Institutional Trust Company is seeking a South Dakota trust charter and is not currently accepting accounts.
Explore account capabilities
HomeLegal › Acceptable Use Policy

Legal

Acceptable Use Policy

What the Investor Services experience may and may not be used for, the obligations that come with delegated authority, and how suspension works.

1. Who this applies to

Every user of the Investor Services experience: account holders, authorised persons acting under delegated authority, advisers, plan sponsors, administrators, sponsors, and any institution that licenses the platform. An institution is responsible for the conduct of everyone acting under its access.

2. Prohibited use

You may not use the service to:

  • break any law, regulation or sanctions programme, or help anyone else do so;
  • facilitate money laundering, terrorist financing, sanctions evasion, tax evasion or fraud;
  • engage in a transaction that is prohibited for the account type — including a prohibited transaction or a transaction with a disqualified person in a retirement account — or structure activity to evade a limit, threshold, approval requirement or reporting obligation;
  • act on an account you are not authorised to act on, use another person’s credentials or Passport, or continue acting under authority that has been revoked;
  • misrepresent identity, entity status, ownership, accreditation, or the nature or value of an asset presented for custody;
  • present anything from the service as investment advice, a recommendation, a suitability determination, an endorsement, or as due diligence performed by us;
  • transmit malware, or attempt unauthorised access to the service, another account or any underlying system.

Why this list is longer than a software AUP

  • A directed custodian executes what the account holder directs. That makes the direction itself the control point, so the conduct rules have to name the account-level behaviour — not just the software behaviour.

3. Delegated authority

Where you grant authority to an adviser or another authorised person:

  • You remain responsible for activity conducted under that authority.
  • Revoke authority you no longer intend to grant. You can do that yourself, without a service request, and it takes effect at the time of the change.
  • Where you configure an approval gate so a transaction is not final until you approve it, you are responsible for operating it. An approval that is never given is not an error in the platform.
  • An authorised person above may terminate one below. Do not use that to obstruct a lawful instruction you are obliged to honour.

4. Data obligations

Upload only personal data you are entitled to provide, for purposes consistent with the notices and consents given to the individuals concerned. Do not place personal data in fields not intended for it — free-text notes, record identifiers, file names — because data there is harder to find, export and delete when someone exercises a right.

5. Security obligations

Use multi-factor authentication. Never share credentials. Never embed a production credential or API key in client-side code, a public repository or a support ticket. Rotate on personnel change. Tell us promptly if you believe a credential is compromised. Do not test the security of the service without written authorisation — coordinated testing is welcome and the route is in our security policy.

Treat any unexpected request for credentials, banking details or a signature as suspicious. We will never ask you for your password.

6. Fair use

Do not circumvent rate limits, run load tests against production without authorisation, scrape at a volume that degrades service, or use the service to build a substantially similar competing service. Published limits and quotas are part of the service definition.

7. Reporting

Report suspected abuse to security@investorservices.com. If the report concerns suspected financial crime within your own institution, follow your own escalation procedure first — we are not your compliance function and cannot file on your behalf.

8. Enforcement and suspension

Where use presents an immediate risk to the service, to another account, or of legal or regulatory harm, we may suspend the affected access without prior notice, narrowed to what is necessary. We will tell you what we did and why, and restore access when the risk is resolved.

Because authorisation is evaluated per record and per purpose, a suspension can usually be scoped to a purpose, a delegation or a record class rather than by disabling an account. Suspending access is not the same as restricting an account holder’s rights in their own assets, and we will not use one as a substitute for the other.

9. Governing law

This policy supplements and does not replace your agreement or the applicable custodial or trust documents. Governed by the laws of the State of California; exclusive venue is the state and federal courts located in San Mateo County, California.

Institutional Trust Company is a proposed trust entity seeking a South Dakota non-depository trust charter. It is not yet chartered, is not accepting accounts, and no regulator has approved any application. Investor Services is a pre-charter demonstration and reference experience operated by Financial Infrastructure, Inc.. Nothing on this site is an offer or solicitation of any security. For self-directed accounts the custodian is a directed, non-discretionary, independent custodian — not a fiduciary, adviser or broker-dealer; the account holder directs, and the custodian does not evaluate, recommend or approve any investment. Trust services are different: a trustee is a fiduciary, and trust-administration duties are described in the applicable trust documents.