Lawful Use Policy
OvernightOps exists to help people build lawful, useful things. This policy lists the activities we do not support, how we screen every order before payment, and how our delivery team re-verifies the work before it proceeds.
Last updated 3 October 2026
This policy applies to every order placed with DataRiver New Zealand Limited, NZBN 9429050155972, trading as OvernightOps. It forms part of the Statement of Work you accept at checkout and is linked from the consent you affirm before payment.
Policy version: LU_v1.0. The version in force is the one published at the time of checkout and recorded against your order.
1. Our position
Legitimate engineering regularly touches sensitive areas: AML and KYC compliance tooling, fraud detection, authorised penetration testing, security research, content moderation, licensed gambling platforms, and pharmaceutical compliance. We support that work. What we refuse is work that exists to commit, enable or conceal an unlawful activity. Our screening is therefore designed to read intent, not to block keywords.
You confirm that the work you order — and every output we deliver — will not be used, directly or indirectly, for any of the activities below. This representation is a condition of the agreement and is repeated in Clause 11 of the Statement of Work.
2. Activities we do not support
The 55 unlawful-activity classes we screen for are grouped into the eleven categories below. This list is illustrative, not exhaustive: we may decline any order on reasonable compliance grounds.
Financial crime, fraud & money laundering
- Money laundering
- Terrorist financing
- Tax evasion
- Accounting fraud
- Wire, mail and securities fraud
- Embezzlement
- Unlicensed financial services
- Pyramid schemes
- Predatory lending
- Insurance fraud
- Perjury
- Obstruction
- Evidence tampering
- Racketeering
Corruption & anti-competitive conduct
- Bribery
- Extortion
- Bid rigging
- Price fixing
- Illegal market allocation
- Unfair competition
Consumer deception, forgery & identity theft
- Consumer deception
- False advertising
- Forgery
- Identity theft
- Phishing-adjacent scams
IP infringement & counterfeiting
- Copyright infringement
- Trademark counterfeiting
- Patent infringement
- Trade secret theft
- Corporate espionage
Cyber abuse & unauthorised access
- Cyberattacks
- Unauthorized system access
- Malware
Data theft & privacy violations
- Data theft
- Privacy violations
- Identity theft
Human rights, labour & trafficking
- Child labour
- Forced labour
- Human trafficking
- Employment discrimination
- Wage theft
- Workplace safety violations
Environmental harm
- Illegal dumping
- Hazardous waste violations
- Unauthorized pollution
- Environmental destruction
Controlled substances
- Narcotics trafficking
- Prescription drug diversion
Exploitation & harmful activities
- Production of child sexual abuse material
- Prostitution facilitation
- Illegal gambling
Weapons, sanctions & export controls
- Illegal weapons manufacturing
- Arms trafficking
- Sanctions evasion
- Illegal export of controlled technology
- Dangerous-AI misuse (deepfake personas for fraud, AI to bypass verification)
3. The standards our practices are informed by
Our screening, review and delivery practices are informed by the frameworks below. This is an alignment statement only: it is not a certification, accreditation or attestation, and we do not claim to hold any certification we have not formally obtained.
| Domain | Frameworks |
|---|---|
| Export controls & sanctions | EAR · ITAR · Wassenaar · OFAC |
| Secure software supply chain | NIST SSDF (SP 800-218) · SLSA · SBOM |
| Information security & privacy management | ISO/IEC 27001 · SOC 2 · NIST 800-171 |
| Financial crime & payments | FATF · FinCEN · PCI-DSS |
| Anti-bribery & compliance management | ISO 37001 · ISO 37301 · FCPA |
| Privacy & regulated data | ISO/IEC 27701 · GDPR · HIPAA |
| Platform harm & child safety | NCMEC protocols · EU DSA · UK OSA |
| Responsible AI | ISO/IEC 42001 · NIST AI RMF |
4. How pre-payment screening works
- Deterministic scan. Before payment can be authorised, the order details — the current state, target state, constraints and access notes you type, plus repository names and any documentation branch — are screened against all eleven categories. The scan is instant, repeatable and runs both in your browser (for live feedback) and on our servers (authoritatively).
- Sentence-level context. A compliance or counter-abuse phrase in the same sentence (for example “AML”, “KYC”, “fraud detection”, “authorised penetration test”, “our own systems”, “content moderation”) clears that match. A phrase elsewhere does not.
- Clear, flagged or blocked. A clear scan unlocks payment once the other gates are met. A flagged result keeps payment off: you can revise your answers to make the lawful purpose explicit, or request a manual review. A blocked result — child sexual abuse material, ransomware/botnet/DDoS builders, counterfeit operations, sanctions or OFAC evasion, weapons or ghost guns, no-prescription pharmaceuticals, or trafficking — keeps payment off and can only be resolved by revising the order; if you believe it is an error, contact [email protected].
- You always see the reason. When we cannot clear an order automatically, we show exactly which passage our review flagged, in your own words. There is never a silent gate.
5. Manual review
If you request a manual review, your order enters our compliance queue and we typically respond within two business hours. You can also revise your answers at any time and re-run the scan. Payment only unlocks after a reviewer records an approval for that specific order. If a review is rejected, we explain the decision and invite you to revise the order.
6. Delivery-team re-verification
Screening does not end at payment. Before work proceeds, our delivery team re-checks the materials you provide — including documentation converted from your repository — against this policy. If a concern appears once work has started, the team pauses, records the concern and follows up through your delivery dashboard. Illegal use may result in the order being held or cancelled in line with Clause 11 of the Statement of Work.
7. What we may do
- Refuse, hold or cancel any order on reasonable compliance grounds.
- Provide a full refund where we cancel an order and no work has been delivered.
- Report suspected unlawful activity to the appropriate authorities where we are legally required or permitted to do so.
8. Contact
Questions about this policy, or a belief that an automated flag is in error, can be sent to [email protected]. The full contractual terms are in the Statement of Work (Clause 11) and the Terms of Service.