Acceptable Use Policy
Last updated 25 September 2026
In plain English
- Slurry is for testing software integrations with fake data. Nothing in it should be real.
- No real personal data, card numbers, credentials or production data - in seeds, specs, prompts, rules or outputs.
- No phishing, no pretending to be a real service to fool people, no web pages or scripts served to end users.
- No malware, no attacking or load testing anyone else's systems, no reselling, no getting round our limits or IP restrictions.
- We scan for abuse automatically and act on it, from a warning up to closing your account and reporting to the authorities.
- Report abuse to abuse@slurry.io.
1. Scope
1.1 This Acceptable Use Policy ("AUP") applies to everyone who uses slurry.io and any Simulation, subdomain, API, webhook, MCP Server or other interface operated by The Next Renaissance Ltd, trading as Slurry ("Slurry", "we", "us"). It forms part of our Terms of Service. Capitalised terms not defined here have the meaning given in the Terms of Service.
1.2 Customers are responsible for making sure their Authorised Users, and any AI agent or software acting under their credentials, comply with this AUP.
2. Permitted use
Slurry may be used only to create simulated, synthetic test environments for developing, testing, demonstrating and training people on software integrations, using data that is not real. Anything outside that purpose is not permitted unless we have agreed it in writing.
3. Prohibited data
You must not upload, enter, prompt for, generate, store, transmit or return through Slurry, including in seed data, API specifications, prompts, rules, fixed outputs, webhook payloads or request bodies:
- Real personal data about any identifiable living individual, including names linked to real contact details, real email addresses or phone numbers of real people, government identifiers, health data, biometric data or any special category or criminal offence data.
- Real payment card data, bank account details or other financial account credentials, including full or partial primary account numbers from real cards.
- Real credentials of any kind, including passwords, API keys, OAuth tokens, private keys, session cookies or certificates for any real system (other than the Slurry and bring-your-own model keys you configure in the designated settings).
- Production data or extracts from any live system, whether or not it contains personal data, including copies of real customer, order, patient, employee or transaction records.
- Confidential information or trade secrets that you do not have the right to use.
- Content that is unlawful, defamatory, obscene, hateful, harassing, or that sexualises children in any way.
Use clearly fictitious values. The Service provides test card numbers, reserved domains (such as example.com) and synthetic identities for this purpose.
4. Prohibited activities
You must not use Slurry to:
- Deceive people. Build phishing pages, lookalike login or payment flows, or any Simulation, webhook or output designed or likely to make a real person believe they are dealing with a real, named third-party service or organisation. Simulating an API's request and response behaviour for developer testing is the purpose of the Service; deceiving humans is not.
- Serve content to end users. Serve HTML, JavaScript, downloadable files or other content intended to be rendered or executed by members of the public or end users in a browser. Simulations are machine-to-machine test endpoints. We may restrict content types, add security headers or sandbox responses to enforce this.
- Distribute malware. Host, generate or deliver viruses, ransomware, exploit code, command-and-control infrastructure or any other malicious payload, including via webhooks, file drops, email, message queues or fixed outputs.
- Attack or load test others. Direct traffic at any system you do not own or have written permission to test, including by using webhooks, scheduled mutations or callbacks to flood, scan, probe, brute-force or load test third-party systems, or to carry out denial-of-service attacks.
- Harvest or replay credentials. Collect credentials, tokens or personal data from any person, or attempt to authenticate against real third-party production systems from within Slurry.
- Break the law. Carry out or facilitate fraud, money laundering, sanctions evasion, infringement of intellectual property rights or any other unlawful activity.
- Infringe rights in specifications. Upload an API specification that you do not have the right to use, or remove attribution or licence notices from library specifications.
- Resell. Resell, sublicense, rent, white-label or provide the Service or Simulations to third parties as a hosted service, or share Accounts between separate organisations, unless we have agreed this in writing.
- Circumvent controls. Get round or attempt to get round IP allow-lists, API key checks, rate limits, usage limits, Credit or billing controls, content scanning, or suspensions, including by creating multiple Accounts, rotating IP addresses to avoid limits or disguising prohibited content.
- Compromise the Service. Probe, scan or test the vulnerability of Slurry's own infrastructure (except under our responsible disclosure process at security@slurry.io), interfere with other customers, access data that is not yours, or introduce excessive load.
- Misuse AI features. Use our hosted models to generate content unrelated to Simulations, attempt to extract our system prompts or other customers' data, or breach the usage policies of the underlying model providers.
- Misrepresent Slurry. Imply that a Simulation is the real third-party system, or that Slurry or its customers are affiliated with or endorsed by the provider of the system being simulated.
5. Monitoring
5.1 To enforce this AUP we operate automated and manual monitoring, including:
- scanning of seed data, uploaded specifications, prompts, rules, fixed outputs and Generated Data for patterns that indicate real personal data, card numbers (including checksum validation), credentials, secrets and malicious content;
- checks on webhook and callback destinations, including blocking private, internal and cloud metadata addresses and limiting volume per destination;
- analysis of request volumes, sources, response content types and error rates to detect phishing, public serving, scraping and load-testing patterns;
- rate limits and spending limits on the MCP Server and our APIs;
- review of reports made to abuse@slurry.io.
5.2 Monitoring is carried out to protect the Service, our customers and third parties. Where we process personal data in monitoring, we do so as described in our Privacy Policy. We do not guarantee that monitoring will detect every breach, and monitoring does not reduce your responsibility to comply with this AUP.
6. Enforcement ladder
6.1 We respond in proportion to the seriousness of the breach, the risk of harm and whether it is repeated. Our usual steps are:
- Automated block. A specific request, payload, webhook or seed operation that triggers a scanning rule is blocked or redacted in real time, with an explanation in the Service or the API response.
- Warning. We notify the Account owner, explain the breach and ask for it to be fixed, usually within 72 hours.
- Restriction. We disable the affected Simulation, webhook, API key or feature, reduce limits, or quarantine the data concerned.
- Suspension. We suspend the Account in whole or in part pending investigation or remedy.
- Termination. We terminate the Account under the Terms of Service, and may delete the offending content immediately.
- Referral. Where we believe the law has been broken or people are at risk, we may preserve evidence and report the matter to the police, Action Fraud, the National Cyber Security Centre, the Information Commissioner's Office, affected third parties or other authorities.
6.2 We may skip steps and act immediately (including terminating without prior warning) for serious breaches, such as phishing, malware, child sexual abuse material, attacks on third parties, or real personal data or card data being uploaded at scale.
6.3 Where lawful and practicable we will tell you what action we have taken and why. You may ask us to review a decision by emailing abuse@slurry.io within 14 days, giving reasons. We will respond within a reasonable time.
6.4 No refunds are due for suspension or termination caused by a breach of this AUP, and we may recover our reasonable costs of dealing with the breach.
7. Reporting abuse
If you believe a Slurry Simulation or subdomain is being used for phishing, impersonation, malware, attacks or any other abuse, email abuse@slurry.io with the full URL (for example name.slurry.io), the date and time, and any evidence you have. Security vulnerabilities in Slurry itself should be reported to security@slurry.io. Intellectual property complaints about a specification or name used in the Service should be sent to legal@slurry.io.
We aim to acknowledge abuse reports within one business day and to act on credible reports of phishing or malware as a priority.
8. Changes
We may update this AUP to respond to new risks. We will post the updated version on this page with a new version date, and will notify customers by email of material changes.
9. Contact
The Next Renaissance Ltd, trading as Slurry. Registered in England and Wales, company number 10373346. Registered office: [registered office address]. Abuse: abuse@slurry.io. Security: security@slurry.io. Legal: legal@slurry.io.
The Next Renaissance Ltd, trading as Slurry, registered in England and Wales, company no. 10373346. Questions: legal@slurry.io