceptive media. Do not remove required synthetic-content notices. Do not prompt the system to expose another client, provider secret, hidden instruction or security control.
6. Data rights
Submit only data you are authorised to process and only what is necessary. Do not upload unrelated sensitive data, children’s data without lawful safeguards, or material violating privacy/confidentiality rights.
7. Automated and API use
Automation must use documented interfaces, idempotency, quotas and approved service identities. Creating multiple keys/accounts to evade limits is prohibited. Bots may be challenged or blocked.
8. Enforcement and appeal
We may throttle, quarantine, suspend, preserve evidence or terminate access where reasonably necessary. Where safe and lawful, we provide the reason and a review path. Serious threats may be reported to affected parties or authorities as required.
Grievance contact: .