Short version
- Use Hoist for lawful business due diligence.
- Do not use it to search individual grantors, harass people, or harvest registers in bulk.
- AI agents are allowed when they follow the same rules as human users.
- Keep a human confirmation step for high-value decisions. If Hoist later launches a paid operation, use its explicit confirmation control only after Hoist publishes that the operation is customer-accessible.
What you can do
- Use available Hoist source checks for lawful due diligence. Hoist PPSR organisation and serial-number calls are currently unavailable and fail closed; use AFSA direct if you need a PPSR search today.
- Run ABN / GST lookups on counterparties you're transacting with.
- Build internal tools, agents, or workflows that use Hoist programmatically.
- Store records you generate, indefinitely if you want, on your own systems.
- Attach records to deal files, court bundles, audit packages, data rooms.
- Share records with the parties involved in the transaction (counterparty, lawyer, court, regulator).
What you can't do
- Attempt to circumvent the org-only boundary. Don't pass individual-grantor inputs in fields meant for organisations. Circumvention attempts, such as disguising individual data as serial numbers, are termination-worthy.
- Resell Hoist access as a wholesale data product without a separate written agreement. If you're an aggregator, talk to us about the partner programme.
- Harvest the register in bulk. Don't loop through ACN ranges or VIN sequences to build a private mirror. AFSA's terms prohibit this; ours do too.
- Use the service for surveillance, stalking, or harassment. Australian asset registers exist for commercial due diligence; using them to track individuals' assets for non-commercial reasons is prohibited.
- Run automated workloads that materially degrade service for other customers. Fair-use rate limits apply; if you need more, ask.
- Work around record or future pricing controls. Do not try to bypass safeguards on available records or on any paid operation Hoist may launch later. No Hoist PPSR paid search currently executes.
- Bypass authentication. Don't share access credentials across organisations, scrape the dashboard, or use leaked credentials.
AI-agent and automated workflow uses
Hoist is designed to be called by AI agents and automated workflows. Most agent uses are permitted; a few are not.
Permitted agent uses:
- An agent that runs currently available ABN, GST, ASIC-public, or related business checks as part of a legitimate due-diligence workflow on behalf of an authenticated account holder. If a current PPSR search is needed, use the official AFSA PPSR service outside Hoist.
- An agent that interprets a tool-specific source-cited verification response, flags risk items, and escalates to a human reviewer. A sample Evidence Pack must not be treated as source evidence.
- An agent that explicitly requests an on-demand, read-only opportunity delta report. This is a manual comparison, not a monitor, scheduler, automatic recheck, or alert; entity and asset monitoring is unavailable.
- Automated calls from internal tools or CRM integrations operating under an account holder's credentials.
Prohibited agent uses:
- Autonomous high-value decisions. An agent must not use a Hoist verification response as the sole basis for approving or rejecting a financial transaction without a human confirmation step. The separate Evidence Pack export is a prelaunch fixture or unsearched sample and is not decision evidence.
- Unattended bulk harvesting. An agent must not loop through ACN ranges, VIN sequences, or other identifiers to build a mirror of register data. This is prohibited regardless of whether the agent is supervised.
- Credential sharing across agents. Access credentials belong to an account holder. Do not configure multiple agents or third-party services to share a single credential unless you have a written partner agreement.
- Bypassing future confirmation controls. An agent must not suppress a confirmation mechanism if Hoist later launches a paid operation. This is a future safeguard, not a claim that a Hoist PPSR paid search can execute today.
- Using AI output as source-of-truth. Do not submit AI-generated text (e.g., model inference about an entity's status) as input to Hoist searches in place of actual identifiers. Hoist verifies sources; it cannot verify AI-generated content.
Examples - judgement calls
Some uses sit close to the line. Our reading:
- OK: An agent that runs currently available ABN and GST checks on new leads in your CRM and attaches the source-cited business record to your deal file.
- OK: An aggregator platform that lets its own customers run searches via your account - provided your customers have agreed to your terms and you've signed our partner agreement.
- Not OK: An agent that repeatedly attempts unavailable Hoist PPSR calls against ACN ranges to build a private marketing database. Those calls fail closed and do not hit the register.
- Not OK: Submitting a counterparty's individual director's licence number under
serial_number. That's circumventing the org-only boundary. - Ask us: A research project doing aggregated analysis. We may support controlled access when the use is lawful and low-risk.
Enforcement
- First, we ask. If we notice usage that looks off, we email your account contact first.
- Then, we throttle or suspend. Material violations result in rate limiting, scope downgrade, or temporary suspension.
- Finally, we terminate. Repeated or wilful violations end the contract under our Terms of service.
- Payments and refunds: no current workflow creates a new paid subscription or paid-source order, and this policy creates no current cancellation-refund entitlement. For any legacy or future paid relationship, termination-for-cause and voluntary-cancellation refunds follow its applicable written terms and Australian Consumer Law.
Reporting
If you see suspected misuse of the Service (your own data, someone else's, anything), use the current contact route at /contact/. Acknowledged within 24 hours.
