This is a new service – your feedback will help us to improve it.

  1. Home
  2. Community
  3. Acceptable Usage Policy

Acceptable Usage Policy

Golden rules for contributors

  • do not publish personal information, secrets, credentials, tokens or sensitive data
  • make sure content is accurate, relevant and kept up to date
  • clearly identify the owning team and route for support or feedback
  • follow MOJ acceptable use, information security and security guidance policies
  • follow any applicable platform-specific terms and conditions, including the MOJ GitHub terms of service where content is maintained in GitHub repositories
  • if in doubt, do not publish - seek advice from the appropriate security, policy or platform owner first

Purpose and scope

This document defines the terms of use for the Developer Portal for all users and contributors. It supports safe, secure and responsible use of the service, protects sensitive information, and helps ensure published guidance is trusted, accurate and maintained.

The developer portal aggregates and references content from a variety of platforms and services. Where content is managed, maintained or contributed through another platform, users must also comply with any applicable platform-specific policies, standards and terms of service. For content maintained in GitHub repositories, the MOJ GitHub terms of service applies in addition to the terms below.

  • applies to anyone accessing, using or contributing to the developer portal
  • complements, but does not replace, MOJ acceptable use, information security and related policies
  • must be read alongside any relevant platform-specific requirements, including the MOJ GitHub terms of service where applicable
  • requires users to follow the stricter requirement where policies or standards overlap

Service use and responsibilities

Intended use

The developer portal is a central place to publish and access discoverable, reusable technical guidance. It supports engineering best practice, developer experience, collaboration and reuse across MOJ digital teams. The developer portal does not own contributed content; ownership remains with the originating team or service, who should

  • use the service for its intended purpose of sharing and consuming technical guidance
  • respect other users and contributors
  • follow published guidance in good faith and raise concerns where content appears inaccurate, unsafe or out of date

User and contributor responsibilities

  • follow MOJ security guidance, the MOJ security acceptable use policy and relevant organisational requirements
  • comply with applicable platform-specific terms of service and standards. Where content is maintained in GitHub repositories, contributors must comply with the MOJ GitHub terms of service
  • only publish content that is suitable for the intended audience
  • ensure content is accurate, current, relevant and reviewed regularly
  • provide ownership and contact information so users know who maintains the content

Content standards

Ownership and maintenance

  • content remains owned by the originating team or service
  • contributors are responsible for the accuracy, currency, relevance and ongoing maintenance of published content
  • content should be reviewed regularly and updated or removed when it is no longer accurate or useful

Publishing standards

Published guidance must be

  • clear, accurate, user-focused and written for the intended audience
  • aligned with MOJ security guidance and relevant documentation standards, including GDS and MOJ patterns where applicable
  • owned by a named team or service, with a clear support or contact route
  • maintained regularly and updated when requirements or guidance change

Content that must not be published

Contributors must not publish content that includes, exposes or enables access to sensitive information. This includes, but is not limited to

  • personal information, personally identifiable information or sensitive personal data
  • classified, restricted or internal-only government information not approved for the intended audience
  • security-sensitive information, including unapproved vulnerability information or internal architecture details
  • credentials, passwords, API keys, tokens, cryptographic keys, private certificates, TLS certificates, IPsec credentials, connection strings or configuration containing sensitive values

Where content is stored or maintained in GitHub repositories, contributors must also comply with the MOJ GitHub terms of service, including restrictions relating to organisational data, personal information, regulated data and repository content.

Security, data handling and tooling

Users and contributors must handle information responsibly and follow all relevant MOJ security, data classification and acceptable use requirements.

Only share information that is appropriate for the intended audience.

Apply the principle of least privilege when referencing systems, access or permissions.

Use approved tooling, repositories and processes for creating, reviewing and publishing content.

Store secrets only in approved secure systems and never within developer portal content or documentation.

Follow platform-specific security requirements where applicable. GitHub users must comply with requirements relating to secrets management, code review, security scanning, repository controls and incident reporting.

Report any suspected data exposure, security concern or policy violation immediately through the appropriate MOJ reporting route.

Relevant material

Governance, compliance and reporting

Document ownership

These terms are owned and maintained by the Developer Portal/Developer Experience team. They should be reviewed regularly to ensure alignment with MOJ standards, security guidance and operating practices.

Compliance and enforcement

All users and contributors are expected to comply with these terms. Failure to comply may result in content being removed and, where appropriate, escalation to line management, security teams or organisational leadership.

Failure to comply with applicable platform-specific requirements, including the MOJ GitHub terms of service, may also result in additional enforcement action under those terms.

Reporting issues

Users must report

  • security concerns
  • suspected data exposure
  • policy violations
  • inappropriate content
  • unsafe or misleading guidance

Reports should be raised through the appropriate MOJ security, incident management or service support process.