Terms of Use

Atbash Platform Terms of Use

Legal

Terms of Use

Atbash Technologies Ltd. — Platform Terms of Use

Version date: _______

1.ACCEPTANCE AND CONTRACTING PARTIES

1.1

Agreement and Parties. This Platform Terms agreement (the “Agreement” or the “Terms”) is entered into between Atbash Technologies Ltd. (“Atbash”) and the entity identified as the customer in the applicable Order or, if no Order applies, during account registration (“Customer”). Atbash and Customer are each referred as a “Party” and collectively the “Parties.”

1.2

Acceptance and Effective Date. This Agreement becomes effective on the earlier of the date Customer: (a) affirmatively accepts these Terms through an electronic acceptance mechanism that identifies and provides access to them; or (b) enters into an Order that incorporates these Terms by reference (the “Effective Date”). The individual accepting this Agreement on Customer’s behalf represents and warrants that such individual is an Authorized User and has authority to bind Customer. A person without that authority must not accept on Customer’s behalf. Atbash may create and retain electronic records evidencing Customer’s acceptance.

2.DEFINITIONS

2.1

Action” means any operation proposed, initiated or performed by an Agent, including any tool call, transaction, communication, access to or modification of data, workflow step or other operation that may affect Customer Systems or any third party.

2.2

Submitted Action” means an Action, together with the applicable Decision Inputs, submitted to the Services through an Integration for evaluation, approval, enforcement or recording. An Action is subject to execution control by the Services only if the applicable Deployment Mode is configured for enforcement and the Action is routed through the applicable enforcement point before execution.

2.3

Affiliate” means any entity that directly or indirectly controls, is controlled by or is under common control with a Party. For purposes of this definition, “control” means ownership of more than 50% of the voting interests of an entity or the power to direct its management or policies, whether through ownership, contract or otherwise.

2.4

Agent” means any artificial intelligence model, bot, automated process, script, or other software actor that Customer connects to, integrates with, or registers with the Services, or whose Actions Customer submits to the Services.

2.5

Authorized User” means a natural person (and specifically excluding any Agent) whom Customer authorizes to access or use the Services on its behalf, including Customer’s employees and independent contractors and, to the extent expressly permitted under the applicable Order, personnel of its Affiliates.

2.6

Operator” means an Authorized User whom Customer explicitly designates and authorizes to configure or administer Policies, review or approve Actions generated by an Agent, or exercise other administrative, oversight, or approval authority through the Services.

2.7

Atbash Control Boundary” means the functions, components and enforcement points that Atbash operates or for which Atbash expressly assumes responsibility under the Agreement, as specified in the applicable Order, Product Schedule and Documentation. The Atbash Control Boundary includes the Atbash-hosted portions of the Services, Judges operated by or on behalf of Atbash as part of the Services (“Atbash-Operated Judges”), and the documented functionality of Atbash-supplied software components, including components installed within Customer Systems. The Atbash Control Boundary does not include the operation, configuration or security of Customer Systems or Third-Party Products, except to the extent Atbash expressly assumes responsibility for them under the Agreement. The physical or logical location of a component does not, by itself, determine whether that component falls within the Atbash Control Boundary.

2.8

Atbash Technology” means: (a) the Services and underlying platform, software, source and object code, architecture, interfaces, dashboards, administrative tools and Documentation; (b) all policy templates, policy packs, rule libraries, control frameworks, evaluation criteria, prompts, workflows, schemas and other policy-authoring or governance materials created or developed by or on behalf of Atbash, whether generally available or developed, configured or adapted for Customer; (c) all SDKs, APIs, plugins, connectors, adapters, middleware, integration code, sample code, libraries and other Integration components developed by or on behalf of Atbash; (d) Atbash’s evaluation engines, Judges, models, algorithms, methodologies, authentication mechanisms, enforcement functionality, audit and recording technology, analytics and related tools and know-how; (e) all deliverables and other technology or materials developed by or on behalf of Atbash in performing implementation, configuration, consulting, support or other services under this Agreement; and (f) all modifications, enhancements, updates, adaptations and derivative works of the foregoing, together with all Intellectual Property Rights therein. Atbash Technology includes these items whether developed before or during this Agreement, independently or in connection with Customer’s requirements, and whether hosted by Atbash, installed in Customer Systems or incorporated into another product or deliverable. Atbash Technology excludes Customer Materials and independently procured Third-Party Products as such, but their incorporation into or use with Atbash Technology does not transfer ownership of the underlying Atbash Technology.

2.9

Customer Data” means data, content and other materials submitted to or made available through the Services by or on behalf of Customer, including Customer-provided Policies and policy configurations, Decision Inputs and Customer-provided credentials; “Customer Records” means Customer-specific Decisions, approval records, Action logs, policy and version histories, and reports generated through Customer’s use of the Services. Customer Data and Customer Records do not include Atbash Technology, including any Atbash-provided policy packs, models, evaluation methodologies, de-identified, aggregated operational telemetry derived from the Services or other underlying proprietary information or data incorporated into them.

2.10

Customer Systems” means Agents, models, applications, infrastructure, environments, tools, networks, accounts, credentials and business systems provided or controlled by Customer or parties acting on its behalf, excluding Atbash Technology as such.

2.11

Decision Inputs” means the information made available to a Judge or other evaluation mechanism in connection with a Submitted Action, including the Action’s description and parameters, tool names and arguments, operational context, identity and authority information, relevant metadata and system state, applicable Policies, and any other information used to evaluate the Submitted Action.

2.12

Decision” means a result generated by the Services in response to the evaluation of a Submitted Action, which may include an ALLOW, HOLD or BLOCK designation and any associated explanation, information or metadata.

2.13

Deployment Mode” means the configuration under which the Services are provided, including the applicable hosting, evaluation, enforcement, advisory and audit functionality, as identified in the applicable Order, Product Schedule or Documentation.

2.14

Integration” means an SDK, API, plugin, adapter, framework connection or other interface made available by Atbash or identified in the Documentation as supported for connecting the Services with Customer Systems.

2.15

Judge” means an evaluation engine used to assess Decision Inputs and generate a Decision, whether using semantic, model-based, deterministic or combined evaluation methods.

2.16

Intellectual Property Rights” mean all patent, copyright, trade secret, trademark, database, design and other intellectual property or proprietary rights worldwide, including applications, registrations, renewals and extensions.

2.17

Documentation” means Atbash’s then-current official technical and user documentation made available to Customer for the applicable Services, Integration, Deployment Mode and supported version, including documented configuration requirements, dependencies and limitations. Documentation does not include advertisements, general marketing materials, sales presentations or roadmap statements unless expressly incorporated into an Order as a binding commitment.

2.18

Order” means an order form, statement of work or electronic subscription order entered into by the Parties that identifies the applicable Services and commercial terms. An electronic Order includes the subscription details presented to Customer at checkout and Atbash’s corresponding order confirmation.

2.19

Product Schedule” means a schedule incorporated into the Agreement that sets forth additional terms applicable to a particular product, Integration, Deployment Mode, industry or use case.

2.20

Subscription Term” means the period during which Customer is authorized to access and use the Services under an Order, including any renewal terms.

2.21

Policies” rules, thresholds, restrictions, prohibitions, approval requirements and other authorization criteria selected, configured or approved by Customer for the evaluation or control of Actions, including any applicable Atbash-provided policy packs.

2.22

Services” means the Atbash platform functionality, software and related services identified in an applicable Order, including any support expressly included in that Order. A reference in the Agreement to any feature or functionality does not entitle Customer to use that feature or functionality unless it is included in Customer’s subscription and supported under the applicable Deployment Mode.

2.23

Third-Party Products” mean software, models, Judges, applications, frameworks, platforms, services and other products independently selected and obtained by Customer from third parties for use with the Services. Third-Party Products do not include infrastructure or services that Atbash procures from its subcontractors to perform Atbash’s obligations under the Agreement.

2.24

Usage Data” means operational and technical data concerning the use, operation and performance of the Services, such as request volumes, resource consumption, latency, feature usage and error metrics. Usage Data does not include the substantive content of Actions, Policies, Decision Inputs or Customer Records.

3.ORDERS; ENGAGEMENT

3.1

Orders. Each Order will identify the Services purchased by Customer and the applicable Subscription Term, usage entitlements or limits, fees and other commercial terms. Customer authorizes its designated subscription administrators to enter into electronic Orders and modify subscriptions on Customer’s behalf within the scope of their assigned permissions, and Customer will be bound by their actions. Atbash has no obligation to provide any Services, capacity, professional services, custom development or other deliverables not expressly included in an accepted Order.

3.2

Use by Affiliates and Contractors. Subject to the applicable Order, Customer may permit its Affiliates and contractors to access and use the Services under Customer’s subscription solely for the internal business purposes of Customer and its permitted Affiliates. Customer remains responsible and liable for their acts and omissions relating to the Services as if they were Customer’s own.

4.ACCESS RIGHTS; SCOPE AND OPERATION OF THE SERVICES

4.1

Access and Use Rights. Subject to Customer’s full compliance with the terms and conditions of this Agreement and timely payment of all applicable fees, Atbash grants to Customer, during the applicable Subscription Term, a limited, non-exclusive, non-transferable, and non-sublicensable right to: (a) permit its Authorized Users to access and use the hosted Services and Documentation, and connect authorized Agents thereto, solely for Customer’s internal business operations; and (b) install, configure, and execute Atbash-supplied Integrations and software components within Customer Systems solely as necessary to interact with the Services, in each case strictly in accordance with the Documentation and applicable Order.

4.2

Customer-Facing and Embedded Use. Customer may use the Services to monitor, evaluate or control Agents deployed within Customer’s products, services and customer-facing workflows. Unless expressly authorized in an Order, Customer may not: (a) resell or sublicense the Services; (b) provide third parties with standalone access to the Services; (c) offer the Services as a standalone authorization, governance or agent-control service; or (d) operate the Services as a managed service for third parties. Customer’s end customers may receive the benefit of the Services through Customer’s permitted products and workflows, but do not thereby become Authorized Users, acquire any direct right to access the Services or Documentation, or obtain any contractual rights or remedies against Atbash.

4.3

Provision of the Services. Customer is purchasing only the Services and functionality included in its applicable Order as of the relevant Subscription Term. Customer’s purchase is not contingent on the delivery of any future functionality, and Atbash will have no obligation to provide any future feature, integration or enhancement unless expressly committed in an Order signed by both Parties..

4.4

Processing and Enforcement. Atbash will process supported Submitted Actions that are properly transmitted to the Services in material accordance with the applicable Documentation, based on the Decision Inputs made available to the relevant Judge or other evaluation mechanism. Atbash will perform only those enforcement functions that are included in Customer’s subscription, supported by the applicable Integration and Deployment Mode, and properly enabled and configured. Without derogation of any other provision hereunder, Atbash shall have no liability or obligation for any failure, delay, or incorrect Decision resulting from Customer’s improper configuration, failure to enable supported features, or provision of inaccurate, corrupted, or incomplete Decision Inputs. These obligations apply solely within the Atbash Control Boundary and do not constitute an undertaking by Atbash to monitor or control Customer’s entire agentic, software or operational environment.

4.5

Functionality by Deployment Mode. Atbash processes properly transmitted Submitted Actions within the Atbash Control Boundary in material accordance with the Documentation, based on the applicable Deployment Mode:

4.5.1

Enforcement functionality: Evaluates and gates execution paths, solely to the extent the supported Integration is correctly implemented, enabled, and configured to route the Action through an enforcement point prior to execution.

4.5.2

Advisory functionality: Generates and displays Decisions or recommendations for informational purposes, and does not delay, gate, or prevent the execution of an Action.

4.5.3

Audit or observation functionality: Records and displays submitted activity, and does not evaluate, approve, gate, or prevent an Action.

The foregoing modes may operate concurrently within a single subscription. Applicable functionality is governed strictly by the Deployment Mode designated in the applicable Order, Product Schedule, or Documentation, and is not determined by the commercial plan name or marketing tier. Atbash shall have no liability for executed Actions resulting from Customer’s selection of Advisory or Audit Mode or misconfiguration of Enforcement points.

4.6

Unrouted Actions. The Services cannot evaluate, approve, block or record an Action unless the Action and necessary Decision Inputs are routed through the applicable evaluation, enforcement or observation point. Customer is responsible for identifying and appropriately securing any alternative execution paths, direct access to tools or systems, downstream permissions and any activity occurring after an Action leaves the applicable enforcement point. Atbash shall have no liability for any Action executed via unrouted or bypassed execution paths.

4.7

Shared Responsibilities. Where the operation of the Services depends on tasks performed by both Parties, including integration, routing, collection and transmission of Decision Inputs, Judge connectivity and human-approval workflows, each Party is responsible for performing the tasks allocated to it under the Agreement, the applicable Order and the Documentation. Neither the involvement of Customer Systems nor that of a third party will relieve Atbash of responsibility to the extent Atbash’s breach of its allocated obligations independently caused the relevant failure. Conversely, Atbash will not be responsible to the extent a failure results from Customer’s breach, Customer Systems, Third-Party Products or matters outside the Atbash Control Boundary.

5.AGENT REGISTRATION; IDENTITY, CREDENTIALS AND AUTHORITY

5.1

Agent Registration and Access Controls. Customer is responsible for accurately registering each Agent, associating it with the appropriate Customer organization, Policies and permissions, and keeping that information current. Customer will designate appropriate Operators and will provision, protect, rotate and revoke all credentials, tokens, keys and other authentication materials under Customer’s control (“Credentials”). Customer will implement the supported authentication controls described in the Documentation and ma. intain appropriate security measures, including least-privilege access, secure storage of Credentials and timely revocation of unnecessary or compromised access. Customer is responsible for activity conducted through its Credentials. Customer will notify Atbash without undue delay through Atbash’s designated security-reporting channel of any actual or suspected unauthorized access, disclosure or compromise that may affect the Services, and will reasonably cooperate in mitigating its effects.

5.2

Cryptographic Keys and Secrets. The generation, issuance, signing, use, storage, rotation, recovery and revocation of cryptographic keys and other secrets will be governed by the applicable Order, Product Schedule and Documentation. Customer will not transmit private keys, passwords or other authentication secrets through support tickets, ordinary email, logs or any other channel not expressly designated by Atbash for the secure transmission of such information. Customer is responsible for safeguarding and administering keys and secrets generated, stored or controlled within Customer Systems. Atbash is responsible for operating any Atbash-provided key-handling functionality in material accordance with the Agreement, including the applicable Documentation. Unless an Order expressly provides otherwise, Atbash does not retain recoverable copies of private keys controlled by Customer, provide key-recovery or escrow services, or act as a custodian of such keys. Loss or compromise of a Customer-controlled private key may therefore result in permanent loss of access or authority, and Atbash may be unable to recover or replace it.

5.3

Reliance on Authenticated Instructions. Atbash may treat any instruction or request authenticated through the agreed authentication mechanisms and within the permissions assigned to the relevant Agent, Authorized User or Credential as authorized by and binding on Customer. Atbash may continue to rely on such authentication unless and until: (a) Atbash receives notice of a suspected compromise through its designated reporting channel and has had a reasonable opportunity to take appropriate protective action; or (b) Atbash has actual knowledge of a compromise or of a failure in an authentication mechanism within the Atbash Control Boundary. Successful cryptographic authentication establishes only that an instruction is associated with the applicable Credential. It does not independently establish the identity, intent, legal capacity or actual authority of the individual using that Credential, the accuracy of any submitted information, or the legality or appropriateness of the requested Action. Customer remains responsible for establishing and maintaining the organizational authority and permissions represented by its Credentials and configurations.

5.4

No Agency or Authority over Assets. Registration of an Agent, authentication of an instruction or issuance of a Decision does not appoint Atbash as Customer’s agent, representative, fiduciary, trustee or custodian. Atbash has only the technical permissions and authority expressly enabled by Customer and necessary to provide the subscribed Services under the applicable Deployment Mode.

6.INTEGRATIONS; CUSTOMER SYSTEMS AND EXECUTION CONTROLS

6.1

Implementation and Maintenance. Except to the extent an Order expressly assigns implementation responsibilities to Atbash, Customer is responsible for, inter-alia:

6.1.1

installing, configuring, integrating, testing and maintaining Customer-side Integrations;

6.1.2

providing compatible Customer Systems, environments, connectivity, information and access reasonably necessary for the Integrations to operate;

6.1.3

implementing supported updates, patches and configuration changes within the periods reasonably specified by Atbash where necessary to address security risks, maintain compatibility or continue receiving support; and

6.1.4

ensuring that its use of each Integration complies with the applicable Documentation.

Before using an Integration in production, Customer will test its routing of Submitted Actions, processing of Decisions, approval workflows and behavior in the event of errors, timeouts, unavailable responses and other failure conditions. Customer will repeat appropriate testing following any material change to the Integration, Customer Systems, applicable Policies or Deployment Mode. Atbash remains responsible for any implementation tasks and deliverables expressly assigned to it under an Order.

6.2

Implementation of Decisions. Where Customer code, a host application, framework or other component outside the Atbash Control Boundary controls whether an Action is executed, Customer is responsible for implementing the behavior associated with each Decision. Without limitation, Customer will configure the applicable component to: (i) prevent execution following a BLOCK Decision; (ii) where a pre-execution human approval is required, prevent execution following a HOLD Decision unless and until a valid approval is received through the designated approval workflow; and (iii) handle errors, timeouts, unavailable responses and other processing states in accordance with Customer’s required security posture and the applicable Documentation.

6.3

Transaction Integrity and Decision Binding. Except to the extent expressly included in the subscribed Services, Customer is responsible for maintaining transaction and execution integrity within Customer Systems, including, inter-alia: (i) idempotency and prevention of duplicate execution; (ii) management of state changes, retries, resumed sessions and concurrent requests; (iii) verifying that the Action ultimately executed corresponds to the Action and parameters submitted for evaluation; and (iv) preventing substitution or material modification of an Action after evaluation. Each Decision applies only to the specific Submitted Action, Decision Inputs and operational context evaluated by the Services and, if applicable, only during the validity period indicated by the Services or Documentation. A Decision may not be reused for a retried, resumed or modified Action if its parameters, identity, authority, state or other material context has changed. In such circumstances, Customer must submit the Action for a new evaluation unless the Documentation expressly provides otherwise.

7.POLICIES; DECISION IPUT; CONTEXT

7.1

Customer Policy Authority. Customer determines its organizational authority structure and is solely responsible for selecting, configuring, validating, approving, assigning and maintaining Policies appropriate for its Agents, use cases and risk tolerance. This responsibility includes establishing appropriate authorization limits, approval thresholds, segregation of duties, escalation procedures and Operator permissions. Customer controls and is responsible for Policy changes made by its Operators. Before implementing a Policy or Policy change, Customer will assess its intended operation and potential effect on pending and future Actions. Policy changes will take effect in accordance with the versioning, activation and propagation behavior described in the Documentation.

7.2

Templates and Guidance. Atbash may make available policy templates, suggested controls, configuration recommendations and implementation guidance to assist Customer in designing and administering Policies. Those materials are provided for general informational and operational purposes and do not constitute legal, regulatory, financial, medical or other professional advice, or a representation that any Policy is sufficient or appropriate for Customer’s particular activities, risks or compliance obligations. Customer-provided policy rules and Customer-specific configurations constitute Customer Data. Atbash retains all rights in the Atbash Technology incorporated into or used to create or implement Policies, including its preexisting templates, policy packs, taxonomies, evaluation methods and policy-authoring technology. Customer’s rights to use those materials are limited to the rights granted under its subscription.

7.3

Platform-Level Controls. Atbash may implement and enforce platform-level security, integrity and abuse-prevention controls that operate independently of Customer Policies. In accordance with the Agreement, those controls may restrict access to the Services, reject or limit submissions, suspend processing or prevent use that creates a security, legal or operational risk.

7.4

Customer Responsibility for Decision Inputs. Customer is responsible for ensuring that all Decision Inputs provided by Customer, its Agents or Customer Systems: (i) are collected, used and disclosed lawfully and with all necessary rights, notices and consents; (ii) satisfy the applicable input and formatting requirements described in the Documentation; (iii) are accurate, timely, sufficiently complete and internally consistent in all material respects; and (iv) fairly represent the identity, authority, parameters, context and intended effect of the Action that may ultimately be executed. Customer will provide all information reasonably required for evaluation and will not omit, obscure or mischaracterize any material aspect of a Submitted Action or its intended execution.

7.5

Reliance on Decision Inputs. Atbash may rely on Decision Inputs supplied by or on behalf of Customer without independently investigating or verifying their factual accuracy, completeness, legal sufficiency or authenticity. If Decision Inputs are missing, inconsistent, contradictory or otherwise insufficient, the Services may request additional information, return a HOLD, BLOCK or ERROR response, or decline to complete the evaluation, as described in the Documentation. The Services’ ability to identify certain deficiencies does not constitute a commitment to detect every omission, inconsistency, inaccuracy or misrepresentation. Where the subscribed Services expressly include the collection, transformation or transmission of particular information, Atbash will perform that functionality in material accordance with the Documentation. Atbash is not responsible for the accuracy or completeness of information at its source merely because the Services retrieve, process or transmit that information.

8.EVALUATION AND DECISIONS

8.1

Meaning of decisions:

8.1.1

ALLOW means that, based on the Decision Inputs and applicable Policies evaluated at that time, the Submitted Action satisfied the authorization criteria applied by the Services. An ALLOW Decision does not require Customer to execute the Action and does not independently establish that the Action is lawful, factually accurate, safe or appropriate.

8.1.2

HOLD means that the Submitted Action requires further review or approval under the applicable evaluation. A HOLD Decision does not constitute affirmative authorization. Whether execution is technically paused depends on the applicable Integration, Deployment Mode and configuration.

8.1.3

BLOCK means that the Submitted Action did not satisfy the applicable authorization criteria. Whether execution is technically prevented depends on the applicable enforcement mechanism and Customer’s implementation.

8.1.4

ERROR, timeout, unavailable response, indeterminate result or absence of a Decision means that the Services have not provided affirmative authorization. An Action may nevertheless proceed where Customer has expressly configured a fail-open or advisory path. Customer is responsible for evaluating and accepting the risks associated with such a configuration.

8.2

Evaluation Methods and Limitations. The Services may evaluate Submitted Actions using deterministic rules, probabilistic or semantic analysis, one or more Judges, or a documented combination of those methods. Model-based and probabilistic evaluations are inherently variable and may produce false positives, false negatives or different results for similar inputs. Any explanation, confidence indicator, rationale or supporting metadata accompanying a Decision is provided to assist Customer’s review and does not constitute independent verification of the underlying facts or a guarantee that the Decision is complete or correct. Customer remains responsible for applying human review, escalation procedures and other safeguards appropriate to the nature and potential consequences of its Actions.

8.3

Scope and Duration of Decisions. Decision applies only to the specific Submitted Action, Decision Inputs, Policies and operational context evaluated by the Services at the time of evaluation and, if applicable, only during the validity period indicated by the Services or Documentation. Customer must resubmit an Action for evaluation whenever its material parameters or relevant context change or as otherwise required by the Documentation. Atbash does not guarantee the commercial, operational, legal or other outcome of any Action, including an Action that receives an ALLOW Decision.

8.4

Human Review and Approval. The Customer is responsible for appointing appropriately qualified Operators, defining and maintaining the scope of their authority, and ensuring adequate availability, training, review and escalation procedures. Subject to the Agreement and applicable platform-level controls, any approval, rejection or permitted override submitted by a duly authorized Operator through the agreed authentication mechanisms constitutes an instruction from Customer on which Atbash may rely. Customer is responsible for ensuring that each Operator acts within the authority granted to that Operator. Atbash does not provide human reviewers or assume responsibility for Customer’s approval decisions unless an Order expressly provides for an Atbash-operated review service.

8.5

Approval Presentation and Implementation. Where supported, the Services will present an Operator with the Submitted Action and the Decision Inputs available to the applicable approval workflow and will associate the Operator’s response with that submission. Customer is responsible for ensuring that its Customer System executes only the Action, parameters and context corresponding to the Operator’s approval. Features such as cryptographic or technical binding of an approval to specific parameters, approval expiration, single-use approvals, dual approval, step-up authentication and automatic resubmission are available only where expressly identified as supported in the applicable Order, Product Schedule or Documentation and are properly enabled and configured. References to such features in the Agreement do not imply that they are available for every Integration or Deployment Mode.

8.6

Effect of a HOLD. A HOLD Decision that remains unresolved does not constitute human approval or affirmative authorization. Depending on the applicable Integration and configuration, a HOLD may place an Action into an asynchronous review queue without technically preventing the host application from executing it. If Customer requires approval before execution, Customer must select, configure and maintain a supported mechanism that pauses the applicable execution path until a valid approval is received. The appearance of an Action in an approval queue, its status in the dashboard or an approval issued after execution does not establish that the Action was technically paused. A subsequent approval cannot reverse, validate or otherwise affect an Action that has already been executed.

8.7

Atbash-Operated Judges. Atbash-Operated Judges include Judges supplied and operated by Atbash as part of the Services and Judges operated by providers that Atbash engages to perform that function on its behalf. Atbash remains responsible for the performance of an Atbash-Operated Judge as part of the Services to the same extent as for its other subcontracted functions, subject to the documented characteristics and limitations of model-based evaluation and the other terms of the Agreement. If Customer independently selects or contracts with a Judge provider, Customer is responsible for: (i) the relationship with and terms applicable to that provider; (ii) obtaining all rights, notices and consents necessary to transmit Customer Data and Decision Inputs to the provider; (iii) supplying and maintaining valid API credentials and appropriate account permissions; (iv) procuring sufficient capacity and paying all provider charges; and (v) assessing the provider’s suitability, outputs, security and compliance characteristics. Customer instructs and authorizes Atbash to use Customer-provided credentials and transmit the information reasonably necessary to the endpoint configured by Customer for that purpose. Atbash remains responsible for operating its connector in material accordance with the Documentation and for its handling of Customer Data and credentials while within the Atbash Control Boundary. Atbash does not warrant or assume responsibility for the external provider’s outputs, availability, latency, capacity, security, compliance or continued availability of any model or API. Identification of a provider as compatible or supported does not constitute an endorsement or warranty of that provider or its services.

8.8

Customer-Hosted and Custom Judges. Any Customer-hosted or custom Judge, together with its supporting infrastructure, constitutes part of Customer Systems. Customer is responsible for its deployment, operation, authentication, availability, security, output integrity and compatibility with the Services. Atbash will perform any response-authentication, format-validation, routing or similar function expressly included in the subscribed Services. Atbash’s receipt, acceptance, display or routing of a response from a Customer-hosted or custom Judge does not constitute validation of the response’s substantive accuracy, completeness or suitability.

8.9

Availability, Failover and Provider Changes. Judge-provider outages, capacity constraints, rate limits, latency, API changes and model changes may affect the availability, timing or outcome of an evaluation. Any failover arrangements, fallback providers, model-pinning functionality and fail-open or fail-closed behavior will be determined by the applicable Order, Product Schedule, Documentation and enabled configuration. For Customer-selected Judges, Atbash will not route Customer Data to an alternative Judge endpoint unless authorized through Customer’s configuration or written instructions. For Atbash-Operated Judges, Atbash may use fallback providers included within the subscribed configuration, subject to the applicable Data Processing Addendum and any required subprocessor notice or authorization procedures. The allocation of responsibility under this Section does not alter the Parties’ respective roles under the Data Processing Addendum. A Customer-selected Judge provider does not become an Atbash subprocessor merely because the Services connect to it at Customer’s direction, unless Atbash separately engages that provider to process personal data on Atbash’s behalf.

9.ENFORCEMENT AND EXECUTION AUTHORIZATION

9.1

Scope of Enforcement. Enforcement functionality applies only to the execution points, Action types, Integrations and components expressly identified as supported and enabled for Customer’s applicable Deployment Mode. Atbash will operate its blocking and gating functionality at those enforcement points in material accordance with the Documentation. Customer is responsible for implementing and maintaining the corresponding host-side controls, routing requirements and execution restrictions within Customer Systems. Atbash does not assume responsibility for Actions that bypass or are not routed through an applicable enforcement point, or for controlling any tool, Credential, Agent process, transaction or downstream system beyond the Atbash Control Boundary.

9.2

Failure-State Configuration. Customer is responsible for selecting, configuring and testing the behavior required for timeouts, errors, connectivity failures, unavailable or indeterminate responses, pending approvals and interruptions to audit or evaluation functionality. Unless expressly stated for a particular supported configuration, the Services do not provide universal fail-closed behavior. Any default failure-state behavior described in the Documentation applies only to the specified component, Integration, configuration and supported version. Customer-developed code, overrides, exception handlers, retry logic and configuration changes may alter the resulting execution behavior.

9.3

Decision Verification and Execution Integrity. Customer will authenticate or verify Decisions using any mechanism required by the Documentation for the applicable Integration. Except where expressly included in the subscribed Services, Atbash does not provide: atomic evaluation and execution, rollback, cancellation or reversal of completed Actions, transaction or settlement finality, protection against replay outside the Atbash Control Boundary, or assurance that the Action’s parameters, system state or other context will remain unchanged between evaluation and execution. Customer retains control over downstream credentials and execution authority and is responsible for maintaining appropriate transaction-binding, replay-prevention, state-validation and other independent safeguards within Customer Systems. An ALLOW Decision is an authorization signal based on the evaluated submission and does not itself execute an Action or guarantee that the downstream execution will correspond to that submission.

10.BLOCKING, JAILING AND EMERGENCY CONTROLS

10.1

Available Containment Functions. Where included in Customer’s subscription and supported by the applicable Integration, the Services may block a Submitted Action, flag or designate an Agent as “jailed,” revoke or suspend its authorization within the Services, or apply other containment measures described in the Documentation. A containment measure affects only the Atbash authorization mechanisms and participating Integrations that receive, consult and enforce the applicable status. Unless expressly included in the subscribed functionality, a containment measure does not terminate an Agent process, disable Customer Systems, revoke credentials issued by a third party, cancel pending external instructions, or reverse an Action or transaction that has already been executed.

10.2

Release, Reactivation and Emergency Response. Customer is responsible for determining who may authorize the release, reactivation or override of an Agent and for maintaining appropriate approval and escalation procedures for those actions. Atbash may require supported authentication, step-up verification or other security controls before implementing such an instruction. Customer is responsible for implementing emergency-response measures within Customer Systems, including, where appropriate, suspending Agent processes, revoking external credentials, restricting network or system access, disabling tools and attempting to cancel pending transactions. Atbash’s containment functionality does not replace those measures.

10.3

Disabling Controls; Platform Suspension. Disabling evaluation, enforcement or logging functionality may have materially different consequences. In particular, disabling evaluation or logging does not necessarily block or terminate an Agent and may permit it to continue operating without Atbash evaluation or recording. Customer will review and test the documented consequences before disabling or bypassing any control. Atbash may separately restrict or suspend access to the Services to protect the Customer, the Services, other customers or third parties. Such a platform-level restriction or suspension is an administrative or security measure and does not constitute an Agent-specific Policy evaluation or Decision.

11.AUDIT RECORDS AND ANALYTICS

11.1

Recording and Reporting Functionality. Atbash will provide the recording, retrieval, export, analytics and reporting functionality included in Customer’s subscription in material accordance with the Documentation. The fields recorded, timing of record creation, durability, visibility, searchability, export formats and retention periods depend on the applicable Services, Deployment Mode and configuration. Customer Records reflect the information received, generated or observed by the Services. A record may describe a proposed Action, a Decision, an Operator response or a result reported by Customer Systems or a third party. Unless the Services directly observe and record the relevant event within the Atbash Control Boundary, a record does not necessarily establish that an Action was executed, prevented or completed, or that the executed Action corresponded exactly to the Submitted Action.

11.2

Evidentiary Limitations. Timestamps, signatures, hashes, approval records and other technical evidence may support Customer’s audit and investigation activities, but do not independently establish the factual accuracy of the underlying information, the legal authority of a person or Agent, or the admissibility or sufficiency of a record for any particular legal, regulatory or evidentiary purpose. Customer is responsible for determining whether the subscribed recording functionality satisfies its recordkeeping and compliance requirements.

11.3

Append-Only and DLT Records. Where the subscribed Services include DLT-based or other append-only recording, the applicable Product Schedule or Documentation will describe the material characteristics of that functionality, including the categories of information recorded, the relevant network or recording mechanism, and applicable submission and confirmation behavior. Customer will assume that every Action is recorded before execution, that all records are public or private, or that only hashes or non-substantive information are recorded, except as expressly stated in the applicable Order, Product Schedule or Documentation. Customer acknowledges that information written to a public, decentralized or append-only system may be visible to third parties and may not be capable of modification or deletion, including following expiration or termination of the Agreement. A DLT transaction, hash or other cryptographic record establishes only the information technically represented by that record and does not independently establish the factual accuracy or lawfulness of its contents.

11.4

Customer Recordkeeping Responsibilities. Customer will not include passwords, private keys, authentication secrets or unnecessary personal, confidential or sensitive information in any field designated for persistent or public recording. Customer is responsible for maintaining exports, backups and independent records required for its business, legal or regulatory obligations. Unless an Order expressly provides otherwise, the Services are not Customer’s exclusive system of record.

12.UNDERTAKINGS

12.1

Customer will: (i) maintain complete and accurate account, billing and notice information; (ii) administer its Authorized Users, Operators, credentials, roles and permissions; (iii) obtain and maintain all rights, authorizations, notices, consents and lawful bases necessary for Customer Data, Customer’s Integrations and its deployment and use of the Services; (iv) use the Services in accordance with the Agreement and applicable Documentation; and (v) provide reasonable information and cooperation requested by Atbash to investigate and remediate security, operational or technical issues affecting the Services. Customer is responsible for its Agents, underlying models, Customer Systems, business processes and deployment decisions, including the selection of use cases and the manner in which Customer acts or relies on Decisions. These responsibilities do not limit Atbash’s obligations within the Atbash Control Boundary.

12.2

Security, Resilience and Human Governance. Customer will maintain cybersecurity, identity and access management, business-continuity, backup, incident-response and human-governance measures appropriate to the nature of its deployment and the potential consequences of its Agents’ Actions. Customer will assess residual risks, monitor and respond to relevant alerts, test its safeguards and maintain appropriate escalation and recovery procedures. For Actions that may be irreversible or have material legal, financial, operational or security consequences, Customer will maintain appropriate defense-in-depth measures and will not use the Services as its sole safeguard where additional independent controls are reasonably required by the risk.

12.3

Prohibited Conduct. Customer will not, and will not permit any other person to: (a) use the Services in violation of applicable law or in a manner that infringes, misappropriates or otherwise violates any intellectual-property, privacy, confidentiality or other right; (b) use the Services to gain or facilitate unauthorized access to any account, system, network, credential or data; (c) circumvent or attempt to circumvent authentication requirements, subscription or usage limits, licensing controls, Decisions, containment measures or other security or technical restrictions of the Services; (d) interfere with, disrupt, damage or materially degrade the integrity, security, availability or performance of the Services or any third-party system; (e) introduce malicious code or content intended to compromise or harm the Services or another person; (f) reverse engineer, decompile, disassemble or otherwise attempt to derive nonpublic source code, model components, algorithms or underlying structure of the Atbash Technology, except to the extent such restriction is prohibited by nonwaivable law or inconsistent with an applicable open-source license; (g) copy, modify, translate or create derivative works of the Atbash Technology except as expressly permitted by the Agreement; (h) access or use nonpublic aspects of the Services, Documentation or Atbash Confidential Information to develop, train or improve a product or service that competes with the Services; (i) remove, obscure or alter any proprietary-rights notice contained in the Services or Documentation; or (j) sell, resell, sublicense, distribute or provide access to the Services.

12.4

Authorized Security Testing. Customer may conduct ordinary functional testing and, through features expressly designed for that purpose, submit adversarial examples, simulated attacks and threat samples involving systems that Customer is authorized to test. Any penetration test, vulnerability scan, load or stress test, denial-of-service simulation, or attempt to access or compromise Atbash infrastructure requires Atbash’s prior written approval and mutual agreement on the applicable scope, timing and safeguards. The restrictions on malicious code and content do not prohibit authorized security research or evaluation conducted through documented testing features and in accordance with the Agreement. Customer remains responsible for safely handling any live malware, credentials, personal data or other sensitive testing materials.

12.5

Allocation of Regulatory Responsibility.

12.5.1

Use of the Services by an entity operating in a regulated industry is not categorically prohibited. Each Party will comply with the laws and regulatory obligations applicable to that Party’s role in providing or using the Services. Customer is responsible for determining whether its Agents, underlying business activities, Customer Data and deployment of the Services are lawful, appropriately authorized and suitable for the intended use. Customer will obtain all required licenses, approvals and consents and implement any legally required human oversight, explanations, testing, governance and recordkeeping. Atbash does not become Customer’s compliance officer, fiduciary, regulated decision-maker, financial advisor, healthcare provider or other professional adviser merely by providing the Services. Nothing in the Agreement overrides any legal role or obligation imposed on either Party by applicable law.

12.5.2

Sector-Specific Requirements and Restricted Data. Any use requiring sector-specific contractual, security, audit, localization, certification or operational commitments must be expressly supported by the applicable Services and addressed in an Order, Product Schedule or addendum signed by the Parties.

12.5.3

Customer will not submit or otherwise make available through the Services:

12.5.3.1

protected health information subject to HIPAA unless a business associate agreement is in effect;

12.5.3.2

cardholder data or sensitive authentication data subject to PCI DSS unless the applicable Service is expressly identified as supporting such data;

12.5.3.3

classified government information;

12.5.3.4

export-controlled technical data requiring access restrictions not expressly supported by the Services; or

12.5.3.5

any other specially regulated data for which the required contractual and technical safeguards have not been implemented.

12.5.4

This Section does not prohibit ordinary use of the Services by financial-services, healthcare, government or other regulated organizations where the applicable use and data are supported. Customer will not represent that the Services satisfy a sector-specific certification or regulatory requirement unless Atbash has expressly confirmed that status in writing.

12.6

Safety-Critical Uses. Customer will not deploy the Services as the sole or primary fail-safe control in any system where failure or an incorrect Decision could reasonably be expected to cause death, serious bodily injury, or severe physical or environmental damage, unless a Product Schedule signed by both Parties expressly authorizes the deployment and specifies the required safeguards.

12.7

No use prohibited by applicable law is permitted.

13.CUSTOMER DATA AND USAGE DATA

13.1

Ownership of Customer Data and Customer Records. As between the Parties, Customer and its licensors retain all right, title and interest in and to Customer Data. Customer also retains its rights in the Customer-specific content embodied in Customer Records. To the extent Atbash owns any rights in Customer-specific Decisions or other Customer Records, Atbash grants Customer a perpetual, worldwide, nonexclusive, royalty-free license to retain, reproduce, use, export and disclose those Customer Records for Customer’s business, operational, legal, regulatory, audit, evidentiary and customer-reporting purposes. This license does not transfer any right in the underlying Atbash Technology, including Atbash’s models, evaluation methods, policy packs, templates or platform functionality, and does not provide Customer with continued access to the Services after expiration of the applicable access or retention period.

13.2

License to Atbash. Customer grants Atbash a nonexclusive, worldwide license during the term of the Agreement to host, process, reproduce, transmit, store, display and otherwise use Customer Data and Customer Records solely as reasonably necessary to: (i) provide, operate, secure, support and administer the Services; (ii) generate Decisions and Customer Records; (iii) perform Atbash’s obligations and exercise its rights under the Agreement; and (iv) comply with applicable law and binding legal process. Atbash may exercise this license through its personnel and subcontractors performing those purposes, subject to the confidentiality, security and data-protection obligations applicable under the Agreement.

13.3

Usage Data. Atbash may collect and use Usage Data to operate, secure, monitor, support, analyze and improve the Services, manage capacity, prevent fraud or abuse, and administer subscriptions and billing. As between the Parties, Atbash owns Usage Data, subject to the restrictions in the Agreement. To the extent Usage Data identifies Customer or an individual, reveals Customer Confidential Information or constitutes personal data, it remains subject to the applicable confidentiality, security and privacy obligations. Information does not cease to be Customer Confidential Information or personal data merely because Atbash characterizes it as telemetry or Usage Data.

13.4

Aggregated and De-Identified Data. Atbash may create, use and disclose aggregated or de-identified statistics derived from use of the Services for service improvement, security analysis, capacity planning, benchmarking and industry analysis.

13.5

Data Processing Addendum. To the extent Atbash processes personal data on Customer’s behalf, the Atbash Data Processing Addendum available online or another DPA executed by the Parties, is incorporated into and forms part of the Agreement (the “DPA”). The DPA governs the subject matter and duration of processing, categories of personal data and data subjects, security measures, subprocessors, international-transfer mechanisms, assistance obligations, and return and deletion of personal data. In the event of a conflict between the DPA and another component of the Agreement concerning the processing of personal data, the DPA will control. Customer will not submit personal data for processing on its behalf unless the applicable DPA is in effect.

13.6

Parties’ Privacy Responsibilities. Each Party is responsible for providing the notices, obtaining the consents and establishing the lawful bases required for the personal-data processing undertaken in its respective role. Any data-residency commitment or restriction on the location of processing or international transfers must be expressly stated in the applicable Order or DPA. These Terms do not independently create a data-residency or data-localization commitment.

14.CONFIDENTIALITY

14.1

Definition. “Confidential Information” means any nonpublic information disclosed or made available by or on behalf of a Party (“Discloser”) to the other Party (“Recipient”) that: (a) is designated as confidential; or (b) reasonably should be understood to be confidential given its nature and the circumstances of disclosure. Confidential Information includes Customer Data, Customer Records, nonpublic Atbash Technology, product and security information, vulnerability information, business plans, and the nonpublic commercial terms and negotiated pricing under the Agreement. “Confidential Information” excludes information the recipient can demonstrate became public without breach, was lawfully known without restriction, was independently developed without using the information, or was lawfully received without restriction from a third party.

14.2

Use and Protection. With respect to Confidential Information, the recipient will:

14.2.1

use the Discloser’s Confidential Information solely to perform its obligations, exercise its rights or enforce the Agreement;

14.2.2

protect it using at least the same degree of care the Recipient uses to protect its own confidential information of similar sensitivity, and in no event less than reasonable care; and

14.2.3

disclose it only to the Recipient’s employees, Affiliates, contractors, subcontractors and professional advisers that have a need to know it for a permitted purpose and are bound by confidentiality obligations or professional duties at least as protective as those set forth in this Section.

The Recipient is responsible for any breach of this Section by those recipients as if the breach were committed by the Recipient. A Party may disclose the Agreement and related commercial terms, subject to appropriate confidentiality protections, in connection with a bona fide financing, insurance placement, acquisition, investment, corporate reorganization or due-diligence process. This permission does not authorize disclosure of substantive Customer Data or Customer Records for those purposes

14.3

Required Disclosure. The Recipient may disclose Confidential Information to the extent required by applicable law, regulation, subpoena or court or governmental order. To the extent legally permitted and reasonably practicable, the Recipient will (i) provide the Discloser with advance written notice; (ii) disclose only the portion legally required; and (iii) provide reasonable assistance, at the Discloser’s expense, if the Discloser seeks a protective order or other confidential treatment. A compelled disclosure does not otherwise remove the disclosed information’s confidential status under the Agreement.

14.4

A recipient may disclose information as legally required, giving advance notice where lawful and practicable, limiting disclosure to what is required, and reasonably assisting protective measures at the discloser’s expense. Unauthorized publication does not eliminate responsibility for the disclosure. Upon request, the recipient will return or delete Confidential Information subject to Section 37 and lawful archival retention.

14.5

These duties continue for three years after termination, except that trade secrets remain protected while qualifying as trade secrets and Customer Data and Customer Records remain protected while retained. Either Party may seek equitable relief for threatened or actual unauthorized disclosure or use, subject to applicable law.

14.6

The Recipient may retain copies contained in routine backups or archives, required by applicable law, or reasonably necessary to establish or exercise legal rights, provided that retained information remains protected under this Section and is not used for any other purpose.

14.7

Each Party acknowledges that unauthorized use or disclosure of Confidential Information may cause harm for which monetary damages are an inadequate remedy. Accordingly, the affected Party may seek appropriate injunctive or equitable relief, in addition to other available remedies, subject to applicable law.

15.INTELLECTUAL PROPERTY

15.1

Atbash Technology. Ownership and Reservation of Rights. As between the Parties, Atbash and its licensors retain all right, title and interest in and to Atbash Technology. Except as expressly provided in a mutually signed Order or statement of work that specifically identifies the deliverable and rights being transferred, no Atbash Technology is a work made for hire for Customer, and no ownership transfers to Customer because Customer commissions, funds, specifies, configures, tests, contributes Feedback concerning or otherwise participates in its development. To the extent Customer acquires any Intellectual Property Rights in modifications, enhancements or derivative works of Atbash Technology, excluding Customer Materials embodied in them, Customer hereby assigns those rights to Atbash and will follow Atbash’s instructions in documenting that ownership.

15.2

Customer Materials; Configured Policies. As between the Parties, Customer retains its rights in Customer Data and in code, content, business requirements, rules and other materials independently developed by or for Customer without incorporating or deriving from Atbash Technology (“Customer Materials”). Customer’s selection, configuration or use of an Atbash-created policy template, policy pack or Integration does not transfer ownership of that item or its underlying structure, code or other protectable elements. Customer retains its rights in its independently supplied policy content, thresholds, instructions and business-specific parameters, while Atbash retains its rights in the Atbash Technology used to implement, express, evaluate or enforce them. Neither Party acquires ownership of the other’s materials merely because those materials are combined.

15.3

Limited Use Rights. Customer receives only the access and use rights expressly granted under this Agreement and the applicable Order. Unless expressly agreed otherwise, Atbash-created policy materials, Integration components and service deliverables may be used only within the scope of Customer’s authorized use of the Services during the applicable Subscription Term. No right to exploit them separately, sublicense or distribute them, or obtain source code is granted by implication, estoppel or otherwise.

15.4

Feedback Rights. Customer may voluntarily provide, directly or through its Authorized Users, suggestions, ideas, recommendations, enhancement requests or other feedback concerning Atbash Technology, including its policy templates, evaluation functionality and Integrations (“Feedback”). Customer hereby assigns to Atbash all of Customer’s right, title and interest, including Intellectual Property Rights, in that Feedback. To the extent any such rights cannot be assigned, Customer grants Atbash a perpetual, irrevocable, worldwide, nonexclusive, transferable, sublicensable, fully paid-up, royalty-free license to use, reproduce, modify, disclose, distribute, create derivative works from and otherwise exploit the Feedback for any purpose, including developing and commercializing products and services, without attribution, accounting or compensation. Customer will ensure that persons submitting Feedback on its behalf have authorized the rights granted under this Section. Atbash has no obligation to implement Feedback, and its receipt or implementation creates no ownership, approval or participation right for Customer in Atbash Technology.

16.THIRD-PARTY PRODUCTS

16.1

Third-Party Products. Customer’s acquisition and use of Third-Party Products are governed solely by Customer’s agreement with the applicable third-party provider. Atbash’s integration with, listing, identification, recommendation or support of a Third-Party Product does not: (a) make the Third-Party Product part of the Services; (b) constitute an endorsement or warranty of that Third-Party Product; or (c) guarantee its continued availability, compatibility, security or performance. Third-Party Products exclude Atbash-supplied Integration components as such and providers or components Atbash procures to perform its own obligations under this Agreement. Customer’s access to and use of Third-Party Products are governed by its arrangements with the applicable providers. Customer is responsible for obtaining and maintaining the necessary rights, accounts, permissions, credentials and subscriptions, paying applicable charges, and complying with the applicable provider terms. Atbash’s listing, integration, recommendation or identification of a Third-Party Product as compatible does not make it an Atbash Service or incorporate the provider’s commitments into this Agreement.

16.2

Separate Component Licenses. An SDK, plugin, sample-code package or other separately supplied component may be subject to additional license terms that are expressly presented and accepted for that component. Those terms govern the licensing and use of the identified component only. They do not amend the Agreement’s enterprise-service, confidentiality, data-protection, security, indemnification or liability provisions unless the amendment is expressly identified and agreed in accordance with the Agreement’s amendment requirements.

17.FEES

17.1

Fees and Subscription Commitments. The Customer will pay all fees in the currency and according to the billing schedule specified in the applicable Order. Unless an Order expressly provides otherwise, fees for committed subscriptions are based on the purchased Services, quantities and usage entitlements, regardless of Customer’s actual use. Usage-based fees apply only where the Order or an incorporated pricing schedule expressly identifies the applicable metered charges. Except as expressly provided in the Agreement or an Order: (i) subscription commitments are noncancelable; (ii) prepaid fees are nonrefundable; and (iii) purchased quantities, usage commitments and service levels may not be reduced during a Subscription Term; and (iv) Customer’s non-use, under-use, delayed deployment or failure to implement the Services does not relieve Customer of its payment obligations. Fees for a renewal term will be charged at the rates specified in the applicable Order or, if none are specified, Atbash’s then-current rates. The Parties acknowledge that the fees reflect this allocation of risk and that Atbash would not provide the Services on the same economic terms without these exclusions and limitations.

17.2

Self-Service Subscriptions and Automatic Charges. For a self-service subscription, Customer authorizes Atbash and its payment processor to charge Customer’s designated payment method for all fees, taxes, usage charges, overages and renewal amounts disclosed and accepted at checkout. Customer will maintain complete, accurate and current billing and payment information. If Customer affirmatively accepts automatic-conversion terms when enrolling in a trial, Atbash may charge the disclosed subscription fees beginning on the stated conversion date unless Customer cancels through the stated cancellation mechanism before that date. Customer’s trial enrollment alone will not authorize paid conversion unless the applicable price, billing frequency, conversion date and cancellation terms were presented and accepted.

17.3

Usage Measurement and Overages. Atbash may measure usage through its service records and metering systems. Those records will control for billing purposes absent clear and demonstrable error. The applicable Order or pricing schedule will identify the billable units, included capacity, rate limits and applicable overage rates. Customer is responsible for usage generated through its account, Authorized Users, Agents, Integrations and Credentials, including usage resulting from Customer-configured retries or duplicate submissions. Atbash may invoice overages at the agreed rates as they are incurred or in arrears. If Customer exceeds a usage entitlement for which no overage rate has been agreed, Atbash may, without obligation to provide excess capacity: (i) reject, throttle or suspend excess usage; (ii) require Customer to purchase additional capacity; or (iii) offer additional capacity at Atbash’s then-current rates through a new or amended Order. Any usage information supplied by Atbash is provided to support invoice review and does not transfer control of, or responsibility for, Atbash’s metering methodology.

17.4

Overdue Amounts. Customer may not withhold payment or apply any setoff, deduction, counterclaim or recoupment against amounts due, except for an agreed credit or deduction required by applicable law. Customer’s procurement, vendor-onboarding or internal approval procedures do not modify payment deadlines. Amounts not paid when due may accrue interest at the lesser of 1.5% per month or the maximum rate permitted by applicable law. Customer will reimburse Atbash for reasonable costs of collecting overdue undisputed amounts, including reasonable attorneys’ fees. Atbash may suspend the affected Services if an undisputed amount remains unpaid after Atbash provides Customer with a notice of the delinquency. Atbash need not provide additional notice where Customer has previously received notice concerning the same overdue amount.

17.5

Taxes and Withholding. Fees exclude all sales, use, value-added, goods and services, withholding and similar taxes, duties or governmental assessments arising from Customer’s purchase or use of the Services (“Transaction Taxes”). Customer is responsible for all Transaction Taxes, except taxes imposed on Atbash’s net income, property or personnel. If Customer is required to deduct or withhold any amount from a payment, Customer will: (i) timely remit the required amount to the applicable authority; (ii) provide Atbash with official evidence of remittance; and (iii) increase the payment so that Atbash receives the full amount it would have received without the deduction or withholding. Customer must provide any valid exemption certificate before the applicable charge is invoiced. The Parties will reasonably cooperate to obtain available exemptions or treaty benefits, but Atbash is not required to incur material cost or assume additional liability in doing so.

17.6

Resellers and Marketplaces. Where Customer purchases through an Atbash-authorized reseller, marketplace or other channel, the channel order governs only the invoicing, collection and payment arrangements between Customer and that channel. The Agreement governs Atbash’s provision of the Services. No channel partner has authority to modify the Agreement or make any representation, warranty, indemnity, service commitment or other obligation binding on Atbash unless Atbash expressly accepts it in a writing signed by an authorized representative. Refunds relating to channel purchases must be requested and processed through the applicable channel, and Atbash has no obligation to provide a duplicate refund. For purposes of any liability limitation calculated by reference to fees, the relevant amount is the net amount actually received by Atbash for the affected Services, excluding taxes, reseller margins, marketplace fees and amounts attributable to other products or services.

18.DISCLAIMER

18.1

EXCEPT FOR ANY WARRANTY EXPRESSLY SET FORTH IN THE AGREEMENT, AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICES, ATBASH TECHNOLOGY, DOCUMENTATION, DECISIONS AND ALL RELATED MATERIALS ARE PROVIDED “AS IS” AND “AS AVAILABLE.” ATBASH AND ITS LICENSORS DISCLAIM ALL OTHER WARRANTIES, REPRESENTATIONS AND CONDITIONS, WHETHER EXPRESS, IMPLIED, STATUTORY OR ARISING FROM COURSE OF DEALING, USAGE OR TRADE PRACTICE, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, RELIABILITY OR QUIET ENJOYMENT. NO ORAL OR WRITTEN INFORMATION, RECOMMENDATION OR ADVICE PROVIDED BY ATBASH CREATES A WARRANTY OR COMMITMENT NOT EXPRESSLY STATED IN THE AGREEMENT.

18.2

Agentic-System and Decision Limitations. ATBASH DOES NOT WARRANT OR REPRESENT THAT: (i) every Action will be submitted, visible, evaluated, gated, blocked or recorded; (ii) every unauthorized, malicious, fraudulent, unsafe or noncompliant Action will be detected or prevented; (iii) any semantic, probabilistic or model-based evaluation will be complete, consistent or correct; (iv) Customer’s Policies will identify, express or address every applicable risk, requirement or circumstance; (v) incomplete, inaccurate, stale, misleading or inconsistent Decision Inputs will be detected or produce an appropriate Decision; or (vi) a Decision will remain valid following any change in parameters, identity, authority, Policies, system state or other relevant context. An ALLOW Decision means only that the Submitted Action satisfied the criteria applied by the Services based on the Decision Inputs available at the time of evaluation. It is not independent confirmation that an Action, transaction, recipient, credential or underlying fact is genuine, accurate, authorized, lawful, secure, nonfraudulent or commercially advisable..

18.3

Operational and Security Limitations. ATBASH DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, IMMUNE FROM ATTACK OR COMPROMISE, COMPATIBLE WITH EVERY CUSTOMER SYSTEM OR THIRD-PARTY PRODUCT, OR INCAPABLE OF BEING BYPASSED. ATBASH DOES NOT WARRANT THAT: (i) audit records will satisfy any particular legal, regulatory or evidentiary requirement; (ii) an Action can be reversed, cancelled or recovered after execution; (iii) the Services will prevent all unauthorized access, downstream loss or adverse outcomes; or (iv) any Third-Party Product, Customer-selected Judge, model or Integration will remain available or unchanged. The Services supplement, and not replace, Customer’s cybersecurity, identity and access management, transaction controls, regulatory compliance, professional advice, business continuity or human governance. Customer assumes the risks arising from its selection of fail-open behavior, advisory functionality, alternate execution paths and other configurations that do not technically prevent execution. If generally available paid Services materially fail to conform to an express warranty in the Agreement, Customer must notify Atbash within 30 days after becoming aware of the nonconformity and provide information reasonably sufficient for Atbash to investigate it. Atbash’s sole obligation, and Customer’s exclusive remedy, will be for Atbash to use commercially reasonable efforts to correct the nonconformity. If Atbash determines that correction is not commercially reasonable, Atbash may terminate the affected Services and refund prepaid fees allocable to the unused portion of the terminated Subscription Term. This remedy does not apply to failures caused by Customer Systems, Customer Data, Third-Party Products, unsupported configurations, Customer’s breach or matters outside the Atbash Control Boundary.

19.INDEMNIFICATION

19.1

Indemnity. Customer will defend Atbash, its Affiliates, licensors and subcontractors, and their respective officers, directors, employees and agents, against any third-party claim, action, investigation or proceeding arising out of or relating to: (a) Customer Data, Customer Records, Customer Policies, Customer Agents or other materials supplied by or on behalf of Customer; (b) Customer’s products, services, business processes, customer-facing workflows, deployment decisions, instructions or Actions; (c) Customer Systems, Customer-hosted Judges or Customer-selected Third-Party Products; (d) Customer’s or an Authorized User’s violation of applicable law or third-party intellectual-property, privacy, confidentiality or other rights; (e) Customer’s failure to obtain any required authorization, license, notice, consent or lawful basis; (f) Customer’s breach of the Acceptable Use or Regulated and High-Impact Deployment provisions; (g) unauthorized activity conducted through Customer’s Credentials or account, except to the extent directly caused by Atbash’s breach; or (h) a dispute between Customer and any end customer, user, Operator, contractor, Judge provider or other third party concerning Customer’s Agent, product, workflow, transaction or use of the Services. Customer’s obligations apply whether the relevant Action received an ALLOW, HOLD, BLOCK or other Decision. Customer will pay all damages, penalties to the extent legally indemnifiable, reasonable legal costs and expenses finally awarded against an indemnified party, together with settlement amounts approved by Customer in writing. Customer has no obligation under this Section to the extent a claim would have arisen independently from Atbash’s material breach of the Agreement or willful misconduct.

19.2

Indemnification Procedure. The indemnified Party will promptly notify the indemnifying Party of a covered claim and provide reasonable cooperation at the indemnifying Party’s expense. A delay in notice relieves the indemnifying Party of its obligations only to the extent materially prejudiced by that delay. The indemnified Party may participate through separate counsel at its own expense.

20.LIMITATION OF LIABILITY

20.1

Excluded Damages. TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY NOR ITS AFFILIATES, LICENSORS OR SUBCONTRACTORS WILL BE LIABLE UNDER OR IN CONNECTION WITH THE AGREEMENT FOR: (a) INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES; (b) LOSS OF PROFITS, REVENUE, BUSINESS, BUSINESS OPPORTUNITY, GOODWILL, REPUTATION OR ANTICIPATED SAVINGS; (c) BUSINESS INTERRUPTION, LOSS OF USE OR COST OF SUBSTITUTE SERVICES; (d) LOSS, CORRUPTION OR RECONSTRUCTION OF DATA; OR (e) FAILURE TO REALIZE EXPECTED SECURITY, OPERATIONAL OR COMMERCIAL BENEFITS, IN EACH CASE, WHETHER THE LOSS IS ASSERTED AS DIRECT, INDIRECT, CONSEQUENTIAL OR OTHERWISE; WHETHER ARISING IN CONTRACT, TORT, NEGLIGENCE, STRICT LIABILITY, STATUTE OR ANY OTHER THEORY; AND REGARDLESS OF WHETHER THE LOSS WAS FORESEEABLE, WHETHER THE PARTY WAS ADVISED OF ITS POSSIBILITY, OR WHETHER ANY LIMITED OR EXCLUSIVE REMEDY FAILS OF ITS ESSENTIAL PURPOSE. This Section does not exclude amounts payable to an unaffiliated third party under an express indemnification obligation, but those amounts remain subject to any applicable cap. Nothing in this Section creates an independent obligation to reimburse incident-response, investigation, notification, restoration, replacement-service or similar costs.

20.2

General Liability Cap. Except as expressly provided below, each Atbash’s total aggregate liability arising out of or relating to the Agreement will not exceed the greater of: (a) US$100; or (b) the fees actually paid to Atbash for the affected Services during the 12 months immediately preceding the first event giving rise to the liability, in each case net of refunds and credits (the “Base Amount”). The Base Amount is a single aggregate cap for all claims arising from the same or related events and does not reset or multiply by year, claim, claimant, Order, Agent, Decision or theory of liability.

20.3

Exceptions. Sections 20.1 through 20.2 do not limit instances of fraud or willful misconduct and liability that applicable law does not permit to be excluded or limited, including liability for gross negligence only to the extent the applicable jurisdiction prohibits its limitation. Except as expressly stated above, ordinary negligence, negligent misrepresentation, alleged negligent authorization and failure to prevent an Agent or Operator Action remain subject to the cap in the form of the Baes Amount.

20.4

Mitigation. Atbash is not responsible to the extent a loss results from: (a) Customer Data, Customer Policies or Decision Inputs; (b) Customer’s configuration, deployment decision or failure to implement a Decision; (c) Customer Systems, Agents or Credentials; (d) a Third-Party Product or Customer-selected Judge; (e) an Action outside the Atbash Control Boundary; or (f) Customer’s failure to follow the Agreement or Documentation. Each Party will take reasonable steps to mitigate any loss. Customer’s use of the Services in an Agent workflow does not make Atbash responsible for the workflow’s outcome, and Customer’s involvement does not excuse a breach independently caused by Atbash within the Atbash Control Boundary.

21.TERM, RENEWAL AND TERMINATION

21.1

Agreement Term. This Agreement continues from the Effective Date and continues until all Orders have expired or been terminated and Customer has ceased all access to the Services. Atbash may terminate an account without an active Order on notice to Customer. Unless an Order expressly provides otherwise: (a) a monthly subscription automatically renews for successive monthly periods until Customer cancels it before the next renewal date; and (b) any other subscription automatically renews for successive 12-month periods unless either Party gives notice of nonrenewal at least 30 days before the end of the then-current Subscription Term. Customer may submit a nonrenewal notice through any electronic cancellation mechanism made available by Atbash. Cancellation or nonrenewal takes effect only at the end of the then-current Subscription Term and does not terminate, reduce or entitle Customer to a refund for that committed term.

21.2

Renewal Pricing. Unless an Order expressly provides for fixed renewal pricing, price protection or a renewal cap, each renewal will be charged at Atbash’s then-current rates for the applicable Services and usage entitlements. Promotional, pilot and introductory pricing expires at the end of the period for which it was expressly granted. Atbash may notify Customer of revised renewal pricing at least 30 days before the renewal date. Customer’s exclusive right if it does not accept the revised pricing is to prevent renewal by submitting a timely nonrenewal notice. If Atbash provides notice after an otherwise applicable nonrenewal deadline, Customer may submit a nonrenewal notice within 10 days after receiving the pricing notice. Continued use during the renewed Subscription Term constitutes acceptance of the renewal and its pricing.

21.3

Termination. Customer may terminate an affected Order if Atbash materially breaches the Agreement and fails to cure that breach within 30 days after receiving written notice that describes the breach in reasonable detail. Atbash may terminate or suspend an affected Order, Customer account or the Agreement at any time.

21.4

Termination Effects. Upon expiry or termination, Customer will cease using the affected Services and uninstall or disable licensed components, except for rights that expressly survive and any limited export access. Customer must safely reconfigure its Agents and Customer Systems; termination does not revoke downstream credentials or assure that Agents stop. Accrued payment obligations remain due.

21.5

Survival. The provisions in the following sections will survive expiration or termination of this Agreement: 1, 13,14,15,16,17,18,19,20 and 24.1.

22.DISTRIBUTED AND APPEND-ONLY RECORDS

22.1

Where Customer enables blockchain-based or other append-only recording, Customer instructs Atbash to submit the categories of information identified in the applicable Product Schedule, Documentation or configuration to the applicable recording mechanism. Customer acknowledges that: (a) submitted information may become public or accessible to third parties; (b) records may be replicated across systems outside Atbash’s control; (c) modification, recall and deletion may be technically impossible; and (d) termination of the Agreement does not remove previously submitted records. Customer is responsible for determining whether the proposed recording is lawful and appropriate and for ensuring that Submitted Actions do not contain private keys, passwords, unnecessary personal data or other information unsuitable for persistent or public recording. Customer will not enable append-only recording of personal or specially regulated data unless the applicable Order, DPA and Product Schedule expressly support it.

22.2

Customer is responsible for determining whether the proposed recording is lawful and appropriate and for ensuring that Submitted Actions do not contain private keys, passwords, unnecessary personal data or other information unsuitable for persistent or public recording. Customer will not enable append-only recording of personal or specially regulated data unless the applicable Order, DPA and Product Schedule expressly support it.

22.3

Atbash will implement any agreed access controls, off-chain deletion measures or other mitigation within the Atbash Control Boundary. Atbash does not warrant or undertake to delete, modify or suppress records held by independent nodes, networks, indexers, archival services or other third parties outside its control.

23.PUBLICITY

Unless Customer opts out in the Order or by written notice, Atbash may identify Customer by name and use its logo in ordinary customer lists, following any supplied reasonable brand guidelines. Atbash will cease new use promptly after opt-out and remove digital listings within a reasonable period. Case studies, endorsements, substantive statements about Customer’s deployment and press releases require Customer’s prior written consent. Neither Party may imply an endorsement not given.

24.MISCELLANEOUS

24.1

Jurisdiction; Venue. This Agreement and disputes arising out of or relating to it are governed by the laws of the State of Delaware, USA, law, excluding conflict-of-laws rules. The UN Convention on Contracts for the International Sale of Goods does not apply. Subject to applicable nonwaivable law, the state and federal courts located in Delaware have exclusive jurisdiction, and each Party consents to personal jurisdiction and venue there. Either Party may seek temporary protective relief in a competent court to preserve confidentiality or intellectual property pending resolution in the selected forum. EACH PARTY KNOWINGLY WAIVES TRIAL BY JURY TO THE EXTENT ENFORCEABLE.

24.2

Notices. Legal notices must be sent to the legal-notice email or physical address identified in the Order or, for Atbash, and for Customer, its designated legal contact or account administrator. Email notice is effective when received without a delivery failure during the recipient’s business hours, otherwise on its next business day; courier notice is effective on recorded delivery. Operational notices may be sent through the Services. Notices of breach, termination or material contractual changes require email or courier, not dashboard posting alone. Each Party will maintain current contact details.

24.3

Assignment. Neither Party may assign this Agreement without the other’s prior written consent, not unreasonably withheld, except in case Atbash and with respect to an Affiliate of Atbash or in connection with a merger, reorganization or sale of substantially all relevant assets. Assignment does not expand usage rights or relieve accrued obligations. A prohibited assignment is void to the extent permitted by law.

24.4

Force majeure. Neither Party is liable for delay caused by events beyond its reasonable control that could not reasonably have been prevented or overcome, excluding payment obligations and lack of funds. The affected Party will promptly notify the other and use reasonable mitigation efforts. A cyberattack, internet connection disruptions, war, natural disasters, validator shutdown, provider outage, network failure or any act of God qualifies only to the extent those conditions are met and does not excuse failure to meet payment obligations.

24.5

Amendments. Atbash may modify these Terms and any incorporated policy, schedule or Documentation from time to time in its sole discretion. Unless Atbash specifies otherwise: (a) non-material changes become effective when posted; (b) material changes become effective on the date stated in a notice delivered by email, through Customer’s account or dashboard, or by another reasonable electronic method; and (c) changes reasonably required to address applicable law, security threats, fraud, abuse, third-party requirements or material operational risk may become effective immediately upon notice. The revised Agreement applies prospectively to Customer’s continued access to and use of the Services, including under then-current Orders, from its effective date. Customer’s continued access or use after that date constitutes acceptance of the revised Agreement. Atbash may require Customer or an Authorized User to affirmatively accept a revision and may suspend access until acceptance is completed. If Customer does not agree to a revision, Customer’s sole remedy is to cease using the Services and submit a timely nonrenewal notice. Objection to a revision does not terminate or reduce an existing subscription commitment, excuse payment, or entitle Customer to a refund.

24.6

Entire agreement. Entire Agreement; Contractual Documents. The “Agreement” consists exclusively of: (a) these Terms; (b) each Order entered into under them; (c) each applicable Product Schedule, DPA, service-level or support policy, Acceptable Use Policy and other addendum or policy expressly incorporated by reference, including through a hyperlink made available to Customer; and (d) the Documentation, solely to the extent incorporated under these Terms. Each such document forms part of the Agreement and must be interpreted together with the other components of the Agreement, subject to the applicable order-of-precedence provisions. The Agreement constitutes the complete and exclusive agreement between the Parties concerning its subject matter and supersedes all prior and contemporaneous proposals, negotiations, communications, understandings, representations and agreements, whether oral or written. Customer acknowledges that it has not relied on any representation, warranty, commitment or statement not expressly set forth in the Agreement and that its purchase is not contingent on the delivery of any future feature, functionality or product. An Order forms part of the Agreement and does not create a separate or independent contract unless it expressly states otherwise.

24.7

Electronic Acceptance and Execution. Customer may enter into this Agreement and any Order electronically. By clicking an “Accept,” “Agree,” “Submit Order,” “Purchase,” “Start Subscription” or similar button; selecting a checkbox presented with a link to the applicable terms; completing an electronic checkout or account-registration process; or otherwise using an electronic mechanism that Atbash identifies as constituting acceptance, the accepting individual: (a) affirmatively agrees to the Agreement or applicable Order; (b) intends to provide an electronic signature having the same legal effect as a handwritten signature; and (c) represents and warrants that the individual has authority to bind Customer. Customer is bound by electronic acceptances and Orders submitted through its account by its Authorized Users and designated subscription administrators acting within their actual or apparent authority. Atbash may rely on information submitted through Customer’s account and is not required to obtain a handwritten signature, corporate seal, board resolution or separate confirmation of authority. Atbash may accept an electronic Order by issuing an electronic confirmation, provisioning the applicable Services, enabling the requested subscription or otherwise beginning performance. No countersignature by Atbash is required unless the applicable Order expressly provides otherwise. Customer consents to the use of electronic records, signatures, notices and communications in connection with the Agreement. Atbash may create and retain electronic records of acceptance and execution, including the accepting individual’s name, account identifier, email address, IP address, timestamp, acceptance method and the version of the applicable terms presented. Absent manifest error, those records will constitute evidence of Customer’s acceptance and the applicable transaction. Electronic signatures, clickwrap acceptances, scanned signatures and signatures applied through an electronic-signature service are effective and binding to the same extent as original handwritten signatures. Any electronically stored or reproduced copy of the Agreement or an Order may be used as an original for evidentiary and enforcement purposes. Orders and other signed instruments may be executed in counterparts, each of which is deemed an original and all of which together constitute one instrument.