Skip to content

Draft — not yet reviewed

These terms describe accurately how the product is sold and operated today. It has not been reviewed by a lawyer and several details are unfilled. It should not be relied on until the marked placeholders are completed and it has been reviewed against the law of the jurisdictions you operate in.

Legal

Terms of service

The agreement between you and [LEGAL ENTITY NAME] for use of Agent Trust Cloud. Plain language throughout — where a clause limits what you can expect from the product, it says so directly rather than burying it.

Last updated: 19 September 2026

1. Who this is between

These terms are between [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS] ("we", "us"), and the organization that subscribes to Agent Trust Cloud ("you"). By creating an account, starting a subscription or connecting a system, you accept them on behalf of that organization and confirm you may do so.

2. What the service is

Agent Trust Cloud is a control plane for AI agents and the machine identities they run as. It discovers agents and identities, records what they are and who owns them, evaluates policy against the actions they attempt, and keeps evidence of the decisions made.

An enforcement point only governs the traffic that passes through it. Where an agent, tool or workload reaches a system by a route that does not traverse a gateway or SDK you have deployed, that action is outside the product's control and is neither decided nor recorded. Coverage is a function of how you deploy it, and we do not represent otherwise.

Discovery, risk scoring and recommendations are decision support. They are not a security assessment, a certification, or a determination that you comply with any framework. Control mappings show what the platform can evidence, not what an auditor will accept.

3. Connected systems and credentials

You authorize us to read metadata from the systems you connect, for the purpose of building your inventory. Connectors are read-only by default. Any capability that writes to your environment — rotating a credential, disabling an identity, removing a permission, quarantining an agent — is off until you explicitly enable it, and every such action is logged against the account that authorized it.

You are responsible for having the right to connect each system, and for revoking our access when a subscription ends.

4. What each of us is responsible for

We are responsible for operating the platform, for enforcing the policy as written, and for keeping the evidence we say we keep. You are responsible for the policy itself — what an agent may do, which actions need a human, and who holds an approval. The platform will enforce a permissive policy exactly as faithfully as a strict one.

You are responsible for the agents you run and the actions they take on your behalf, including where those actions are allowed by a policy you configured.

5. Acceptable use

You may not use the service to:

  • Govern, conceal or lend legitimacy to activity that is unlawful where you or the affected people are.
  • Process data you have no lawful basis to process, or connect a system you are not authorized to connect.
  • Attempt to reach another customer’s tenant, evidence or identities.
  • Probe, load-test or attempt to circumvent the platform without written permission, except through a security disclosure.
  • Resell, sublicense or provide the service to a third party as your own, unless we have agreed that in writing.

Security research is welcome. Report what you find through the support page and we will not pursue you for testing carried out in good faith against your own tenant.

6. Plans, billing and renewal

Subscriptions are sold by plan. 2 plans are available self-serve; Enterprise is quoted. A plan includes seats, an allowance of protected actions, and — where the machine identity module is taken — an allowance of governed machine identities. Usage beyond an allowance is billed in blocks at the rate published on the pricing page at the time.

Discovery is never billed. Finding an agent, an MCP server or a machine identity costs nothing on any plan, because charging for it would give you a reason to hide the objects this product exists to reveal.

Term discounts apply to the base subscription only; seats, overages and add-on modules are charged at their full rate. Subscriptions renew for the same term unless either of us gives notice before the renewal date. Fees are exclusive of tax. We may change prices for a renewal term with notice before it begins; we will not change the price of a term already paid for.

7. Your data and your evidence

Your inventory, policies, decisions and evidence are yours. We process them to run the service and for no other purpose — we do not sell them, and we do not use your data to train models. What the website itself collects is set out in the privacy notice, and how the platform stores and isolates customer data is set out in the trust centre.

Evidence is retained for the period your plan provides. You can export it at any time while the subscription is active. After termination we keep it for [RETENTION PERIOD] so you can retrieve it, then delete it.

8. Availability and support

We aim to keep the service available continuously and will give advance notice of planned maintenance where we reasonably can. Any committed availability target and response time is the one stated in your order or enterprise agreement; absent that, the service is provided without a specific uptime commitment.

9. Intellectual property

We keep all rights in the platform, its documentation and anything we develop. You keep all rights in your data and your policies. If you send us feedback or a feature suggestion, we may act on it without obligation or payment — that is not a claim on anything else you own.

10. Confidentiality

Each of us will protect the other's non-public information with at least the care we use for our own, and will disclose it only to people who need it and are bound to similar terms. This does not cover information that is already public, independently developed, or required to be disclosed by law — and where the law requires disclosure, we will tell you unless we are forbidden from doing so.

11. Warranties and disclaimers

We warrant that we will provide the service with reasonable skill and care, and that we will not knowingly introduce malicious code into it.

Beyond that, the service is provided as is. We do not warrant that it will detect every risky agent, prevent every unwanted action, identify every machine identity, or satisfy any particular regulator. A control plane reduces exposure; it does not eliminate it, and no security product honestly claims otherwise.

12. Limitation of liability

Neither of us limits liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot lawfully be limited.

Subject to that, neither of us is liable for indirect or consequential loss, lost profits, lost revenue or lost data, and each party's total liability under these terms is capped at the fees paid or payable by you in the twelve months before the claim arose.

13. Term and termination

Either of us may terminate at the end of a term by giving notice before it renews. Either of us may terminate immediately if the other commits a material breach and does not fix it within thirty days of being told about it. We may suspend the service without notice if continuing it would put other customers, our infrastructure or somebody's data at risk — and we will tell you why as soon as we can.

On termination, your access ends, we stop reading from your connected systems, and you should revoke the access you granted. Export your evidence first: see clause 7 for how long it survives.

14. Changes to these terms

We may update these terms. If a change materially reduces your rights we will give notice before it takes effect for you, and it will not apply to a term you have already paid for. The date at the top records the last revision.

15. Governing law

These terms are governed by the law of [GOVERNING JURISDICTION], and the courts of that jurisdiction have exclusive jurisdiction over any dispute — except that either of us may seek an injunction wherever it is needed.

16. Contact

Questions about these terms go to [PRIVACY CONTACT EMAIL] or through the contact page. To report something broken or a security concern, use support.